TrustRadius: an HG Insights company

Microsoft Sentinel

Score8.6 out of 10

156 Reviews and Ratings

What is Microsoft Sentinel?

Microsoft Sentinel (formerly Azure Sentinel) is designed as a birds-eye view across the enterprise. It is presented as a security information and event management (SIEM) solution for proactive threat detection, investigation, and response.

Read more details.

Media

Microsoft Sentinel
Microsoft Sentinel
Screenshot of Microsoft Sentinel Capabilities

1 / 3

Top Performing Features

  • Centralized event and log data collection

    Effectiveness of real-time centralized event and log data collection

    Category average: 8.5

  • Correlation

    Correlation of logs and events to pinpoint significant threats

    Category average: 8.4

  • Integration with Identity and Access Management Tools

    Integration with access control tools like Active Directory and LDAP

    Category average: 8.2

Areas for Improvement

  • Data integration/API management

    Ease and quality of data integrations between SIEM and other systems

    Category average: 8

  • Reporting and compliance management

    Ease and quality of reporting and compliance functions

    Category average: 8.5

  • Deployment flexibility

    Ability to tune system to maximize threat detection and minimize false positives

    Category average: 7.4

Who Buys & Uses Microsoft Sentinel

Pros

  • AI-powered threat detection and automated response capabilities
  • Seamless integration with the broader Microsoft ecosystem (e.g., Defender, Azure)
  • Unified view of security data and strong correlation abilities for investigations

Cons

  • Complex licensing model and high consumption-based log retention costs
  • Limitations or challenges with robust integration in non-Microsoft environments
  • Steep learning curve, particularly for KQL, and inconsistent documentation

My Experience With Microsoft Sentinel - Great SIEM Capabilities.

Use Cases and Deployment Scope

We use Microsoft Sentinel to boost our security, and it works amazingly well. It is our primary SOAR and SIEM solution, ensuring we have the best visibility into our security operations. With the tool in place, detection and responding to threats is easy thanks to its AI capabilities. In addition, it boosts our security by making it easy to collect data from all users, devices, and applications for threat analytics. Finally, it integrates with Microsoft products for better protection and management.

Pros

  • It works well as a SIEM and SOAR solution.
  • It comes with amazing AI threat detection capabilities.
  • It works across on-premises and multi-cloud environments.
  • It offers automated threat response.
  • Works well when it comes to threat analytics.
  • It supports integrations more so with Microsoft products such as MS Azure.

Cons

  • So far Microsoft Sentinel has been awesome. No serious challenges to list.

Return on Investment

  • With Microsoft Sentinel, we protect both on-premises and multi-cloud business environments.
  • The AI features ensures fast and accurate threat detection.
  • With the tool in place, we enjoy automated threat response, which guarantees minimal to no threat-related damage.

Usability

Other Software Used

Zoho Assist, Microsoft 365, Zoho Meeting

Dealing With Cyber Threats With Microsoft Sentinel.

Use Cases and Deployment Scope

We use Microsoft Sentinel to boost our cybersecurity. It is our primary SIEM and SOAR solution, and it's reliable for detecting, investigating, responding to, and remediating cyber threats across our multi-cloud environments. It has greatly increased our security operations by effectively reducing false positives and centralizing security logs.

Pros

  • AI powered threat detection increases accuracy.
  • It automatically responds to threat incidences.
  • Proactive threat hunting adds a layer of security.
  • Comes with great threat intelligence features.
  • Makes monitoring and visualization easy.

Cons

  • We have experienced improper tiering.
  • Limited integration with non Microsoft ecosystems.

Return on Investment

  • Proactive threat hunting is very helpful.
  • Ability to auto responds to threats keeps our infrastructure secure.
  • Threat intelligence helps deal with known and unknown threats.

Usability

Other Software Used

Microsoft Defender for Business, Microsoft Defender XDR, Hornetsecurity Email Encryption

Microsoft Sentinel Review

Use Cases and Deployment Scope

We use Microsoft Sentinel as our primary SIM. We have many cloud applications that generate a lot of logs. We ingest all of those in Microsoft Sentinel. From there, we use other technologies to alert us.

Pros

  • Microsoft Sentinel integrates really well with SAP Rise, which is our ERP solution.

Cons

  • I would like to see some alerting options right in Microsoft Sentinel. For example, we have to use applications like PagerDuty and whatnot to then alert us on our cell phones. I wish Microsoft Sentinel would have that out of the box.

Return on Investment

  • It's really hard to justify ROI on anything security-related. You don't know what it has prevented or helped you with. So that's a very hard question to answer because you can't really quantify a number. But I hope it has stopped things from going bad.

Usability

Microsoft Sentinel review

Use Cases and Deployment Scope

We use it to correlate logs, aggregate logs, automate alerts and incidents, and to investigate alerts and incidents.

Pros

  • The visual presentation of data is terrific, so including what we had prior to Microsoft Sentinel, it presents data in a much more usable way, so that's been quite refreshing. It's not quite as complex to understand what you're looking at.

Cons

  • Automation is still a bit manual and clunky, as is the case with all the products out there doing that. If your automation were as simple as your visual presentation, it would be a much better product. But yeah, it's still a little clunky to build automation.

Return on Investment

  • Certainly nothing negative, positive. Again, it was a partial justification for the move to E5 because it allows me to reduce costs elsewhere. It gives me some cost avoidance for tools that I don't need elsewhere. It's not just Microsoft Sentinel by itself; it's the other things that come with it, associated with data leakage protection, risk management, insider risk, and so on. It certainly enhanced the business case for a move to E5 and for gaining those approvals, and it allows us to demonstrate to the executives, the board, and so on that we're being good stewards of the money we have.

Microsoft Sentinel Review

Use Cases and Deployment Scope

We use Microsoft Sentinel as a fully managed Security Operations Center (SOC) service across all of its core capabilities. It serves as the central platform for managing security incidents across multiple customer environments. Our use of Sentinel includes continuous monitoring, incident triage and management, threat investigation, and coordinated response activities. This approach helps us deliver scalable, multi-tenant security operations, improve visibility across diverse environments, and provide timely, consistent detection and response to our customers.

Pros

  • Strong integration with the Microsoft security ecosystem allows seamless connection to services such as Microsoft Defender, Microsoft 365, and Azure. This makes it easy to bring together identity, endpoint, and cloud signals to support investigation and detection scenarios.
  • Effective correlation of alerts and incidents in collaboration with Microsoft Defender XDR helps combine related signals into higher‑fidelity incidents. This reduces noise and improves visibility into attack context, making investigations more efficient.
  • High scalability for data ingestion and processing enables large volumes of security telemetry to be handled efficiently.

Cons

  • An area for improvement is how case management is surfaced within the Microsoft Sentinel experience, as clearer integration into Sentinel workflows would reduce context switching and improve incident handling.
  • There is an opportunity to further expand agentic, autonomous investigation and response capabilities.

Return on Investment

  • From my perspective as a provider working with clients across industries, Microsoft Sentinel positively impacts ROI by improving visibility into the threat landscape and enabling faster detection and response, thereby reducing overall business risk.

Usability

Other Software Used

Microsoft Defender for Cloud, Microsoft Defender XDR