Forum Discussion
Cristian Calinescu
Nov 05, 2019Brass Contributor
Adding playbooks to Microsoft Security out-of-the-box alert rule templates
Hi all, I am trying to find a way to attach a playbook to the default Microsoft Security alert rules in Azure Sentinel. I am referring to the rules that automatically create Azure Sentinel incidents...
Ofer_Shezaf
Microsoft
Jul 16, 2020pemontto : the feature is currently in private preview.
Manvie
Jan 08, 2021Copper Contributor
Ofer_Shezaf Do you have an update on the progress for this feature ?
Thanks
- Ofer_ShezafJan 10, 2021
Microsoft
Manvie : still in private preview, I hope we are getting closer to going public. We made major changes based on private preview input.
- Asaad_MoosaAug 27, 2021Copper Contributor
Ofer_Shezaf any update on this please?
- GaryBusheyAug 27, 2021Bronze Contributor
Asaad_Moosa Azure Sentinel Automation is available to everyone. You can create a playbook that uses the Azure Sentinel incident trigger and then create an automation rule that can be run when the rule creates an incident.
https://docs.microsoft.com/en-us/azure/sentinel/automate-incident-handling-with-automation-rules