Microsoft Sentinel: analytics rules, incidents and triage
How Microsoft Sentinel turns data into alerts and incidents: the analytics rule types, the settings of a scheduled rule (schedule, lookback, threshold, event and alert grouping, entity mapping), and how to triage, investigate, classify and close incidents, including handling false positives with automation rules or query exceptions.
- Level
- Intermediate
- Length
- About 55 minutes
- Contents
- 3 lessons · final exam
- Status
- Published · updated 1 Oct 2026
- Microsoft Sentinel
Skills you'll practise
- Distinguish scheduled, NRT, anomaly and Microsoft security rules and the specialized rule templates
- Configure a scheduled rule's schedule, lookback, threshold, event grouping, entity mapping and alert grouping
- Triage an incident: take ownership, set status, review entities, timeline and similar incidents, and record evidence
- Close an incident with the correct classification and a comment that explains the evidence
- Choose between an automation rule exception and a query or watchlist exception for a false positive
Course outline
- 1.Analytics rule typesLesson · 15 min
- 2.Building a scheduled ruleLesson · 20 min
- 3.Triage, classification and false positivesLesson · 20 min
- 4.Microsoft Sentinel: analytics rules, incidents and triage: knowledge checkKnowledge check · 14 questions
- 5.MFA prompts, then a sign-in from abroadScenario
- 6.Final exam8 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- Microsoft Learn: Threat detection in Microsoft Sentinel (analytics rule types)
- Microsoft Learn: Scheduled analytics rules in Microsoft Sentinel
- Microsoft Learn: Investigate Microsoft Sentinel incidents in depth
- Microsoft Learn: Investigate incidents with Microsoft Sentinel (closing and classification)
- Microsoft Learn: Handle false positives in Microsoft Sentinel
- Microsoft Learn: Automate threat response in Microsoft Sentinel with automation rules
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.