Reader small image

You're reading from  Microsoft 365 Security, Compliance, and Identity Administration

Product typeBook
Published inAug 2023
PublisherPackt
ISBN-139781804611920
Edition1st Edition
Right arrow
Author (1)
Peter Rising
Peter Rising
author image
Peter Rising

Peter Rising has over 25 years' experience in IT. He has worked for several IT solutions providers and private organizations in a variety of technical and leadership roles, with a focus on Microsoft technologies. Since 2014, Peter has specialized in the Microsoft 365 platform, focusing most recently on security and compliance in his role as a Consulting Services Manager for Insight. Peter is heavily involved in the wider Microsoft community and has been recognized by Microsoft as an MVP. He holds several Microsoft certifications, including MCSE: Productivity; Microsoft 365 Certified: Enterprise Administrator Expert; and Microsoft 365: Cybersecurity Architect Expert.
Read more about Peter Rising

Right arrow

Configuring playbooks in Microsoft Sentinel

In Microsoft Sentinel, playbooks are collections of responses and actions that can be run like a routine. Playbooks automate and orchestrate threat responses and can be integrated with other systems, both internal and external. They can be configured to run manually or automatically in response to specific alerts or incidents. An example of an automated trigger for a playbook is an automation rule.

Automation rules enable users to centrally manage incident automation. This includes the ability to assign playbooks to incidents and automate responses for multiple analytics rules at once. Additionally, you can automatically tag, assign, or close incidents without requiring a playbook. You can also control the order of the actions executed.

Playbooks are based on Azure Logic Apps. Microsoft Sentinel can leverage the following logic app types:

  • Consumption: This is the more classic Azure Logic Apps experience
  • Standard: This is...
lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
Microsoft 365 Security, Compliance, and Identity Administration
Published in: Aug 2023Publisher: PacktISBN-13: 9781804611920

Author (1)

author image
Peter Rising

Peter Rising has over 25 years' experience in IT. He has worked for several IT solutions providers and private organizations in a variety of technical and leadership roles, with a focus on Microsoft technologies. Since 2014, Peter has specialized in the Microsoft 365 platform, focusing most recently on security and compliance in his role as a Consulting Services Manager for Insight. Peter is heavily involved in the wider Microsoft community and has been recognized by Microsoft as an MVP. He holds several Microsoft certifications, including MCSE: Productivity; Microsoft 365 Certified: Enterprise Administrator Expert; and Microsoft 365: Cybersecurity Architect Expert.
Read more about Peter Rising