An organization wants to automatically perform a series of actions, such as blocking a user in Microsoft Entra ID and creating a ticket in a service management system, whenever a high-severity incident is generated in Microsoft Sentinel.
Which capability enables this type of automated, multi-step response?