-
Notifications
You must be signed in to change notification settings - Fork 55
❓ FAQ
Yes, you can run both versions of STAT in the same subscription. STATv1 will continue to work. However, STATv2 has improved performance and additional features you might want to consider.
There is no upgrade path. The existing playbooks will continue to function, but you will need to replace the STATv1 actions by STATv2 actions or create a new playbook from scratch that uses STATv2.
The connector is only visible for logic apps created in the same region as the connector.
During the deployment you are being asked to provide the Microsoft Defender for Cloud Apps URL (formally known as MCAS). You can find this URL from the Defender portal (https://security.microsoft.com) in the Settings section.
![image](https://private-user-images.githubusercontent.com/22434561/323795474-df8473ba-a6f5-4d07-becb-01285a190abb.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MjEzMzIxMTQsIm5iZiI6MTcyMTMzMTgxNCwicGF0aCI6Ii8yMjQzNDU2MS8zMjM3OTU0NzQtZGY4NDczYmEtYTZmNS00ZDA3LWJlY2ItMDEyODVhMTkwYWJiLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNDA3MTglMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjQwNzE4VDE5NDMzNFomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTk4ZDRjOWE5ZTNkMTgxZTFmOTBmMGMzMTUyYjVhNzhkZTkzNjMzOTZkZDgwNDgyODdjMTllYjMxMjVkMzNmNmEmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JmFjdG9yX2lkPTAma2V5X2lkPTAmcmVwb19pZD0wIn0.BrD33aWcpIEVACfKVlpJmUvpfC7_OtVbRE0PBMX7G1o)
Select Cloud apps and you will see the API URL in the About section.
![image](https://private-user-images.githubusercontent.com/22434561/323795693-82d1a714-8d79-4d6e-99db-fb640107b7db.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MjEzMzIxMTQsIm5iZiI6MTcyMTMzMTgxNCwicGF0aCI6Ii8yMjQzNDU2MS8zMjM3OTU2OTMtODJkMWE3MTQtOGQ3OS00ZDZlLTk5ZGItZmI2NDAxMDdiN2RiLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNDA3MTglMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjQwNzE4VDE5NDMzNFomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWNlZWFlOTlmYjM2ZTA5ZmIzMGUzMGM0OGEyMzg4ZjdjOTY4MDEwZmQ0N2UxM2Y1ZjdkOTE4NGIzM2RkYjU5ODMmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JmFjdG9yX2lkPTAma2V5X2lkPTAmcmVwb19pZD0wIn0.mKotoJ8yU9EggyWzeW5YPwmLvCFAHjMLLchHs2rMyXQ)
You can enter a bogus string in the wizard to validate the deployment. Note that you will then not be able to call the Microsoft Defender for Cloud Apps module.
When your Sentinel playbook is saved in a different resource group than your STATv2 deployment, the Logic App designer will prompt you for a function code before customizing your step:
![image](https://private-user-images.githubusercontent.com/22434561/337753360-347fef1c-fb65-465b-8fbd-cbe106ffd159.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MjEzMzIxMTQsIm5iZiI6MTcyMTMzMTgxNCwicGF0aCI6Ii8yMjQzNDU2MS8zMzc3NTMzNjAtMzQ3ZmVmMWMtZmI2NS00NjViLThmYmQtY2JlMTA2ZmZkMTU5LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNDA3MTglMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjQwNzE4VDE5NDMzNFomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWNmN2Q5MDMwNWNiMjExNjQwY2Y1NzNjOTg0MDFlNTI2M2Q0ZGMzYTQyYTU5ZGQyMjBkNDQ0MTAxNjJjODM5ZTAmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JmFjdG9yX2lkPTAma2V5X2lkPTAmcmVwb19pZD0wIn0.e9QYpJCfp7BmVMvuT6TQGdpaqWkk8dTUIudWqOUyC-s)
You can enter the name you want (it will be use to identify the connection of the connectors in the logic app code and saved as an API connection in your current resource group). For the code, you can find it in the STATv2 function resource under Overview > Functions tab > modules > :
![image](https://private-user-images.githubusercontent.com/22434561/337791575-d2c18b6a-14c0-40fe-b50f-03188ef89aed.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MjEzMzIxMTQsIm5iZiI6MTcyMTMzMTgxNCwicGF0aCI6Ii8yMjQzNDU2MS8zMzc3OTE1NzUtZDJjMThiNmEtMTRjMC00MGZlLWI1MGYtMDMxODhlZjg5YWVkLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNDA3MTglMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjQwNzE4VDE5NDMzNFomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWMxYWEwMWU5MGNhMGY5NGMxZGJiYmQ0YjhiZmRmNjBkMDk4Yzc4ODZmODFkN2UyOTlmZWI5YTkwYzVlMTVjYmYmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JmFjdG9yX2lkPTAma2V5X2lkPTAmcmVwb19pZD0wIn0.Wjq50B0dUddvLAsueP_iN6vbyzQprxzWgsdrEA0PLw8)
![image](https://private-user-images.githubusercontent.com/22434561/337790884-8748114d-7686-4de8-bdee-036720b3b5fa.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MjEzMzIxMTQsIm5iZiI6MTcyMTMzMTgxNCwicGF0aCI6Ii8yMjQzNDU2MS8zMzc3OTA4ODQtODc0ODExNGQtNzY4Ni00ZGU4LWJkZWUtMDM2NzIwYjNiNWZhLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNDA3MTglMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjQwNzE4VDE5NDMzNFomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPThiYjY1YjNjM2RhOGRhNThmMGZhYTY3YjJlNWM0ZDZiZWM3ZmYzMWU3N2E5OWY3ZGZhZDU4YjVkZGJlYzU2NmEmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JmFjdG9yX2lkPTAma2V5X2lkPTAmcmVwb19pZD0wIn0.7c2OEDTf0DtFaMSef08gmJEyfe1ozVCdmeedPir21kA)
You can copy the value of the key directly into your clipboard and then paste it in the Function code field of the connector. Note that once you have done that one time in your designer, you will no longer be prompted for future STATv2 calls for all playbooks located in the same resource group.