StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 1: Manage a security operations environment

Analytics rules: scheduled, near-real-time (NRT), Microsoft incident creation, anomaly and Fusion; entity mapping, alert grouping, custom details

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Analytics rules are how Sentinel turns data into alerts and incidents. An alert is a single detection; an incident groups one or more alerts into the unit of work an analyst investigates. The exam expects you to know each rule type, when to use it, and the settings that make its alerts useful to analysts. You create rules under Configuration, Analytics, often starting from a template installed by a Content hub solution. Scheduled rules are the workhorse. You write a KQL query, choose how often it runs (query frequency) and how far back it looks (lookback), and set a threshold, such as generate an alert when the query returns more than zero results. The lookback should usually be at least as long as the frequency so events are not missed, and a little overlap covers ingestion delay. You also choose event grouping: one alert for all results, or one alert per result row. Near-real-time (NRT) rules run about every minute over a very short lookback, for high-priority detections where minutes matter, such as a break-glass account signing in. NRT rules have more limits on query complexity than scheduled rules.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan