Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
07Create detections and perform investigations using Microsoft Sentinel8 modules · 56 units · Analytics, automation, playbooks, incidents, UEBA, ASIM, workbooks, and content management0/56 units complete
Learning path 07 · Create detections and perform investigations using Microsoft Sentinel

8 modules · 56 units · Analytics, automation, playbooks, incidents, UEBA, ASIM, workbooks, and content management

0%

Study focus

Detection and response

Build analytics rules, automate triage, run playbooks, and manage security incidents.

Analytics and content

Apply UEBA, ASIM, KQL, workbooks, Content Hub solutions, and repository-based deployment.

8 modules · 56 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

02

Module 2

Automation in Microsoft Sentinel

Focus: automation triggers, conditions, ordered actions, expiration, and incident orchestration.
0/5
01 / 05Introduction

Automation reduces repetitive triage and coordinates consistent incident handling. Automation rules manage incident properties and invoke playbooks for broader response.

Official moduleAutomation objectives
02 / 05Understand automation options

Rules trigger on incident creation or update, or alert creation. Conditions can inspect provider, rule, severity, status, tags, and owner. Native actions assign owners, change status or severity, add tags, and run playbooks. Use playbooks for APIs, enrichment, notification, ticketing, or containment.

Official lessonRules versus playbooks
03 / 05Create automation rules
  1. Select a trigger and scoped conditions.
  2. Add actions in the intended order.
  3. Set order relative to other rules.
  4. Optionally define expiration.
  5. Enable, test, and monitor.

Order matters because an earlier rule can change properties evaluated by a later rule.

Official lessonCreate and prioritize rules
04 / 05Module assessment

Review triggers, conditions, native actions, playbook execution, ordering, expiration, and the boundary between Sentinel automation and Logic Apps.

Official assessmentAutomation knowledge check
05 / 05Summary and resources

Use explicit automation rules for deterministic changes and governed playbooks when a workflow crosses services or requires complex logic.

Official moduleSummary and resources
End of learning pathCreate detections and perform investigations using Microsoft Sentinel