Microsoft Sentinel
Cloud and workloads

Create Tasks Playbook

In brief

The playbook text now says the task targets the user associated with the researched malicious IP address. The document date and authoring metadata were also updated.

What Defender admins need to know

Administrators can use the revised wording to better understand the user targeted by the analyst task; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security analyst, I want to automate incident management tasks using playbooks so that I can streamline and manage complex workflows efficiently.

The following sample procedure shows how to add a playbook action that researches an IP address appearing in an incident.

  • If the results of this research are that the IP address is malicious, the playbook creates a task for the analyst to disable the user using thatassociated with the researched IP address.
  • If the IP address isn't a known malicious address, the playbook creates a different task, for the analyst to contact the user to verify the activity.

To add and configure the IP-research condition and conditional task-creation actions, take the following steps: