
Join a live, interactive Microsoft Sentinel expert course with real-time demos and a sandbox environment, guided by Go Remote Cloud security experts to train remote cloud engineers.
Leverage Microsoft Sentinel's cloud native, scalable SIEM to collect, detect, investigate, and respond to real-time threats with automation, machine learning, and broad integration.
Identify prerequisites for Microsoft Sentinel, including an active Azure subscription, required permissions, data sources such as Azure Active Directory and Azure Activity, security data connectors, and Azure services knowledge.
Shivam explains the Azure management levels and hierarchy—management groups, subscriptions, resource groups, and resources. He highlights ownership and security risks from misapplied permissions.
Identify data sources and determine workspace requirements for a Microsoft Sentinel environment. Plan security, integrate with Azure services, deploy the workspace, and monitor and fine-tune it.
Explore the life cycle of Microsoft Sentinel, from collect data across endpoints and clouds to detect in real time, investigate with AI and machine learning, and respond with automated playbooks.
Explore Microsoft Sentinel pricing as a SaaS, including pay-as-you-go and commitment tiers based on data ingested, stored, and security events analyzed, plus free data sources and a pricing calculator.
Discover how to deploy Microsoft Sentinel by signing into the Azure portal, choosing a subscription and region, creating or selecting a log analytics workspace, and applying tags.
Watch a live demo of the Microsoft Sentinel overview tab. Explore events, alerts, incidents, and the new overview features including automation and Mitre attack framework insights.
Explore the Microsoft Sentinel logs tab, view log details in a pop-up, and run pre-built queries like Azure Monitor, with tables, queries, functions, and filters guiding analysis.
Explore the Microsoft Sentinel news and guides tab for updates on features, changes, best practices, and security insights, plus access to a content hub, documentation, and tutorials.
Explore the Microsoft Sentinel search tab to query logs by user, machine, or time frame, switch tables, and run investigations; learn about saved searches and data restoration limits.
Learn to manage and investigate incidents in the Microsoft Sentinel incidents tab, assign severity and owners, update status, and analyze triage and closure via the security efficiency workbook.
Explore the Microsoft Sentinel workbooks tab in threat management to create customizable reports and visualizations from security data, using KQL to monitor trends and threats.
Explore Microsoft Sentinel's hunting tab in threat management to proactively search threats with 211 pre-built queries and detection rules. Run and view results, then investigate in the log analytics workspace.
Explore the Microsoft Sentinel Notebooks tab in threat management to create and share Jupyter notebooks using an Azure machine learning workspace and pre-built templates.
Learn how Microsoft Sentinel uses entity behavior analytics (Yuba) to monitor user and entity activity. Enable Yuba and connect Active Directory and Azure Active Directory data sources.
Explore the Microsoft Sentinel threat intelligence tab to refresh data, add new indicators (domain, file, IPv4/IPv6, URL), and import IOCs from files or solutions.
Explore how Microsoft Sentinel maps to the MITRE ATT&CK framework, examining execution techniques, active and anomaly rules, analytical templates, and simulated coverage for threat detection.
Explore the microsoft sentinel content hub in public preview, enabling out-of-the-box content like analytical rules, playbooks, or interrogations, with quick search and one-click installs.
Learn to manage Microsoft Sentinel content with central repositories, automating deployment of rules, playbooks, workbooks, hunting queries, and watchlists from GitHub or Azure DevOps.
Explore the Microsoft Sentinel communities tab in content management to access community news, security threats and campaigns, including security awareness campaigns, plus white pages and forums on Twitter and LinkedIn.
Explore how Microsoft Sentinel data connectors onboard cloud, on-prem, and third-party data with pre-built and custom options, including search, status filtering, and essential prerequisites.
Learn how Microsoft Sentinel analytics correlate alerts into incidents with built-in and customized rules, reduce noise, and deploy rules through schedule query, entity, or Microsoft incident rule creation.
Learn to configure the Microsoft Sentinel watchlist to monitor entities and trigger alerts, using local or Azure storage CSV files and search keys like user principal name.
Learn how Microsoft Sentinel automates security workflows with automation rules and playbooks, triggering playbooks, changing the severity, closing tickets, and adding tags and tasks within the soar framework.
Explore Microsoft Sentinel settings and workspace configuration to manage playbook permissions, data usage, anomalies, tagging, and health monitoring, then export templates to clone or remove the workspace.
Explore advanced Microsoft Sentinel topics with interactive detail courses, configuring a complete Azure Lighthouse environment, diving into KQL, playbooks and automation, and building dashboards and workbooks.
Microsoft Sentinel & The Next Gen-SOC
Learn Microsoft Sentinel Today!
Create interactive reports by using workbooks
Collect data at cloud scale across all users, devices, applications, and infrastructure, both on-premises and in multiple clouds.
Detect previously undetected threats, and minimize false positives using Microsoft's analytics and unparalleled threat intelligence.
Investigate threats with artificial intelligence, and hunt for suspicious activities at scale, tapping into years of cyber security work at Microsoft.
Respond to incidents rapidly with built-in orchestration and automation of common tasks.
Microsoft Sentinel monitors an organization’s entire IT infrastructure, 365 days 24/7, to detect any threat or alert in real time and solve them as quickly and effectively as possible and timely analysis of threats to find ways to improve the organization’s security posture.
Learn What Is a SIEM + SOAR
Learn How To Deploy Microsoft Sentinel
Learn Microsoft Sentinel Design & Architecture
Learn About Threat Intelligence
Hunting
Microsoft Sentinel delivers intelligent security analytics and threat intelligence across the enterprise. With Microsoft Sentinel, you get a single solution for attack detection, threat visibility, proactive hunting, and threat response.
Deliver intelligent security analytics and threat intelligence across the enterprise. With Microsoft Sentinel, you get a single solution for attack detection, threat visibility, proactive hunting, and threat response.
Correlate alerts into incidents by using analytics rules
Automate and orchestrate common tasks by using playbooks
Automate your common tasks and simplify security orchestration with playbooks that integrate with Azure services and your existing tools.
Investigate the scope and root cause of security threats
Microsoft Sentinel deep investigation tools help you to understand the scope and find the root cause of a potential security threat. You can choose an entity on the interactive graph to ask interesting questions for a specific entity, and drill down into that entity and its connections to get to the root cause of the threat.