Introducing Microsoft Sentinel Automation
In the previous chapter, we introduced a few SOAR tools and some of the main features we can utilize in our day-to-day operations. We showcased what incident management, investigation, automation, and reporting look like in real tools and offered some directions on how to utilize them.
This chapter will focus on Microsoft Sentinel automation, and we will dive deep into each element when working with it. We will discuss automation rules, playbooks, their elements and permissions, and prepare you for hands-on examples that will be covered in Chapters 6 to 8.
In this chapter, we will discuss the following:
- The purpose of Microsoft Sentinel automation
- All about automation rules
- All about playbooks
- Monitoring automation rules and playbook health