Sentinel analytics rules have _SentinelHealth() for failure monitoring. Defender XDR custom detections have... nothing. No table, no native alerting. Just the GUI. How is everyone catching these silent detection failures? @msftsecurity#MicrosoftDefender
Sentinel Analytics: Why can't I add UserPrincipalName to Account type directly? UserPrincipalName used by Defender, but Sentinel makes it so difficult. Is splitting the preferred solution? #MicrosoftSentinel https://t.co/OjRUGuNrBi