Dec 20 2023 01:28 PM
Hello,
Looking for a Query that will search within Sentinel for the last logon attempt for ALL terminated users over the past 11 months, please.
Dec 29 2023 06:03 AM
Jan 03 2024 05:20 AM
Highly suggest using a Watchlist to store the terminated employees. There is a template for it and, with the help of a Logic App that queries the Graph API, you can keep it up to date automatically.
Jan 07 2024 05:26 PM
Jan 08 2024 05:17 AM
Watchlist template is available is Microsoft Sentinel
and here is an example of logic app for watchlist automation