StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 1: Manage a security operations environment

Automation: automation rules vs Logic Apps playbooks, triggers, incident tasks; watchlists, workbooks, UEBA and threat intelligence connectors

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Sentinel has two automation layers. Automation rules are lightweight, built-in rules that run when incidents are created or updated, or when alerts are created. They can change status, severity or owner, add tags, add incident tasks and run playbooks. Rules have an order number (lower runs first), an optional expiration date, and conditions such as analytics rule name, severity, tag or entity values. They are ideal for triage: assign all phishing incidents to the email team, raise severity when a VIP account is involved, or close known-benign incidents automatically, perhaps for a limited time while a rule is fixed.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan