SOC Automation with SOAR: Playbooks That Scale Your Security Team
A typical security team spends a disproportionate amount of time on repetitive, manual tasks. Copying indicators between systems, looking up threat intelligence databases, sending notifications to stakeholders, collecting context data for investigation. These tasks are necessary, but they do not require human judgment — and they consume time that could be spent on work that does.
SOAR (Security Orchestration, Automation and Response) is about automating the predictable so that analysts can focus on what requires expertise.
What Is SOAR?
SOAR combines three capabilities:
- Orchestration — — coordinating actions across different security tools and systems
- Automation — — executing repetitive tasks without human intervention
- Response — — standardized actions performed in response to security incidents
In the Microsoft ecosystem, SOAR is implemented through Sentinel automation rules and Logic Apps (playbooks). Sentinel triggers the playbook based on an alert or incident, and Logic Apps orchestrate actions across Azure, Microsoft 365, and third-party systems.
The Sentinel + Logic Apps Architecture
Sentinel automation works in two layers:
Automation Rules
Simple rules triggered by alerts or incidents in Sentinel. They can:
- Assign an incident to a specific analyst or group
- Change severity based on additional criteria
- Automatically close known false positives
- Trigger a Logic App playbook
Logic Apps Playbooks
More advanced workflows that can integrate with any system that has an API:
- Retrieve data from external sources
- Perform actions in Azure AD, Microsoft 365, firewalls, and other systems
- Send notifications via email, Teams, or SMS
- Update the Sentinel incident with context and results
Five Practical Playbook Examples
1. Auto-Enrich Alerts with Threat Intelligence
**Trigger:** New alert containing an IP address, domain, or file hash.
**Workflow:**
- Extract IOCs (IP, domain, hash) from the alert
- Look up IOCs in threat intelligence sources (VirusTotal, AbuseIPDB, Microsoft TI)
- Write results back as a comment on the Sentinel incident
- Adjust severity based on TI results (known malicious = high)
**Value:** The analyst skips manual lookups and gets immediate context during triage.
2. Auto-Disable Compromised User
**Trigger:** Alert for confirmed account compromise (high confidence).
**Workflow:**
- Disable the user account in Entra ID
- Revoke all active sessions and refresh tokens
- Reset MFA registrations
- Send notification to the IT lead and the user's manager via Teams
- Create an IT ticket for password reset and recovery
- Log all actions as a comment on the Sentinel incident
**Value:** Response time drops from minutes to seconds. Critical during credential stuffing and BEC attacks.
3. Auto-Block Malicious IP
**Trigger:** Alert for known malicious IP address with active communication.
**Workflow:**
- Verify the IP against threat intelligence (avoid blocking legitimate IPs)
- Add the IP to the block list on Azure Firewall or NSG
- Search logs for other machines communicating with the same IP
- Document the block as a comment on the incident
**Value:** Stops ongoing communication with attack infrastructure without manual intervention.
4. Auto-Collect Forensics Data
**Trigger:** Incident requiring investigation (manually triggered by analyst).
**Workflow:**
- Collect sign-in history for the involved user from Entra ID (last 48 hours)
- Retrieve mailbox rules and forwarding configuration from Exchange Online
- Gather device information and recent alerts from Defender for Endpoint
- Collect relevant logs from other systems
- Compile everything into an investigation report attached to the incident
**Value:** The analyst gets all context data assembled automatically instead of spending 30-60 minutes on manual collection.
5. Auto-Notify Stakeholders
**Trigger:** Incident classified with high severity.
**Workflow:**
- Identify affected systems and service owners from CMDB or tagging
- Send structured notification to relevant stakeholders via Teams and email
- Include incident summary, severity, and expected actions
- Update status page or internal communication channel as needed
- Log all notifications on the incident for compliance
**Value:** Ensures consistent and rapid communication without the analyst spending time on manual notifications.
How to Identify Automation Candidates
Not every process should be automated. The best candidates have three characteristics:
- High volume — — the task is performed many times daily or weekly
- Low complexity — — the steps are well-defined and do not require human judgment
- Well-defined steps — — the process follows a fixed flow with predictable outcomes
Start by mapping the analysts' daily tasks. Ask: "What do you spend the most time on that feels repetitive?" The answers usually point directly to the best automation candidates.
Build vs. Buy Playbooks
Microsoft offers a library of pre-built playbook templates in the Sentinel Content Hub. These cover common use cases and can be customized.
**Use pre-built templates when:**
- The use case is standard (enrichment, notification, user disablement)
- You want to get started quickly
- The team has limited Logic Apps experience
**Build custom playbooks when:**
- You have specific integration requirements with internal systems
- Standard workflows do not fit your organization
- You need specially tailored logic
Measuring Automation ROI
To justify the investment in automation, measure the following:
- Time saved per incident — — compare analyst time before and after automation
- MTTR reduction — — how much faster are incidents resolved with automation
- Incident volume handled — — the number of incidents the team can handle without scaling headcount
- Consistency — — the percentage of incidents handled according to the defined process
A typical enrichment playbook saves 5-10 minutes per alert. With 50 alerts per day, that is over 4 hours saved daily — enough for an analyst to shift focus to proactive work.
Common Mistakes
- Automating everything at once — — start with 2-3 playbooks, optimize them, and build out gradually
- No human-in-the-loop for critical actions — — auto-disabling user accounts should have an approval step or a high confidence threshold
- Playbooks that fail silently — — implement monitoring and alerting for playbook failures, or you will not notice when automation has stopped
- Not testing playbooks — — test with simulated incidents before production, and test regularly to verify they still work after API or permissions changes
ForSec designs and implements SOAR playbooks in Microsoft Sentinel tailored to your organization. We help you identify the right automation candidates and build playbooks that truly scale your security team.
Need help with cybersecurity?
We help Norwegian organizations protect against digital threats. Contact us for a no-obligation conversation.
Contact us