Skip to content

Microsoft Sentinel: automation rules, playbooks and workbooks

Automate incident handling safely with automation rules (triggers, conditions, actions, order and expiration) and playbooks built on Azure Logic Apps, with the permissions they need. Build and share workbooks from Content hub templates for monitoring and reporting.

Level
Intermediate
Length
About 50 minutes
Contents
3 lessons · final exam
Status
Published · updated 1 Oct 2026
  • Microsoft Sentinel

Skills you'll practise

  • Choose the right automation rule trigger (incident created, incident updated or alert created) for a scenario
  • Predict how automation rule order and conditions affect which rules run
  • Grant the permissions Microsoft Sentinel needs to run playbooks and assign the right roles to people
  • Decide whether a task needs only an automation rule or also a playbook, and explain the cost implication
  • Create a workbook from a template and explain what is saved and who can see it

Course outline

  1. 1.Automation rulesLesson · 17 min
  2. 2.PlaybooksLesson · 17 min
  3. 3.WorkbooksLesson · 16 min
  4. 4.Microsoft Sentinel: automation rules, playbooks and workbooks: knowledge checkKnowledge check · 14 questions
  5. 5.Firewall detections went quietScenario
  6. 6.Final exam9 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.