Category: Vendor Runbooks · View source ↗
Vendor Runbooks
Defender M365 Alerts
Triage Microsoft Defender and Entra alerts: Safe Links or Safe Attachments detonation, suspicious inbox rules, risky sign-in. Correlate to the incident.
Runs as: Skill — you run it in Super Magic and confirm each write; there’s no Flow trigger for this one.
Connectors: Thread — native, no connector required
Role: Security & Compliance Owner, Technician
Outcome: Risk & Compliance, Faster Resolution & Response
When to use: A Defender or Microsoft 365 security alert lands as a ticket (email notification or SIEM/PSA integration); a tech asks where in the Microsoft portals to work a given alert; or multiple Microsoft alerts arrive for the same user and need correlating.
Run it: on the alert ticket.
Was this page helpful?
⌘I