sentinel
Microsoft Sentinel
Microsoft Sentinel is a cloud-native SIEM + SOAR built on a Log Analytics workspace and delivered through the Microsoft Defender portal as part of the unified SecOps platform. It ingests logs from Microsoft and third-party sources, runs scheduled and near-real-time detections in KQL, correlates alerts into incidents, and orchestrates response via Logic Apps playbooks.
When to use
Centralising security logs from Microsoft and third-party sources, building detections, hunting across data, and automating response. Use Sentinel when you need a single SIEM across clouds, on-prem, and SaaS - not only Microsoft 365.
Do not use this skill when the goal is only correlating M365 alerts (use defender-xdr)
or onboarding the existing Sentinel workspace into the unified Defender portal (use
unified-secops-platform).