Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
This playbook adds URLs to the Zscaler security blacklist using OAuth2 authentication.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Zscaler Internet Access |
| Source | View on GitHub |
📄 Source: Oauth2BlacklistURL/readme.md
This playbook enables automated URL blocking in Zscaler Internet Access (ZIA) when triggered by Microsoft Sentinel incidents. It uses OAuth2 authentication to securely communicate with the Zscaler API and add malicious URLs to a designated block category.
The Zscaler-Oauth2-BlacklistURL playbook is designed to:
Before deploying this playbook, ensure you have:
Click the button below to deploy the Zscaler-Oauth2-BlacklistURL playbook to your Azure environment:
After deployment, complete the following steps:
Authorize API Connections - Navigate to the Logic App in the Azure portal - Go to API connections and authorize the Microsoft Sentinel connection - Ensure the managed identity has appropriate permissions
Grant Required Permissions - Assign the Logic App managed identity the "Microsoft Sentinel Responder" role - Verify the authentication playbook is accessible from this playbook
Configure Zscaler Block Category - Verify the block category specified during deployment exists in Zscaler - To change the category, edit the playbook and update the category variable
Configure Automation Rules - Create automation rules in Microsoft Sentinel to trigger this playbook - Configure rules to run on incidents containing URL entities
| Parameter | Description | Default Value |
|---|---|---|
| PlaybookName | Name of the Logic App | Zscaler-Oauth2-BlacklistURL |
| Zscaler Authentication Playbook | Name of the OAuth2 authentication playbook | Zscaler-Oauth2-Authentication |
| Zscaler Admin URL | Your Zscaler admin portal URL | https://admin.zscaler.net |
| Block Category | Zscaler URL category for blocking | OTHER_MISCELLANEOUS |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊