Skip to main content
Question

Any Drawbacks with SecOps SOAR based integration for MDE Alerts Ingestion

  • October 9, 2026
  • 1 reply
  • 22 views

soaruser
Forum|alt.badge.img+6

Hi,

Can anyone explain about the SOAR based approach to ingest alerts from MDE to SecOps SOAR instead SecOps SIEM? 
 

Does anyone faced any challenges? 
Which connector I should use? Microsoft Graph Security

1 reply

cmorris
Staff
Forum|alt.badge.img+17
  • Staff
  • October 9, 2026

You would use the MS 365 Incidents Connector - 

The connector will ingest the alerts directly into the SOAR, as opposed to having them in SIEM and using the passthrough rule set to get them as alerts