Response automation for Microsoft Sentinel built as a Logic Apps workflow, triggered manually or by an automation rule to do things like block IPs, open tickets or assign incidents. Launching one directly from an analytics rule is retired.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Playbook in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
- Logic Apps
Low-code Azure service for building automated workflows from triggers, actions and connectors, used for things like integrating systems or sending approval emails.
- Foundry workflows
Preview Foundry feature that orchestrates agents and logic in a fixed, declarative order, supporting variables, if/else branches and human-in-the-loop steps. Workflows are being retired on 1 December 2026 and Agent Framework replaces them.
- Automation rule
Microsoft Sentinel rule triggered when an incident or alert from any source is created or updated, used to centrally set status, assign owners, apply tags and launch playbooks.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- Analytics rule
KQL-based detection in Microsoft Sentinel that searches ingested data, generates alerts and bundles them into incidents. Rules identify threats but do not fix them.
Related terms
- Integration profiles
Hold the base URL, credentials and authentication method an AI-generated playbook needs to reach an outside API. You can't edit the URL or authentication method after the profile exists.
- Microsoft Sentinel Automation Contributor
An Azure built-in role given to the Microsoft Sentinel service account on the resource group holding a playbook, so that automation rules are able to trigger it. It has no other purpose and should not be assigned to users.
- Playbook Generator
For Sentinel workspaces in the Defender portal, you chat with an AI coding agent in Visual Studio Code and it produces a Python playbook, which uses integration profiles to call outside APIs.