Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
07Create detections and perform investigations using Microsoft Sentinel8 modules · 56 units · Analytics, automation, playbooks, incidents, UEBA, ASIM, workbooks, and content management0/56 units complete
Learning path 07 · Create detections and perform investigations using Microsoft Sentinel

8 modules · 56 units · Analytics, automation, playbooks, incidents, UEBA, ASIM, workbooks, and content management

0%

Study focus

Detection and response

Build analytics rules, automate triage, run playbooks, and manage security incidents.

Analytics and content

Apply UEBA, ASIM, KQL, workbooks, Content Hub solutions, and repository-based deployment.

8 modules · 56 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

03

Module 3

Threat response with Microsoft Sentinel playbooks

Focus: Logic Apps SOAR, Sentinel triggers, permissions, and real-time or on-demand execution.
0/7
01 / 07Introduction

Playbooks are Logic Apps workflows for enrichment, notification, ticketing, containment, and remediation beyond native incident-property changes.

Official moduleSOAR objectives
02 / 07Exercise - Create a Microsoft Sentinel playbook

Deploy Sentinel and test resources, connect Azure Activity, and create an NRT rule for successful VM deletion to supply incidents for the playbook exercise.

Official exercisePrepare analytics and test data
03 / 07What are Microsoft Sentinel playbooks?

A playbook has a Logic Apps trigger followed by conditions and actions. Sentinel triggers operate on incidents, alerts, or entities; connectors call Microsoft and third-party services. Prefer managed identities and least-privilege RBAC over personal credentials.

Official lessonPlaybook architecture
04 / 07Trigger a playbook in real-time

Use an automation rule to run an incident- or alert-triggered playbook. Grant Sentinel permission to run the Logic App and grant its identity only required permissions. Design for idempotency, retries, rate limits, partial failure, logging, and visible incident comments.

Official lessonAutomated execution
05 / 07Run playbooks on demand

Run eligible playbooks manually from incidents, alerts, or entities when analyst judgment should precede response. This suits enrichment and high-impact containment that should not be automatic.

Official lessonManual response
06 / 07Exercise - Create a Microsoft Sentinel playbook

Create an incident-triggered Logic App, add response actions, authorize connections, attach it through automation, generate a test incident, and inspect run history.

Official exerciseBuild and test a playbook
07 / 07Summary

Safe SOAR requires least privilege, explicit triggers, controlled automation rules, resilient workflows, and visible execution results.

Official moduleSummary and assessment
End of learning pathCreate detections and perform investigations using Microsoft Sentinel