What this guide covers
Microsoft sells Sentinel as a cloud-native SIEM and security operations platform, and the Learn overview will tell you exactly that in one sentence. What it does not tell you is that the whole product has moved into the Microsoft Defender portal, that the Azure portal it was built in stops working on March 31, 2027, and that onboarding to the unified portal can silently disable Fusion (Sentinel's built-in machine-learning rule that fuses lower-fidelity signals into a single multistage-attack incident), rewrite the scope of your automation rules, and strip the incident-provider condition out from under detections you already shipped. The documentation describes each of those changes in its own article. None of them warns you which one breaks what you already built.
This is the connected account the docs never put in one place. It walks the product from the workspace up: the two-tier data lake and what mirroring costs, the licensing math behind Sentinel being generally available without an E5 or a Defender XDR entitlement, ingestion mechanics that double-bill you when a syslog facility is shared, and the RBAC and automation gotchas that fail with cryptic errors instead of clear ones. Every limit, license boundary, and portal path is grounded against current Microsoft Learn and validated in a live Microsoft 365 E5 lab.
You do not need a production SOC to follow along. A trial tenant and a single connected data source are enough to reproduce nearly every behavior in this book.
Chapter map
- Microsoft Sentinel, What It Is and Where It Lives
- Licensing, Prerequisites, and Cost Planning
- Workspace Design and Onboarding
- Roles, RBAC, and Access Control
- Data Tiers, Retention, and the Sentinel Data Lake
- The Content Hub and Data Connectors
- Ingestion Mechanics, AMA, DCRs, Windows Events, Syslog, and CEF
- Analytics Rules, Detection at Every Speed
- Watchlists, Threat Intelligence, and Hunting
- UEBA, User and Entity Behavior Analytics
- Automation Rules, Playbooks, and SOAR Patterns
- Workbooks, SOC Optimization, and Operational Visibility
- Sentinel and Defender XDR Unified, Before You Go to Production
Appendices: PowerShell and Graph Quick Reference; Build a Lab Tenant; Production Readiness Checklist.
Who it is for
This book is for administrators and engineers who run Microsoft Sentinel and want the moving parts wired together rather than listed, for IT pros ramping onto the product who need one coherent production-focused reference, and for anyone sitting the SC-200 (Microsoft Security Operations Analyst) exam who wants depth beyond exam cramming; the material tracks the SC-200 skills measured as of July 28, 2026, which explicitly cover the Sentinel data lake, Sentinel Graph, KQL jobs, notebooks connected to the Sentinel MCP server, and agentic AI tools including embedded Microsoft Security Copilot.