StratoSecure - Escalate to Owner via Email

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


When a Microsoft Sentinel incident from a StratoSecure finding remains unacknowledged, this playbook sends an escalation email via Azure Communication Services and writes an audit record to StratoSecure_PlaybookRuns_CL. Human approval is always required before the action executes.

Attribute Value
Type Playbook
Solution StratoSecure
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
StratoSecure_PlaybookRuns_CL ? ✓ ?

Logic App Connectors

This playbook uses 3 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azureloganalyticsdatacollector Managed 1 1
azuresentinel Managed 1 0
http Built-in 0 1
Action parameters (URLs, paths, function IDs)

azureloganalyticsdatacollector (Managed)

Action Method Endpoint Other
Action_AuditLog post /api/logs —

http (Built-in)

Action Method Endpoint Other
Action_SendEscalationEmail POST [variables('HttpEndpoint')] —

Additional Documentation

📄 Source: StratoSecure-EscalateOwner/readme.md

StratoSecure — Escalate Owner

Sends an escalation email via Azure Communication Services when a StratoSecure finding remains unresolved past SLA. Writes an audit record to StratoSecure_PlaybookRuns_CL regardless of email outcome.

Prerequisites

Post-Deployment Steps

  1. Grant the Logic App system-assigned managed identity the Microsoft Sentinel Responder role on the Sentinel workspace.
  2. Grant the managed identity the Azure Communication Services Contributor role (or use AcsAccessKey parameter instead).
  3. Set the EscalationEmail parameter to your SOC lead address.

Parameters

Parameter Type Description
PlaybookName string Logic App resource name
AcsEndpointHostname string ACS resource hostname (without https://)
AcsManagedIdentityEnabled string true to use managed identity; false to use access key
AcsAccessKey securestring ACS access key (required only when managed identity is disabled)
SenderEmail string Verified sender address in ACS
EscalationEmail string Recipient email for escalation notifications
LogAnalyticsWorkspaceId string Workspace ID for audit logging
LogAnalyticsWorkspaceKey securestring Workspace primary key for audit logging
RequireApproval bool When true, actions execute only after approval condition evaluates (default: true)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to StratoSecure