Azure Sentinel
Standing watch, by your side. Intelligent security analytics for your entire enterprise.
Build next-generation security operations with cloud and AI
See and stop threats before they cause harm, with SIEM reinvented for a modern world. Microsoft Sentinel is your birds-eye view across the enterprise. Put the cloud and large-scale intelligence from decades of Microsoft security experience to work. Make your threat detection and response smarter and faster with artificial intelligence (AI). Eliminate security infrastructure setup and maintenance and elastically scale to meet your security needs—while reducing costs as much as 48 percent compared to traditional SIEMs.1
Collect data at cloud scale—across all users, devices, applications, and infrastructure, both on-premises and in multiple clouds
Detect previously uncovered threats and minimise false positives using analytics and unparalleled threat intelligence from Microsoft
Investigate threats with AI and hunt suspicious activities at scale, tapping into decades of cybersecurity work at Microsoft
Respond to incidents rapidly with built-in orchestration and automation of common tasks
Limitless cloud speed and scale
Invest in security, not infrastructure setup and maintenance, with the first cloud-native SIEM from a major cloud provider. Never let a storage limit or a query limit prevent you from protecting your enterprise. Start using Microsoft Sentinel immediately, automatically scale to meet your organisational needs and pay for only the resources you need. As a cloud-native SIEM, Microsoft Sentinel is 48 percent less expensive and 67 percent faster to deploy than legacy on-premises SIEMs.Read the Total Economic Impact™ of Microsoft Sentinel study by Forrester Consulting

The Total Economic Impact™ of Microsoft Sentinel
Find out how Microsoft Sentinel provides an ROI of 201 percent over three years and reduces costs by 48 percent compared to legacy SIEM solutions. Read the full commissioned study conducted by Forrester Consulting.

The Forrester Wave(tm): Security Analytics Platform Providers, Q4 2020
Forrester Research has named Microsoft Sentinel as a "Leader" in The Forrester Wave(tm): Security Analytics Platform Providers, Q4 2020, with the top ranking in Strategy.
AI on your side
Focus on finding real threats quickly. Reduce noise from legitimate events with built-in machine learning and knowledge based on analysing trillions of signals daily. Accelerate proactive threat hunting with pre-built queries based on years of security experience. View a prioritised list of alerts, get correlated analysis of thousands of security events within seconds and visualise the entire scope of every attack. Simplify security operations and speed up threat response with integrated automation and orchestration of common tasks and workflows.
See how Microsoft drives deep insights based on trillions of signals every day
Behaviour analytics to stay ahead of evolving threats
Detect unknown threats and anomalous behaviour of compromised users and insider threats. Get a new level of insight with user and entity profiling that leverages peer analysis, machine learning and Microsoft security expertise. Gain more contextual and behavioural information for threat hunting, investigation and response using the built-in entity behavioural analytics.
Streamlined and cost-effective security data collection
Simplify data collection across different sources, including Azure, on-premises solutions and across clouds using built-in connectors. Connect with data from your Microsoft products in just a few clicks. Import Office 365 audit logs, Azure activity logs and alerts from Microsoft threat protection solutions for free and analyse and draw correlations to deepen your intelligence.

A match for all your tools
Connect to and collect data from all your sources including users, applications, servers and devices running on-premises or in any cloud. Integrate with existing tools, whether business applications, other security products or homegrown tools and use your own machine-learning models. Optimise for your needs by bringing your own insights, tailored detections, machine learning models and threat intelligence.

A cost-effective, cloud-native SIEM with predictable billing and flexible commitments
Reduce infrastructure costs by automatically scaling resources and only paying for what you use. Save up to 60 percent as compared to pay-as-you-go pricing, through capacity reservation tiers. Receive predictable monthly bills and the flexibility to change your capacity tier commitment every 31 days. Pay nothing extra when you ingest data from Office 365 audit logs, Azure activity logs and alerts from Microsoft threat protection solutions.
Get started in three steps
Set up your Azure free account.
Go to the Microsoft Sentinel dashboard in the Azure portal.
Explore the documentation and quickstarts.
Learn more about Microsoft Sentinel
Explore documentation and quickstarts
Learn how to connect Microsoft services and third-party data sources like servers, network equipment and security appliances including firewalls.
Get instant visualisation and insights across your connected data sources using built-in dashboards.
Track security threats across your organisation's logs with powerful search and query tools.
Download the Microsoft Sentinel quickstart guide.
Use the Microsoft Sentinel All-In-One Accelerator to get up and running fast.
Become an Microsoft Sentinel master with the Microsoft Sentinel Ninja Training.
Read analyst reports
Find out how security professionals are migrating SIEM operations to the cloud to reduce costs, improve protection and reduce alert fatigue in this IDG report: SIEM Shift: How the Cloud Is Transforming Security Operations.
Learn how Microsoft Sentinel provides an ROI of 201 percent over three years in this commissioned study conducted by Forrester Consulting: The Total Economic Impact™ of Microsoft Sentinel.
Learn about current cost-savings offers
Microsoft 365 E5 customers save up to https://aka.ms/m365-sentinel-offer/month on a typical 3,500 seat deployment with Azure credits for up to 100MB/user/month of data ingestion into Microsoft Sentinel.
Trusted by companies of all sizes
Tom Morley: Senior Director for Global IT Engineering Operations and Cyber Security, ABM"With Microsoft Sentinel, we saw the opportunity to develop the automated responses we wanted for threat protection. With a lot of the alerts and data already correlated across Microsoft tools, the queries and playbooks are so simple they kind of write themselves."

Stuart Gregg: Cyber Security Operations Lead, ASOS"We found Microsoft Sentinel easy to set up and now don't have to move data across separate systems. We can literally click a few buttons and all our security solutions feed data into Microsoft Sentinel."

Greg Petersen: Senior Director, Security Technology and Operations Team, Avanade"Using Microsoft Sentinel helps us move beyond managing our SIEM on-premises and instead focus on the value add that's on top of it—how to do more interesting strategic work."

Ryan Smith: Manager of IT Security and Operations, First West Credit Union"We realized right away that Microsoft Sentinel offered a completely different experience. We could onboard our logs from Azure and Office 365 in literally one click. We configured 80 percent of our logs to feed into Microsoft Sentinel within one month versus 18 months with ArcSight."

Alex Kreilein: Chief Information Security Officer"We're here to help first responders and stop terrorists, nation-state attackers, and others from threatening public safety—and we use Microsoft Sentinel to help us do it."

Frequently asked questions about Microsoft Sentinel
-
Microsoft Sentinel is a cloud-native security information and event manager (SIEM) platform that uses built-in AI to help analyse large volumes of data across an enterprise—fast. Microsoft Sentinel aggregates data from all sources, including users, applications, servers and devices running on-premises or in any cloud, letting you reason over millions of records in a few seconds. It includes built-in connectors for easy onboarding of popular security solutions. Collect data from any source with support for open standard formats like CEF and Syslog.
-
Yes, Microsoft Sentinel is built on the Azure platform. It provides a fully integrated experience in the Azure portal to augment your existing services, such as Azure Security Center and Azure Machine Learning. Create your Azure free account to get started.
-
Microsoft Sentinel integrates with many enterprise tools, including best-of-breed security products, homegrown tools and other systems like ServiceNow. It provides an extensible architecture to support custom collectors through REST API and advanced queries. It enables you to bring your own insights, tailored detections, machine learning models and threat intelligence.
Try a modern SIEM solution born in the cloud

1 Commissioned study-The Total Economic Impact™ of Microsoft Sentinel, conducted by Forrester Consulting, 2020