Forum Discussion

myprofile490's avatar
myprofile490
Copper Contributor
May 13, 2022
Solved

Error when running playbook Block-AADUser-Alert

Hello, I have personal account and I am trying Microsoft Sentinel. My senario is when user account (not admin) changes his authentication method, an alert is triggered and then I run built-in playbo...
  • mikhailf's avatar
    mikhailf
    May 14, 2022
    It seems that there are insufficient permissions. How do you connect the "Update user" part to AAD? Do you use managed identity or user? If it is a user, doesn't it have sufficient permissions to disable another user's account?

    Could you try the second playbook for disabling AAD users? The one that is based on Incident.

    And please, check this: https://github.com/microsoftgraph/microsoft-graph-docs/blob/main/api-reference/v1.0/resources/security-api-overview.md
    There is a table with supported methods and systems.
    Does that mean that PATCH method is not supported by Sentinel alerts?

Resources