Would it be easier to use a custom phantom playbook to Add a user to a specific AD group from an event trigger, instead of creating a custom App in splunk using the App builder?
Thank you for the question. I suggest you post in the Phantom threads here: https://community.splunk.com/t5/Splunk-Phantom/bd-p/security-phantom for a quicker response. This section is focused on the DevOps/Observability Suite.
View solution in original post