Skip to content

SecOps - 41203 - Custom data connectors are configured in Microsoft Sentinel for in-scope sources without a built-in connector - #1495

Merged
Thomas Detzner (tdetzner) merged 6 commits into
devfrom
SEC-41203
Aug 12, 2026
Merged

SecOps - 41203 - Custom data connectors are configured in Microsoft Sentinel for in-scope sources without a built-in connector#1495
Thomas Detzner (tdetzner) merged 6 commits into
devfrom
SEC-41203

Conversation

@Manoj-Kesana

Copy link
Copy Markdown
Collaborator

No description provided.

Manoj-Kesana added 2 commits August 10, 2026 18:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a new SecOps assessment (Test ID 41203) to evaluate whether Microsoft Sentinel workspaces have at least one customer-/partner-authored codeless (custom) data connector configured, and provides the accompanying markdown description for reporting/remediation context.

Changes:

  • Introduces Test-Assessment-41203 PowerShell test to enumerate Sentinel workspaces, query data connectors/definitions, classify “custom” connectors by publisher, and emit a summarized markdown table.
  • Adds Test-Assessment.41203.md narrative/remediation content for the new assessment.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.

File Description
src/powershell/tests/Test-Assessment.41203.ps1 New assessment implementation that queries Sentinel workspaces and evaluates presence of custom codeless connectors.
src/powershell/tests/Test-Assessment.41203.md New assessment documentation/remediation text and results placeholder.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/powershell/tests/Test-Assessment.41203.ps1
Comment thread src/powershell/tests/Test-Assessment.41203.ps1
Comment thread src/powershell/tests/Test-Assessment.41203.md Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@Manoj-Kesana Manoj Kesana (Manoj-Kesana) added the ready for review PR is ready for review and merging label Aug 11, 2026
@Manoj-Kesana
Manoj Kesana (Manoj-Kesana) marked this pull request as ready for review August 11, 2026 13:56

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Manoj Kesana (@Manoj-Kesana) Please, address my feedback.

Suggestion: Include inaccessible or unresolved workspace rows in the report. The current table is built only from confirmed onboarded workspaces, so an Investigate result does not show every workspace that caused it.

Comment thread src/powershell/tests/Test-Assessment.41203.ps1 Outdated
Comment thread src/powershell/tests/Test-Assessment.41203.ps1 Outdated
Comment thread src/powershell/tests/Test-Assessment.41203.ps1
Comment thread src/powershell/tests/Test-Assessment.41203.md Outdated
@Manoj-Kesana Manoj Kesana (Manoj-Kesana) removed the ready for review PR is ready for review and merging label Aug 11, 2026
@Manoj-Kesana
Manoj Kesana (Manoj-Kesana) marked this pull request as draft August 11, 2026 18:15
@Manoj-Kesana Manoj Kesana (Manoj-Kesana) added the ready for review PR is ready for review and merging label Aug 12, 2026
@Manoj-Kesana
Manoj Kesana (Manoj-Kesana) marked this pull request as ready for review August 12, 2026 03:20

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@tdetzner
Thomas Detzner (tdetzner) merged commit 480e41e into dev Aug 12, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready for review PR is ready for review and merging

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants