Manually or periodically mitigate accounts with account configuration risks.
Create Account Response playbooks to mitigate risks such as accounts with weak
authentication, accounts that increase your attack surface, and accounts with
excessive privileges.
ImportantTo create Account Response playbooks, you must have the Attack Surface Risk
Management entitlement enabled and configure one of the following required data
sources:
|
Procedure
- Go to .
- On the Playbooks tab, choose .
- On the Playbook Settings panel, select the Account risks type, specify a unique name for the playbook, and click Apply.
- On the Trigger Settings panel,
select the trigger type and click Apply.
-
Manual: Allows you to start the playbook execution by clicking the Run icon ()
-
Scheduled: Allows you to schedule the playbook to run daily, weekly, or monthly
-
- On the Target Settings panel,
select and configure the Target for the playbook and
click Apply.If you need to mitigate more than one risk type, you can add more than one target by using the add node () on the right of the Trigger node. The risk type for each target must be unique.
Important
To enable Security Playbooks to response to at-risk accounts, grant permission to access your Microsoft Entra ID data and Active Directory data in . - If you need to take actions when specific conditions are
met, configure the Condition node.
- Click the add node () on the right of the Target node and click Condition.
- Create a condition setting by specifying the
Parameter, Operator,
and Value.
-
IS: The condition is triggered if any of the values is matched
-
IS NOT: The condition is triggered if none of the values is matched
-
- If you need to configure multiple sets of
condition settings, click Add.The condition operator is evaluated using a logical AND.
- Click Apply.
- If you need to add more than one parallel Condition node, click the add node () on the right of the Target node.
- If you need to configure action settings for the
Condition node, add an
Action node by clicking the add node () on the right.For details, see Step 7.
- If you need to configure else-if conditions or
else actions, add an Else-If Condition or
Else Action node by clicking the add node
() under the
Condition node.For details, see Step 9.
- Configure actions by adding an
Action node.
- Click the add node () on the right of the Condition node and click Action.
- On the Action Settings panel, select
Generate CSV file or a
RESPONSE
action from the Action drop-down list.To configureRESPONSE
actions, you must grant Trend Micro permission to enforce the following user access policies on supported Identity and Access Management (IAM) systems:-
Disable User Account
-
Enable User Account
-
Force Sign Out
-
Force Password Reset
WARNING
If the Disable User Account action disables the account configured in Active Directory (on-premises) Connection Settings in Third-Party Integration, you will not be able to restore the disabled accounts. Trend Micro recommends requiring manual approval for this action. -
- Select whether to send a notification to request
manual approval to create general actions, and then configure the
notification settings if you require manual approval.
Note
Actions pending manual approval for over 24 hours expire and cannot be performed.SettingDescriptionNotification method-
Email: Sends an email notification to specified recipients
-
Webhook: Sends a notification to specified webhook channels
Subject prefixThe prefix that appears at the start of the notification subject lineRecipientsThe email addresses of recipientsThe field only appears if you select Email for Notification method.WebhookThe webhook channels to receive notificationsThe field only appears if you select Webhook for Notification method.Tip
To add a webhook connection, click Create channel in the drop-down list. -
- Click Apply.
- If you need to add more than one parallel action, use the add node () on the right of the Target or Condition node.
- Configure notification settings by adding the second
Action node.
- Click the add node () on the right of the first Action node and click Action.
- On the Action Settings panel, specify how to notify recipients of the playbook results.
- For email and webhook notifications, configure the
following settings.SettingDescriptionSubject prefixThe prefix that appears at the start of the notification subject lineRecipientsThe email addresses of recipientsThe field only appears if you select Email for Notification method.WebhookThe webhook channels to receive notificationsThe field only appears if you select Webhook for Notification method.
Tip
To add a webhook connection, click Create channel in the drop-down list. - For ServiceNow ticket notifications, configure the
following settings.SettingDescriptionTicket profileThe ServiceNow ticket profile to use
Tip
If you need to add a ticket profile, click Create ticket profile in the drop-down list.Ticket profile settingsThe ticket profile settings for the playbookSelecting a ticket profile automatically loads the settings. Changing the settings overrides the ticket profile for the playbook.-
Assignment group: The ServiceNow assignment group you want to assign the ticket to
-
Assigned to: The ServiceNow user you want to assign the ticket to
-
Short description: A short description of the ticket which displays in ServiceNow
-
- If you require manual approval for sending playbook results, follow
Step 7.c to configure the notification
settings.
Note
This setting is available only to ticket notification action. - Click Apply.
- Configure Else-If Conditions or
Else Actions if necessary.
- Click the add node () below the condition node and click Else-If Condition or Else Action.
- Configure a Condition node by following Step 6 or an Action node by following Step 7 or Step 8.
Note
-
The nodes that can be added by using an add node () vary depending on the preceding node. For example, an Action node can only be possibly followed by another Action node; a Condition node can be followed by an Action node or have an Else-If Condition or Else Action attached to it.
-
When a condition is false, the playbook performs the Else Action or checks if its Else-If Condition is met. If the Else-If Condition is met, the playbook continues to perform the corresponding Else Action.
-
Multiple Action nodes configured in a serial mode are taken sequentially.
- Enable the playbook by toggling the Enable control on.
- Click Save.The playbook appears on the Playbooks tab in the Security Playbooks app.