Manage a security operations environment
Defender XDR and Sentinel Automation
CoreRoute security signals to people and workflows, control endpoint automation, and make response actions predictable at the correct scope.
Aligned to SC-200 skills measured as of July 28, 2026; product behavior verified September 18, 2026.
Why this matters
Automation can shorten containment from hours to seconds, but only when notification, investigation, approval, and execution boundaries are understood. A broad rule or overprivileged playbook can amplify a mistake across the tenant.
Must Know
- Defender XDR notification rules route incidents, actions, and threat-analytics updates; receiving an email is not a containment action.
- Alert tuning should identify a stable benign condition while preserving the same signal in other devices, users, and contexts.
- Defender for Endpoint advanced features enable tenant capabilities such as live response; device groups and RBAC limit who can use them and where.
- Custom data collection rules select supported endpoint event types, conditions, a Sentinel workspace, and devices targeted through dynamic tags.
- Use ASR audit mode and a representative pilot before block mode, then create only narrow, evidence-backed exclusions.
- Automated investigation gathers and evaluates evidence; Action center records remediation actions that may require approval.
- Sentinel automation rules evaluate incident conditions and perform ordered incident actions. Playbooks provide executable Logic Apps workflows and authenticated connectors.
Compare and Distinguish
- Notification rules inform people; automation rules change incident handling; playbooks execute Logic Apps workflows.
- Automated investigation and response examines evidence and can remediate; automatic attack disruption contains an active attack across supported signals.
- Device groups define endpoint scope; roles define analyst permissions; automation levels define permitted remediation behavior.
Scenario examples
- Scenario: High-confidence incidents need a Teams message and device isolation workflow. Think: Let a Sentinel automation rule invoke a playbook; do not confuse an email notification with containment.
- Scenario: A line-of-business app breaks under an ASR rule. Think: validate in audit, inspect events, and use the narrowest justified exclusion.
- Scenario: Tier 1 analysts may investigate one device group but cannot approve broad remediation. Think: align RBAC, device-group scope, and automation level.
Exam traps
- A notification rule informs a recipient; it does not run a response workflow.
- A device group, role assignment, and automation level solve different parts of endpoint scope.
- Automatic attack disruption contains supported high-confidence attacks; it does not prove eradication or make recovery review optional.
- A playbook that runs for its author can still fail under an automation rule if Sentinel or a connector lacks authorization.
Key takeaways
- Separate alert delivery, incident orchestration, and executable response.
- Pilot prevention changes, constrain automation, and verify the resulting action record.
- Treat automated containment as the start of validated remediation and recovery.
How it works
- Defender XDR correlates alerts into incidents and records automated or approved remediation in Action center.
- Sentinel evaluates automation-rule conditions in order; a rule can update the incident or invoke an authorized Logic Apps playbook.
Objects and administrative surfaces
- Microsoft Defender portal — XDR notifications, incidents, endpoint settings, device groups, and automated actions.
- Microsoft Sentinel — automation rules associated with incidents and playbooks implemented as Azure Logic Apps.
- Endpoint security policy — ASR and other device controls deployed to the intended device population.
When to use it
- Use Defender settings for endpoint features, alert tuning, device groups, and XDR notification categories.
- Use Sentinel automation for incident orchestration and a playbook when response needs executable connectors or external systems.
Security and governance implications
- Grant responders only the device groups and actions needed for their duties.
- Review high-impact automation, protect connector identities, and preserve the action history for audit.
Troubleshooting signals
- For a failed playbook, check Sentinel authorization to the Logic App and each connector identity.
- For unexpected endpoint remediation, trace device-group membership, precedence, automation level, and Action center source.
More detail
- Defender XDR notification rules route incidents, actions, and threat-analytics updates; receiving an email is not a containment action.
- Alert tuning should identify a stable benign condition while preserving the same signal in other devices, users, and contexts.
- Defender for Endpoint advanced features enable tenant capabilities such as live response; device groups and RBAC limit who can use them and where.
- Custom data collection rules select supported endpoint event types, conditions, a Sentinel workspace, and devices targeted through dynamic tags.
- Use ASR audit mode and a representative pilot before block mode, then create only narrow, evidence-backed exclusions.
- Automated investigation gathers and evaluates evidence; Action center records remediation actions that may require approval.
- Sentinel automation rules evaluate incident conditions and perform ordered incident actions. Playbooks provide executable Logic Apps workflows and authenticated connectors.
Ready for the quiz?
- When is an automation rule sufficient, and when is a playbook required?
- What determines the effective automation level for a device in overlapping groups?
- Which evidence would justify reversing an automatic disruption action?
Related objectives
- D1.1.S1 — Configure email notifications in Microsoft Defender XDR, including incidents, actions, and threat analytics
- D1.1.S2 — Configure alert notifications in Microsoft Defender XDR, including tuning, suppression, and correlation
- D1.1.S3 — Configure Microsoft Defender for Endpoint advanced features
- D1.1.S4 — Configure rules settings in Microsoft Defender for Endpoint
- D1.1.S5 — Configure custom data collection in Microsoft Defender for Endpoint
- D1.1.S6 — Configure security policies for Microsoft Defender for Endpoint, including attack surface reduction (ASR) rules
- D1.1.S7 — Manage automated investigation and response capabilities in Microsoft Defender XDR
- D1.1.S8 — Configure automatic attack disruption in Microsoft Defender XDR
- D1.1.S9 — Configure and manage device groups, permissions, and automation levels in Microsoft Defender for Endpoint
- D1.1.S10 — Create and configure automation rules in Microsoft Sentinel
- D1.1.S11 — Create and configure Microsoft Sentinel playbooks