Which THREE conditions must be met for Microsoft Sentinel to automatically run a playbook on an incident?
Trap 1: The incident severity must be set to High or Critical
Incident severity is merely a condition that can be used in an automation rule, not a mandatory prerequisite. Automation rules can be configured to run on any severity, including Low or Medium, and severity itself is a dynamic property that might be changed by the rule. Therefore, restricting this to High or Critical is unnecessary and would incorrectly limit the rule's applicability.
Trap 2: The user must be signed in to the Azure portal
The execution of playbooks in Microsoft Sentinel is fully asynchronous and occurs in the background via Azure Logic Apps, independent of any interactive user session. The automation rule engine invokes the Logic App using its own identity or a managed identity, and there is no requirement for a user to be actively signed in to the Azure portal. Requiring an interactive sign-in would break the automation's ability to run unattended.
- A
The incident severity must be set to High or Critical
Why it fails: Incident severity is merely a condition that can be used in an automation rule, not a mandatory prerequisite. Automation rules can be configured to run on any severity, including Low or Medium, and severity itself is a dynamic property that might be changed by the rule. Therefore, restricting this to High or Critical is unnecessary and would incorrectly limit the rule's applicability.
- B
The playbook must have the Sentinel Responder role assigned
The Logic App that serves as a playbook must be granted the Microsoft Sentinel Responder role on the relevant Log Analytics workspace or resource group to obtain write permissions for incident management. This role enables the playbook to perform actions like changing incident status, adding comments, or assigning ownership; without this RBAC assignment the automation rule will fail to execute the playbook.
- C
The incident must be created by a scheduled or NRT analytics rule
Automation rules are evaluated only when an incident is created by a supported analytics rule, such as a scheduled query or an NRT rule that runs near real-time. Incidents created manually, via API, or from other sources do not trigger playbook actions because the incident creation event lacks the context and lineage that analytics rules provide. Thus, the playbook automation depends on the incident originating from an analytics rule.
- D
The user must be signed in to the Azure portal
Why it fails: The execution of playbooks in Microsoft Sentinel is fully asynchronous and occurs in the background via Azure Logic Apps, independent of any interactive user session. The automation rule engine invokes the Logic App using its own identity or a managed identity, and there is no requirement for a user to be actively signed in to the Azure portal. Requiring an interactive sign-in would break the automation's ability to run unattended.
- E
The playbook must be set to 'Enabled' on the automation rule
Within an automation rule, each playbook action has its own 'Enabled' toggle; the playbook will only run if this toggle is turned on. Additionally, the underlying Logic App in Azure must itself be in an enabled state. If either is disabled, the action is skipped during incident processing, so the rule must explicitly have the playbook enabled.