Microsoft and SOC Alert

odweik 21 Reputation points
2022-02-04T10:17:26.317+00:00

Dear All,

I need an advise , to check logs or incident inside Microsoft cloud, you need to log to many different console also most of them not reflect for example Azure AD Identify Protection and Azure sentinel

Console need to open to check incident (SOC Alerts)

  • Azure AD identity protection
  • Azure Sentinel
  • Office 365 Security console
  • etc...
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
982 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Alistair Ross 7,101 Reputation points Microsoft Employee
    2022-02-04T19:44:14.077+00:00

    Microsoft Sentinel is a scalable, cloud-native, security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution. Microsoft Sentinel delivers intelligent security analytics and threat intelligence across the enterprise, providing a single solution for attack detection, threat visibility, proactive hunting, and threat response. Sentinel Documentation

    This means it has the capability to ingest, analyze, visualize and respond to events across multiple services, such as Azure AD, M365 Defender and more and provide a birds eye view across the enterprise. However it does not mean it is a specialist in every data type and for that drill down analysis, you potential would have to leverage another application, such as M365 defender for deep and specialist analysis.

    If you are using Microsoft Sentinel, ensure you are ingesting your logs from all your data sources (some are free, check them out on our pricing page) and this should be your primary view that you use for all SOC alerts. If an incident is raised in Sentinel and deeper analysis is required by a security analyst, then you would drill down deeper into the application specific portal.


  2. Andrew Blumhardt 9,496 Reputation points Microsoft Employee
    2022-02-04T21:27:05.557+00:00

    What I have seen is that the M365 Defender portal is where most operators that are more customer facing seen to focus. Those that are working primarily to support users and user devices. The M365D portal consolidated alerts from MDE, MDI, MDO, MCFA(MCAS), ADD Identity protection.

    For those with a more infrastructure focus (servers, subscriptions, cloud, hybrid network, etc.) then Sentinel is the preferred portal. MDFC (ACS) integrates well with Sentinel. As do 3rd party cloud services and on-prem network appliance logs.

    By starting in the tool that is closest to the data or customer being supported you can limit the need to hop through portals.