1Automation in Defender XDR and Sentinel
- 1.1Defender XDR notifications and alert tuning
Understand configuring Microsoft Defender XDR email notifications (incidents/actions/threat analytics) and alert notifications, and tuning, suppressing, and correlating alerts.
- 1.2Configuring Defender for Endpoint and ASR
Understand Microsoft Defender for Endpoint advanced features, rule settings, custom data collection, security policies including attack surface reduction (ASR) rules, and device groups/permissions/automation levels.
- 1.3Automated investigation/response and automatic attack disruption
Understand managing automated investigation and response (AIR) in Microsoft Defender XDR and configuring automatic attack disruption.
- 1.4Sentinel automation rules and playbooks
Understand creating/configuring Microsoft Sentinel automation rules and playbooks (Azure Logic Apps), and automating incident response via SOAR.

