Skip to content

Microsoft Sentinel: analytics rules, incidents and triage

How Microsoft Sentinel turns data into alerts and incidents: the analytics rule types, the settings of a scheduled rule (schedule, lookback, threshold, event and alert grouping, entity mapping), and how to triage, investigate, classify and close incidents, including handling false positives with automation rules or query exceptions.

Level
Intermediate
Length
About 55 minutes
Contents
3 lessons · final exam
Status
Published · updated 1 Oct 2026
  • Microsoft Sentinel

Skills you'll practise

  • Distinguish scheduled, NRT, anomaly and Microsoft security rules and the specialized rule templates
  • Configure a scheduled rule's schedule, lookback, threshold, event grouping, entity mapping and alert grouping
  • Triage an incident: take ownership, set status, review entities, timeline and similar incidents, and record evidence
  • Close an incident with the correct classification and a comment that explains the evidence
  • Choose between an automation rule exception and a query or watchlist exception for a false positive

Course outline

  1. 1.Analytics rule typesLesson · 15 min
  2. 2.Building a scheduled ruleLesson · 20 min
  3. 3.Triage, classification and false positivesLesson · 20 min
  4. 4.Microsoft Sentinel: analytics rules, incidents and triage: knowledge checkKnowledge check · 14 questions
  5. 5.MFA prompts, then a sign-in from abroadScenario
  6. 6.Final exam8 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.