Incident Assignment Shifts

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This playbook will assign an Incident to an owner based on the Shifts schedule in Microsoft Teams. When an incident is assigned, the incident owner will be notified via email. Incidents are assigned to users based on the following criteria:
Only users who have started their shifts during the time the Logic App runs will be considered. Users who still have at least 1 hours left before going off shift (can be configured in playbook) *User with the least incidents assigned on the current Shif

Attribute Value
Type Playbook
Solution SentinelSOARessentials
Source View on GitHub

Additional Documentation

📄 Source: Incident-Assignment-Shifts/readme.md

Incident-Assignment-Shifts

author: Jeremy Tan

version: 2.2

This playbook will assign an Incident to an owner based on the Shifts schedule in Microsoft Teams.

Deploy to Azure Deploy to Azure Gov

Pre-requisites:

Ensure you have the following details:

1. User account or Service Principal or Managed Identity with Microsoft Sentinel Responder role

2. Setup Shifts schedule

3. User account with Owner role in Microsoft Teams

4. User account or Service Principal with Log Analytics Reader role

5. An O365 account to be used to send email notification

Post Deployment Configuration:

1. Enable Managed Identity and configure role assignment



2. Configure connections

3. Select the Shifts schedule


Incident Assignment Logic:

Incidents are assigned to users based on the following criteria:

[Content truncated...]


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Playbooks · Back to SentinelSOARessentials