Unisolate MDE Machine using entity trigger

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This playbook will unisolate Microsoft Defender for Endpoint (MDE) device using entity trigger.

Attribute Value
Type Playbook
Solution MicrosoftDefenderForEndpoint
Source View on GitHub

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 2
wdatp Managed 1 2
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Add_comment_to_incident_(V3)_-_device_isolated post /Incidents/Comment —
Add_comment_to_incident_(V3) post /Incidents/Comment —

wdatp (Managed)

Action Method Endpoint Other
Machines_-_Get_list_of_machines get /api/machines —
Actions_-_Unisolate_machine post /api/machines/@{encodeURIComponent(item()?['id'])}/unisolate —

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to MicrosoftDefenderForEndpoint