Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium

A security operations team wants to receive real-time notifications via Microsoft Teams whenever a high-severity incident is created in Microsoft Sentinel. What is the most efficient way to configure this type of notification?

  1. AUse a custom analytics rule to directly send a webhook to Teams.
  2. BSet up an email notification from Sentinel and forward it to a Teams channel email address.
  3. CConfigure an Azure Logic App (Playbook) triggered by Sentinel incident creation to post to Teams.
  4. DManually create a Teams post for each incident.
Show answer & explanation

Correct answer: C. Configure an Azure Logic App (Playbook) triggered by Sentinel incident creation to post to Teams.

The most efficient and robust way to send real-time notifications to Microsoft Teams from Sentinel incidents is by using an Azure Logic App (a Sentinel Playbook). This allows for rich customization, reliable integration, and automated triggering upon incident creation.

Why the other options are wrong

  • A. While an analytics rule *can* trigger a webhook, a Logic App provides a more managed, feature-rich, and easily maintainable solution for integrating with Teams, handling authentication and complex message formatting.
  • B. While possible, forwarding emails to Teams is less reliable and offers less control over the message format and content compared to a dedicated Logic App.
  • D. Manually creating posts is inefficient and prone to human error, not an automated solution.

Microsoft Sentinel Playbooks (Logic Apps)

Automated, scalable, serverless workflows built on Azure Logic Apps that can be triggered by Sentinel incidents or alerts to perform response actions.

  • Integrate with various services, including Microsoft Teams, ServiceNow, etc.
  • Can perform complex actions like enriching incidents, blocking IPs, or sending notifications.
  • Run automatically via Sentinel Automation Rules.

Memory trick: Playbooks are the 'robot assistants' that take action when an incident happens.

More Mitigate threats using Microsoft Sentinel questions