Azure-Sentinel/Playbooks/Add-IP-Entity-To-Named-Loca...
..
images
AddApiPermissions.ps1
azuredeploy.json
readme.md

readme.md

Add-IP-Entity-To-Named-Location

author: Brian Delaney

This playbook will execute using an incident based trigger and add the IP entities to a Conditional Access Named Location

Quick Deployment

Deploy to Azure Deploy to Azure Gov

Prerequisites

  • None

After Deployment

  • Grant the Logic App Managed Identity access to the Microsoft Graph Policy.Read.All & Policy.ReadWrite.ConditionalAccess which can be done with the included PowerShell script AddApiPermissions.ps1
  • Attach this playbook to an automation rule so it runs when specified incidents are created.

Learn more about automation rules

Screenshots

Designer