Summary and resources


You should have learned how to connect Windows devices to the Microsoft Sentinel workspace using the provided data connectors. The connector offers options to control which events to collect.

You should now be able to:

  • Connect Azure Windows Virtual Machines to Microsoft Sentinel
  • Connect non-Azure Windows hosts to Microsoft Sentinel
  • Configure Log Analytics agent to collect Sysmon events

Learn more

You can learn more by reviewing the following.

Become a Microsoft Sentinel Ninja

Microsoft Tech Community Security Webinars

Microsoft Defender for Cloud data collection with the Azure Monitor Agent (AMA)