Skip to content

Commit

Permalink
update readme
Browse files Browse the repository at this point in the history
added Responder role
  • Loading branch information
BenjiSec authored May 3, 2023
1 parent b7f4874 commit d0b9863
Showing 1 changed file with 3 additions and 2 deletions.
5 changes: 3 additions & 2 deletions Solutions/SOC-Process-Framework/Playbooks/readme.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,10 +16,11 @@ This playbook does a watchlist lookup using an API connection created with in th
</a>

### Post-Deployment Instructions
After deploying the playbook, you must authorize the connections leveraged.
After deploying the playbook, you must authorize the connections leveraged and assign permissions

1. Visit the playbook resource.
2. Under "Development Tools" (located on the left), click "API Connections".
3. Ensure each connection has been authorized.
4. Assign Microsoft Sentinel Responder role to the managed identity. To do so, choose Identity blade under Settings of the Logic App.

**Note: If you've deployed the [Get-SOCActions Playbook](https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/SOC-Process-Framework/Playbooks/Get-SOCActions/azuredeploy.json) playbook, you will only need to authorize the Microsoft Sentinel connection.**
**Note: If you've deployed the [Get-SOCActions Playbook](https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/SOC-Process-Framework/Playbooks/Get-SOCActions/azuredeploy.json) playbook, you will only need to authorize the Microsoft Sentinel connection.**

0 comments on commit d0b9863

Please sign in to comment.