Microsoft Sentinel
Incidents and response

Create Incident Tasks in Microsoft Sentinel using Automation Rules

In brief

The article was refreshed with clearer wording, a new introductory step description, updated links, and reorganized related content. Metadata and the publication date were also updated.

What Defender admins need to know

No administrator action is required. The revised guidance makes task automation procedures and related Sentinel resources easier to find.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Create incident tasksIncident Tasks in Microsoft Sentinel using automation rulesAutomation Rules description: Use automation rules to automatically add incident task lists in Microsoft Sentinel and standardize analyst response workflows across incidents. ms.topic: how-to ms.author: monaberdugo author: mberdugo ms.reviewer: sshuster ms.date: 06/15/07/01/2026 appliesto: - Microsoft Sentinel in the Microsoft Defender portal - Microsoft Sentinel in the Azure portal ms.collection: usx-security ai-usage: ai-assisted ms.custom: msecd-doc-authoring-10141016

Another suchThe scenario of adding tasks to incidents with playbooks is addressed in the following companion article:

Another article, atThe Work with tasks article addresses the following links, addresses scenarios that apply more to SOC analysts:

The Microsoft Sentinel Responder role is required to create automation rules and to view and edit incidents, both of which are necessary to add, view, and edit tasks.

View automation rules with incident task actions

In the Automation page, you can filter the view of automation rules to see only the ones that have Add task actions defined.

:::image type="content" source="media/create-tasks-automation-rule/filtered-grid-on-actions.png" alt-text="Screenshot showing the results of the filter on the automation rules grid.":::

TheseThe filtered results are the automation rules that add tasks to incidents. The **Analytics rule names** column tells you which analytics rules these automation rules are conditioned on, so you'll have a general idea of which incidents are affected.

Add tasks to incidents with automation rules

Perform the following steps to add tasks to incidents by using an automation rule:

  1. In the Automation page, select + Create and select Automation rule.

  2. The Create new automation rule panel will open on the right side.

    1. The order of execution of the automation rules, as determined by the number in the Order setting, and...
    2. The order of the Add task actions defined within each automation rule.

Related content