An organization wants to automatically perform a series of actions, such as blocking a user in Microsoft Entra ID and creating a ticket in a service management system, whenever a high-severity incident is generated in Microsoft Sentinel. Which capability enables this type of automated, multi-step response?
-
A
Workbooks
-
B
Analytics Rules
-
C
Data Connectors
-
D
Playbooks