TrustRadius: an HG Insights company

Microsoft Sentinel

Score8.6 out of 10

175 Reviews and Ratings

What is Microsoft Sentinel?

Microsoft Sentinel (formerly Azure Sentinel) is designed as a birds-eye view across the enterprise. It is presented as a security information and event management (SIEM) solution for proactive threat detection, investigation, and response.

Read more details.

Media

Microsoft Sentinel
Microsoft Sentinel
Screenshot of Microsoft Sentinel Capabilities

1 / 3

Top Performing Features

  • Centralized event and log data collection

    Effectiveness of real-time centralized event and log data collection

    Category average: 8.5

  • Behavioral analytics and baselining

    How effectively activity and behavior baselines are established and maintained

    Category average: 7.7

  • Correlation

    Correlation of logs and events to pinpoint significant threats

    Category average: 8.4

Areas for Improvement

  • Deployment flexibility

    Ability to tune system to maximize threat detection and minimize false positives

    Category average: 7.5

  • Host and network-based intrusion detection

    Ability to detect both endpoint intrusion and network ingress detection

    Category average: 8.1

  • Reporting and compliance management

    Ease and quality of reporting and compliance functions

    Category average: 8.5

Who Buys & Uses Microsoft Sentinel

Pros

  • Seamless integration with Microsoft ecosystem (Defender, M365, Azure)
  • Advanced AI/ML for threat detection, hunting, and automated responses
  • Centralized security data for comprehensive visibility across diverse environments

Cons

  • High and unpredictable costs due to consumption-based pricing for log storage
  • Limitations in out-of-the-box integrations for non-Microsoft ecosystems
  • Steep learning curve for Kusto Query Language (KQL)

Great solution to handle log and analyze these.

Use Cases and Deployment Scope

We use the Sentinel product to collect log data from our systems. This gives us a clear overview of all events and changes occurring within our technical environment. In addition, Sentinel detects security threats, which are automatically forwarded to the security operations center for further analysis. This enables us to effectively safeguard the continuity of our business operations.

Pros

  • Log data collection.
  • Integrates seamlessly with the Azure environment.
  • Anomaly detection.

Cons

  • Integration to non Azure environment solutions should be easier.
  • SAAS solution reporting.
  • The user interface could be clearer and more visual.

Return on Investment

  • Savings equivalent to one person-year.
  • Automated alarms.
  • Good analysis tools.

Usability

Alternatives Considered

Darktrace

Other Software Used

Darktrace, Microsoft Defender for Endpoint

Dealing With Cyber Threats With Microsoft Sentinel.

Use Cases and Deployment Scope

We use Microsoft Sentinel to boost our cybersecurity. It is our primary SIEM and SOAR solution, and it's reliable for detecting, investigating, responding to, and remediating cyber threats across our multi-cloud environments. It has greatly increased our security operations by effectively reducing false positives and centralizing security logs.

Pros

  • AI powered threat detection increases accuracy.
  • It automatically responds to threat incidences.
  • Proactive threat hunting adds a layer of security.
  • Comes with great threat intelligence features.
  • Makes monitoring and visualization easy.

Cons

  • We have experienced improper tiering.
  • Limited integration with non Microsoft ecosystems.

Return on Investment

  • Proactive threat hunting is very helpful.
  • Ability to auto responds to threats keeps our infrastructure secure.
  • Threat intelligence helps deal with known and unknown threats.

Usability

Other Software Used

Microsoft Defender for Business, Microsoft Defender XDR, Hornetsecurity Email Encryption

Microsoft Sentinel Review

Use Cases and Deployment Scope

We use Microsoft Sentinel as our primary SIM. We have many cloud applications that generate a lot of logs. We ingest all of those in Microsoft Sentinel. From there, we use other technologies to alert us.

Pros

  • Microsoft Sentinel integrates really well with SAP Rise, which is our ERP solution.

Cons

  • I would like to see some alerting options right in Microsoft Sentinel. For example, we have to use applications like PagerDuty and whatnot to then alert us on our cell phones. I wish Microsoft Sentinel would have that out of the box.

Return on Investment

  • It's really hard to justify ROI on anything security-related. You don't know what it has prevented or helped you with. So that's a very hard question to answer because you can't really quantify a number. But I hope it has stopped things from going bad.

Usability

Faster Security Investigation using Microsoft Sentinel.

Use Cases and Deployment Scope

Currently, while working with a bank-based application, our team is using Microsoft Sentinel to monitor transactions, banking applications, and payment gateways for unusual user logins and to detect suspicious behavior on the platform. We also use centralized logs for generating compliance reports.It easily integrates with other Microsoft cloud platforms.

Pros

  • Cloud scalability allows automatic scaling. Also, KQL helps with flexible querying for detection.
  • Easily integrates with Microsoft systems like Microsoft azure, Microsoft 365, and other.
  • Provides a built in analytical templates having detection rules and saves setup time.

Cons

  • Pricing model is little bit complex since it is hard to know the cost in advance.
  • KQL learning is required initially.
  • Some rules generates false positive reports.

Return on Investment

  • It reduced the response time, resulting in a roughly 35% reduction in the average time to detect suspicious activity.
  • Cost has increased by 2.3% but matches the worth.
  • Centralized logging made the compliance audit faster since we could pull evidence from one place instead of chasing multiple systems.

Usability

Alternatives Considered

Splunk Cloud Platform and Splunk Enterprise

Other Software Used

Splunk Cloud Platform

Microsoft Sentinel Review

Use Cases and Deployment Scope

It's our main SIEM in our environment. We use it to aggregate security logs and build detections around them, as well as for threat hunting and incident response situations. So we use it for the full use case.

Pros

  • I would say that KQL, the query language, is one of the best parts of Microsoft Sentinel. It's a lot more robust than other competitors' query languages and is a really strong point.

Cons

  • One feature that I would like to see improved is probably the log parsing. I think one of the big things that Splunk does better than Microsoft Sentinel is that it makes it easy to bring in new log streams of arbitrary formats and parse them out into columns and tables. Microsoft Sentinel is a lot more involved, though. It takes a lot more manual work to bring in different log sources and parse them out.

Return on Investment

  • It has a pretty positive impact. Our detection capabilities have improved a lot through what we're able to do with KQL. It takes a lot of manpower to build out those queries and those detection and response processes, but we've grown a lot through Microsoft Sentinel and KQL in the detection space.
  • The cost savings have been—We've had to put some effort into that space, but once we implemented the right cost-saving measures, I think it makes a lot of sense to use Microsoft Sentinel. I would say our ability to quickly detect and respond to threats is greatly improved with Microsoft Sentinel. Just how quickly we can query large amounts of data in time-sensitive situations has been a big advantage for us.

Usability

Other Software Used

Microsoft Defender for Endpoint, Microsoft Defender XDR