Skip to content

Conversation

@briandelmsft
Copy link
Contributor

Change(s):

  • Created 2 new playbooks for incident alerting
  • 1 Playbook sends an email alert with modern template including links to the XDR portal
  • 1 Playbook sends a teams adaptive card with modern template and links to the XDR portal
  • Both playbooks include entity level linking where possible, such as account entities to the XDR user page, and device entities to the XDR Device page

Reason for Change(s):

  • The existing playbooks are centered around the Azure Portal, while things are moving the security.microsoft.com portal. Given that the old portal will be deprecated, a new template is needed. These new playbooks are more modern in design, provide more entity information, and link the security.microsoft.com portal at the incident and where appropriate the entity level as well.

Version Updated:

  • N/A

Testing Completed:

  • Deployment tested
  • Permissioning tested
  • Email template tested
  • Teams card tested

@briandelmsft briandelmsft requested review from a team as code owners December 12, 2025 21:43
@v-shukore v-shukore added Playbook Playbook specialty review needed Solution Solution specialty review needed labels Dec 15, 2025
Added 'Send-Incident-Email-XDRPortal' and 'Send-Incident-Teams-Adaptive-Card-XDRPortal' playbooks to the solution. Updated playbook count in createUiDefinition.json, incremented solution version to 3.0.6, and included the new package zip. Updated mainTemplate.json to deploy the new playbooks and revised playbook template descriptions to reflect the new version.
@v-atulyadav v-atulyadav merged commit ac53c15 into Azure:master Dec 29, 2025
32 of 33 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Playbook Playbook specialty review needed Solution Solution specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants