Skip to content

add sap playbook for agentless and XDR#14071

Merged
v-atulyadav merged 3 commits intoAzure:masterfrom
MartinPankraz:enhance-sap-user-block
Apr 16, 2026
Merged

add sap playbook for agentless and XDR#14071
v-atulyadav merged 3 commits intoAzure:masterfrom
MartinPankraz:enhance-sap-user-block

Conversation

@MartinPankraz
Copy link
Copy Markdown
Contributor

Change(s):

  • playbook added supporting SAP Integration Suite for agentless for user blocking
  • altered alert parsing logic compared to existing playbooks to cater for XDR correlated incidents rather than isolated SAP incidents in Sentinel only

@MartinPankraz MartinPankraz requested review from a team as code owners April 14, 2026 15:08
@v-shukore v-shukore added the SAP label Apr 15, 2026
@v-maheshbh v-maheshbh requested a review from Copilot April 15, 2026 05:55
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Adds a new “Lock SAP User” consumption playbook that supports agentless user blocking via SAP Integration Suite and improves alert parsing to work with correlated Defender XDR incidents (multi-alert).

Changes:

  • Added a new Consumption Logic App playbook with dynamic extraction of SAP Custom Details across all incident alerts.
  • Updated the SAP Playbooks index to list both Consumption and Standard variants.
  • Added documentation for deployment, parameters, and extension points of the new playbook.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 6 comments.

File Description
Solutions/SAP/Playbooks/README.md Updates playbook index to include the new Consumption variant alongside the existing Standard variant.
Solutions/SAP/Playbooks/Basic-SAPLockUser/azuredeploy.json Introduces the new Consumption Logic App ARM template, including XDR-friendly alert filtering and Teams adaptive card workflow.
Solutions/SAP/Playbooks/Basic-SAPLockUser/README.md Documents purpose, prerequisites, deployment parameters, and differences vs. STD.

Comment thread Solutions/SAP/Playbooks/Basic-SAPLockUser/azuredeploy.json
Comment thread Solutions/SAP/Playbooks/Basic-SAPLockUser/azuredeploy.json Outdated
Comment thread Solutions/SAP/Playbooks/Basic-SAPLockUser/azuredeploy.json
Comment thread Solutions/SAP/Playbooks/Basic-SAPLockUser/azuredeploy.json
Comment thread Solutions/SAP/Playbooks/Basic-SAPLockUser/azuredeploy.json
Comment thread Solutions/SAP/Playbooks/Basic-SAPLockUser/azuredeploy.json
@v-atulyadav v-atulyadav merged commit 3cf44ec into Azure:master Apr 16, 2026
31 of 32 checks passed
@MartinPankraz MartinPankraz deleted the enhance-sap-user-block branch April 16, 2026 06:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants