Microsoft Sentinel
Cloud and workloads

Migrate Playbooks To Automation Rules

In brief

Updated the migration page’s metadata, wording, punctuation, and references to required roles and procedures for playbooks used by one or multiple analytics rules.

What Defender admins need to know

Administrators can use the clarified guidance when migrating playbooks. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security engineer, I want to migrate my alert-trigger playbooks to automation rules so that I can streamline automation management and prepare for the deprecation of analytics rule triggers.

[!INCLUDE unified-soc-preview]

Prerequisites

You'll need the:these roles:

  • Logic Apps Contributor role to create and edit playbooksplaybooks.

  • Microsoft Sentinel Contributor role to attach a playbook to an automation rulerule.

For more information,To learn more, see Microsoft Sentinel playbook prerequisites.

Create an automation rule from an analytics rule

Use this procedure if you're migratingFollow these steps to migrate a playbook that's used by only one analytics rule. If the playbook is used by multiple analytics rules, use Create a new automation rule from the Automation page.

  1. For Microsoft Sentinel in the Azure portal, select the Configuration > Analytics page. For Microsoft Sentinel in the Defender portal, select Microsoft Sentinel > Configuration > Analytics.

Create a new automation rule from the Automation page

Use this procedure if you’you're migrating a playbook that's used by multiple analytics rules. Otherwise, use Create an automation rule from an analytics rule

  1. For Microsoft Sentinel in the Azure portal, select the Configuration > Analytics page. For Microsoft Sentinel in the Defender portal, select Microsoft Sentinel > Configuration > Analytics.

  2. Under Conditions, select the analytics rules you want to run a particular playbook or a set of playbooks on.

  3. Under Actions, for each playbook you want this rule to invoke, select + Add action. The Run playbook action is automatically selected and grayed out.

  4. Select from the list of available playbooks in the drop-down list in the line below. Order the actions according to the order in which you want the playbooks to run by selecting the up/down arrows next to each action.

Related content

For more information, see: