Skip to content

Commit 47f4d43

Browse files
committed
USX migration docs for automation
1 parent 03fe48d commit 47f4d43

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

articles/sentinel/automation/automation.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn about Microsoft Sentinel security orchestration, automation,
44
ms.topic: conceptual
55
author: batamig
66
ms.author: bagol
7-
ms.date: 02/12/2025
7+
ms.date: 04/28/2025
88
appliesto:
99
- Microsoft Sentinel in the Microsoft Defender portal
1010
- Microsoft Sentinel in the Azure portal
@@ -68,6 +68,8 @@ After onboarding your Microsoft Sentinel workspace to the Defender portal, note
6868
| **Running playbooks manually on demand** | The following procedures aren't currently supported in the Defender portal: <br><li>[Run a playbook manually on an alert](run-playbooks.md#run-a-playbook-manually-on-an-alert)<br><li>[Run a playbook manually on an entity](run-playbooks.md#run-a-playbook-manually-on-an-entity) |
6969
| **Running playbooks on incidents requires Microsoft Sentinel sync** | If you try to run a playbook on an incident from the Defender portal and see the message *"Can't access data related to this action. Refresh the screen in a few minutes."* message, this means that the incident isn't yet synchronized to Microsoft Sentinel. <br><br>Refresh the incident page after the incident is synchronized to run the playbook successfully. |
7070
| **Incidents: Adding alerts to incidents / <br>Removing alerts from incidents** | Since adding alerts to, or removing alerts from incidents isn't supported after onboarding your workspace to the Defender portal, these actions are also not supported from within playbooks. For more information, see [Capability differences between portals](../microsoft-sentinel-defender-portal.md#capability-differences-between-portals). |
71+
|**Microsoft Defender XDR integration in multiple workspaces**|If you've integrated XDR data with more than one workspace in a single tenant, the data will now only be ingested into the primary workspace in the Defender portal. Transfer automation rules to the relevant workspace to keep them running.|
72+
|**Automation and Correlation engine** |The correlation engine may correlate Sentinel and XDR alerts, leading to alerts that you didn't anticipate being targeted for automation. |
7173

7274
## Related content
7375

0 commit comments

Comments
 (0)