Best practices when finetuning TI Map rules in Sentinel.

Shahani Silva 20 Reputation points
2025-04-30T07:36:13.2833333+00:00

Hi All,

Are there any best practices when configuring or finetuning the TI rules in Sentinel? We have the rules enabled now ootb and they are generating a lot of noise.

Can I know how organizations usually monitor these rules? Are they fine-tuned to monitor only allowed/pass events for example? Are there any recommended changes when fine tuning this rule?

Is there a recommended way to monitor this rule?

Thanks and regards

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,268 questions
0 comments No comments
{count} votes

Accepted answer
  1. Clive Watson 7,636 Reputation points MVP
    2025-04-30T09:57:00.7066667+00:00

    We are an MSSP and I'm sure these are the ones we spend a high proportion of our time on to fine-tune, but we have to make them work across 100s of customers, which may differ for your scenario.

    I'd just say that you will probably need a watchlist for exclusions or have a playbook to handle exclusions, depending where you choose to do the optimization. We don't have a single strategy (apart from using a watchlist) as many needed bespoke work to fine-tune.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.