Incident Response and Automation

Incident Triage Workflow

Use evidence, entities, and timelines to decide what deserves escalation

Microsoft Security Operations Analyst (SC-200)Incident Response and AutomationUpdated Aug 22, 2026
Study options
WatchComing later
ListenComing later
ReadAvailable
ReviewComing later

Study guide

Technical reference and lesson notes

Triage answers a focused question: does this incident represent activity that warrants deeper response?

Start with the reason the incident exists

Review the analytics rule, alert evidence, impacted entities, and timeline before jumping directly into remediation. This establishes what was observed and what assumptions still need validation.

Correlate instead of guessing

Related sign-ins, process events, endpoint alerts, and identity activity can change the severity of an event. Use investigation queries to test a hypothesis rather than collecting unrelated telemetry.

  • Identify the affected user, host, IP, or resource.
  • Determine whether the behavior is expected for that entity.
  • Look for expansion in time, scope, or technique.
  • Record why the incident was closed or escalated.

Good closure is evidence-based

A benign conclusion should explain the evidence that supports it, not simply state that no issue was found.