Microsoft Sentinel
Cloud-native SIEM and SOAR running on Azure with per-GB analytics pricing.
Technical Architecture & Overview
Microsoft Sentinel is a cloud SIEM built on Azure Log Analytics, with analytics rules, automation playbooks through Logic Apps, and ATT&CK-mapped detections. It sits close to Defender and Entra telemetry, and KQL gives analysts query depth across all ingested data. Pricing follows ingestion and retention, with commitment tiers for volume.
Targeted Technical Use Cases
Microsoft-centric estates that want SIEM and SOAR without managing infrastructure.
Evaluation & Trade-offs
Core Strengths
- +Deep integration with Microsoft security telemetry.
- +KQL is expressive and consistent with other Microsoft tooling.
- +No infrastructure to operate.
Trade-Offs & Limitations
- -Costs are sensitive to ingestion discipline.
- -Lock-in to Azure for the data plane.
Defensive Security Application
Cloud SIEM correlation and automated response across Microsoft and third-party sources.
Frequently Asked Questions
What is Microsoft Sentinel?→
Microsoft Sentinel is a cloud SIEM built on Azure Log Analytics, with analytics rules, automation playbooks through Logic Apps, and ATT&CK-mapped detections. It sits close to Defender and Entra telemetry, and KQL gives analysts query depth across all ingested data. Pricing follows ingestion and retention, with commitment tiers for volume.
What is Microsoft Sentinel used for?→
Microsoft-centric estates that want SIEM and SOAR without managing infrastructure.
What are the strengths of Microsoft Sentinel?→
- +Deep integration with Microsoft security telemetry.
- +KQL is expressive and consistent with other Microsoft tooling.
- +No infrastructure to operate.
What are the limitations of Microsoft Sentinel?→
- +Costs are sensitive to ingestion discipline.
- +Lock-in to Azure for the data plane.
How is Microsoft Sentinel used defensively?→
Cloud SIEM correlation and automated response across Microsoft and third-party sources.