You have an Azure subscription named Sub1 and a Microsoft 365 subscription. Sub1 is linked to an Azure Active Directory (Azure AD) tenant named contoso.com.
You create an Azure Sentinel workspace named workspace1. In workspace1, you activate an Azure AD connector for contoso.com and an Office 365 connector for the Microsoft 365 subscription.
You need to use the Fusion rule to detect multi-staged attacks that include suspicious sign-ins to contoso.com followed by anomalous Microsoft Office 365 activity.
Which two actions should you perform? Each correct answer present part of the solution.
NOTE: Each correct selection is worth one point.
arunkum
Highly Voted 3 years, 6 months agoDiscuss4certi
3 years, 6 months agoMenard001
2 years, 10 months agoMenard001
2 years, 10 months agovincenttoolate
2 years, 9 months agoMenard001
2 years, 10 months agoContactfornitish
Highly Voted 3 years, 2 months agopedromonteirozikado
3 years, 1 month agotalosDevbot
Most Recent 6 months, 3 weeks agoStudytime2023
9 months agoRamye
1 year, 2 months agoRamye
1 year, 2 months agoMax_DeJaV
1 year, 3 months agokabooze
1 year, 6 months agochepeerick
1 year, 6 months agodanb67
1 year, 6 months agodanb67
1 year, 6 months agoSaHaGe
1 year, 7 months agomali1969
1 year, 7 months agoitsadel
1 year, 8 months agodonathon
1 year, 8 months agodonathon
1 year, 8 months agoitsadel
1 year, 9 months ago7c0a
1 year, 10 months ago