Creating Sentinel Incidents for Subscription-Based Security Score Recommendations

Someiah C S 100 Reputation points
2025-03-05T09:31:55.1+00:00

I am looking for a way to generate Sentinel incidents based on security score recommendations for subscriptions (as shown in the attached example). Is there a method to achieve this so that we can receive real-time notifications and take immediate action instead of identifying these issues later?

Any insights or recommendations would be greatly appreciated!

User's image

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,241 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Andrew Blumhardt 9,876 Reputation points Microsoft Employee
    2025-03-05T13:16:43.2766667+00:00

    There is no native email service for recommendations but you do have the option of setting governances rules. https://learn.microsoft.com/en-us/azure/defender-for-cloud/governance-rules

    If you look at the Secure Score Over Time workbook it also has instructions for exporting recommendations to Log Analytics. From there you could create custom emails or alerts using Logic Apps. https://learn.microsoft.com/en-us/azure/defender-for-cloud/custom-dashboards-azure-workbooks#secure-score-over-time-workbook

    Consider that these are security posture recommendations for your Azure cloud infrastructure. You will find similar recommendations in the Defender XDR portal for other security solutions like MDE and MDI. Security Operation teams tend to focus on reactive security incidents vs. proactive posture improvements. Mixing reactive and proactive in the same incident queue could be confusing if they are not separated in some way like a naming standard or tag. That is why you often see security posture recommendations as a dashboard or email. They are more subjective, lower priority, and take much longer to resolve.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.