Your organization uses Microsoft Sentinel for SIEM. You receive an alert that a user account was compromised. You need to automatically disable the user's access across all cloud apps (SaaS) and reset their password. What should you use?
Playbooks can automate actions like disabling user and resetting password.
Why this answer
Option B is correct because Microsoft Sentinel can use automation rules with playbooks (Power Automate or Logic Apps) to trigger actions like disabling a user and resetting password in Microsoft Entra ID. Option A is wrong because manual response is not automated. Option C is wrong because Microsoft Defender for Cloud Apps can block access but not reset passwords.
Option D is wrong because Microsoft Intune manages devices, not user accounts.