{
  "Name": "Microsoft Entra ID Protection",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Workbooks/Images/Logos/Entra-ID-protection_logo.svg\"width=\"75px\" height=\"75px\">",
  "Description": "The [Microsoft Entra ID Protection](https://docs.microsoft.com/azure/active-directory/identity-protection/overview-identity-protection) solution for Microsoft Sentinel allows you to ingest Security alerts reported in Microsoft Entra ID Protection for risky users and events in Microsoft Entra ID.",
  "Data Connectors": [
    "Data Connectors/template_AzureActiveDirectoryIdentityProtection.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/CorrelateIPC_Unfamiliar-Atypical.yaml"
  ],
  "Playbooks": [
    "Playbooks/Confirm-EntraIDRiskyUser/alert-trigger/azuredeploy.json",
    "Playbooks/Confirm-EntraIDRiskyUser/incident-trigger/azuredeploy.json",
    "Playbooks/Dismiss-EntraIDRiskyUser/Dismiss-EntraIDRisky-Useralert-trigger/azuredeploy.json",
    "Playbooks/Dismiss-EntraIDRiskyUser/Dismiss-EntraIDRisky-Userincident-trigger/azuredeploy.json",
    "Playbooks/IdentityProtection-TeamsBotResponse/azuredeploy.json"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Microsoft Entra ID Protection",
  "Version": "3.0.4",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "StaticDataConnectorIds": [
    "AzureActiveDirectoryIdentityProtection"
  ]
}