Microsoft Sentinel Review
September 12, 2023

Microsoft Sentinel Review

Anonymous | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User

Overall Satisfaction with Microsoft Sentinel

We use it to collect our logs and then correlate it with security intelligence, so we get alerts.
  • I think what it does the best is the community aspect of it which means it's already integrated in the platform. You can just click and select stuff you like and it is created by other professionals. I think that's what it does the best and it's really easy to integrate into your existing interment.
  • I think it has room for improvement in its ease of use. It's not hard to use, but for someone who doesn't even add someone that shows you everything, at first it could be hard because you don't know what some of the names are. If you don't know it, you could get confused like a playbook. If you don't know what the playbook is, you could be mistaken.
  • I'd say that Sentinel gives us a lot more vision about our stuff. For the business impact, it's really hard to tell because we're an entertainment shop. In fact, it costs us money to get it to run, but it gave us a pre-value. But yeah, it's hard to correlate it with the business impact.
Elasticsearch, we did a demo about it. Also the CrowdStrike platform, we got a demo on it. How did they compare? I think Elasticsearch, for us, it's more hard to configure. Microsoft Sentinel is pretty straight to the point. We turn on stuff, it's plug-and-play. CrowdStrike, I don't know much. Since it was only a demo.

Do you think Microsoft Sentinel delivers good value for the price?

Yes

Are you happy with Microsoft Sentinel's feature set?

Yes

Did Microsoft Sentinel live up to sales and marketing promises?

Yes

Did implementation of Microsoft Sentinel go as expected?

Yes

Would you buy Microsoft Sentinel again?

Yes

On the Microsoft shop, it's very well suited. If you have all your environment. In Microsoft Azure, it's very well suited. If you don't have much, that's where it lacked. I think if someone does not have a Microsoft shop, I don't see the point in getting it.

Microsoft Sentinel Feature Ratings

Centralized event and log data collection
Not Rated
Correlation
Not Rated
Event and log normalization/management
Not Rated
Deployment flexibility
Not Rated
Integration with Identity and Access Management Tools
Not Rated
Custom dashboards and workspaces
Not Rated
Host and network-based intrusion detection
Not Rated
Log retention
Not Rated
Data integration/API management
Not Rated
Behavioral analytics and baselining
Not Rated
Rules-based and algorithmic detection thresholds
Not Rated
Response orchestration and automation
Not Rated
Incident indexing/searching
Not Rated