{
  "Name": "Global Secure Access",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/gsa.svg\" width=\"75px\" height=\"75px\">",
  "Description": "[Global Secure Access](https://aka.ms/GlobalSecureAccess) is a [domain solution](https://learn.microsoft.com/en-us/azure/sentinel/sentinel-solutions-catalog#domain-solutions) and does not include any data connectors. The content in this solution requires one of the product solutions below.\n\n**Prerequisite:**\n\nInstall one or more of the listed solutions to unlock the value provided by this solution.\n1. Microsoft Entra ID \n\n**Underlying Microsoft Technologies used:**\n\nThis solution depends on the following technologies, and some of these dependencies may either be in Preview state or might result in additional ingestion or operational costs:\n1. Product solutions as described above\n",
  "WorkbookBladeDescription": "This Microsoft Sentinel Solution installs workbooks. Workbooks provide a flexible canvas for data monitoring, analysis, and the creation of rich visual reports within the Azure portal. They allow you to tap into one or many data sources from Microsoft Sentinel and combine them into unified interactive experiences.",
  "AnalyticalRuleBladeDescription": "This solution installs the following analytic rule templates. After installing the solution, create and enable analytic rules in the Manage solution view.",
  "Workbooks": [
    "Workbooks/GSAM365EnrichedEvents.json",
    "Workbooks/GSANetworkTraffic.json",
    "Workbooks/GSAMCPInsights.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/Identity - AfterHoursActivity.yaml",
    "Analytic Rules/SWG - Abnormal Deny Rate.yaml",
    "Analytic Rules/SWG - Abnormal Port to Protocol.yaml",
    "Analytic Rules/SWG - Source IP Port Scan.yaml",
    "Analytic Rules/GSA - TI Domain Entity.yaml",
    "Analytic Rules/GSA - TI IP Entity.yaml",
    "Analytic Rules/GSA - TI URL Entity.yaml"
  ],
  "Hunting Queries": [],
  "BasePath": "C:\\git\\Azure-Sentinel\\Azure-Sentinel\\Solutions\\Global Secure Access",
  "Version": "3.0.4",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "StaticDataConnectorIds": [
    "AzureActiveDirectory"
  ]
}
