Workarounds for Azure Sentinel SIR Closure

designitsecure
Tera Expert

Hello,

 

Has anyone implemented a workaround to have Sentinel close SIR incidents since the integration is not bi-directional in this regard?

 

Thanks!

10 REPLIES 10

sach1
Tera Guru

A new property has been introduced in June 2025 release to poll closed incidents.

Microsoft Azure Sentinel - Incident Ingestion Integration for Security Operations release notes