Microsoft Sentinel review
Updated October 15, 2025

Microsoft Sentinel review

Harshit Lal | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User

Overall Satisfaction with Microsoft Sentinel

Microsoft Sentinel is used both as siem and soar solution in our customer environment . We are also sending logs from Microsoft Sentinel to prisma. We are running kql queries on Microsoft Sentinel to do threat hunting

Pros

  • siem solution
  • automation with runbooks
  • soar solution
  • compatible with other vendor solution
  • providing compliance

Cons

  • ticketing system
  • other third party app should also be compatible
  • pricing
  • better features for hybrid cloud
  • reduced cost occured for legacy system and saving 50000 dollar upto 1 year
  • reduced false positive incidents up to 90 percent
  • faster deployment over 100000 dollar up to 1 year
network devices firewall devices waf devices
we hava data connector , it was seamless process
Microsoft Sentinel’s AI, machine learning, and analytics helped in threat hunting and removing false positives. It helped in having automated runbooks for predefined incidents
They are used for threat hunting and can document investigation. we have specific incident page and overall can create graph and investigate
it is easy to use Microsoft Sentinel and has faster deployment and advanced artificial intelligence than splunk

Do you think Microsoft Sentinel delivers good value for the price?

Yes

Are you happy with Microsoft Sentinel's feature set?

Yes

Did Microsoft Sentinel live up to sales and marketing promises?

I wasn't involved with the selection/purchase process

Did implementation of Microsoft Sentinel go as expected?

Yes

Would you buy Microsoft Sentinel again?

Yes

It is well suited where the infrastructure is totally on azure cloud and it is less appropriate when used in hybrid cloud

Microsoft Sentinel Feature Ratings

Centralized event and log data collection
10
Correlation
10
Event and log normalization/management
8
Deployment flexibility
8
Integration with Identity and Access Management Tools
9
Custom dashboards and workspaces
10
Host and network-based intrusion detection
10
Log retention
7
Rules-based and algorithmic detection thresholds
10
Response orchestration and automation
10
Incident indexing/searching
10

Comments

More Reviews of Microsoft Sentinel