You have an Azure Sentinel workspace that has an Azure Active Directory (Azure AD) connector and a Microsoft Office 365 connector.
You need to use a Fusion rule template to detect multistage attacks in which users sign in by using compromised credentials, and then delete multiple files from
Microsoft OneDrive.
Based on the Fusion rule template, you create an active rule that has the default settings.
What should you do next?
mbecile
Highly Voted 3 years, 4 months agoEzeQ
2 years, 9 months agopete26
Highly Voted 2 years, 10 months agoMaxx4
Most Recent 1 year, 11 months agoGPerez73
2 years agoabrub
2 years, 2 months agomcclane654
2 years, 4 months agoARYMBS
3 years agoHei
3 years, 2 months agokakakayayaya
3 years, 4 months agomkoprivnj
3 years, 5 months agoAlexanderSaad
3 years, 5 months agoRstilekar
3 years, 6 months agoBrandon_2319
3 years, 6 months agoFluffhead
3 years, 7 months agosaeedsaf
3 years, 8 months agokiketxu
4 years, 2 months ago