Security
Microsoft Sentinel
Microsoft Sentinel
Microsoft Sentinel: Setup and permissions
Manual handoffs between security operations teams and IT teams often slow down incident response, as information moves across separate security and ITSM tools. This results in lost context, duplicated updates, limited visibility, and critical actions that depend on manual coordination.
The Atomicwork–Microsoft Sentinel integration reduces this friction by bringing Sentinel incidents, alerts, and threat intelligence directly into ITSM workflows, enabling security and IT teams to work from a single system of record while preserving native controls and context.
Capabilities
IT teams can automate Microsoft Sentinel operations directly within Atomicwork workflows, including:
- Viewing and retrieving Sentinel incidents and incident details
- Creating, updating, and synchronizing incidents between Atomicwork and Sentinel
- Fetching alerts associated with Sentinel incidents for investigation context
- Managing Threat Intelligence (TI) indicators such as IPs, URLs, domains, and file hashes
- Appending or replacing tags on threat indicators for classification and enrichment
- Retrieving threat indicator metrics for reporting and analytics
- Discovering Sentinel subscriptions, resource groups, and workspaces for correct scoping
This enables end-to-end automation for security and IT collaboration, including SOC-to-ITSM incident flow, threat intelligence management, SLA enforcement, and security-driven change and remediation workflows.
Permissions
To set up the integration, you need the following roles:
