Microsoft Sentinel
By Microsoft
Microsoft's cloud SIEM with automation playbooks and consumption-based data ingestion. Many Microsoft 365 log sources ingest without charge. New customers have been directed to the Microsoft Defender portal since July 2025, and support for the Azure portal experience ends March 31, 2027.
Verified Sources: microsoft.com, learn.microsoft.com
- Product type
- Software
- Deployment
- SaaS
- Organization size
- SMBMid-marketEnterprise
- Pricing tier
- $$
Capability checklist
SIEMHow Microsoft Sentinel measures up against the full Security Information & Event Management taxonomy.
- Broad log ingestion — supported
- Collects and normalizes logs from network, endpoint, cloud, and SaaS sources.
- Correlation & detection rules — supported
- Turns raw events into alerts via built-in and custom detection logic.
- Fast historical search — supported
- Query months of data quickly during investigations.
- Behavior analytics (UEBA) — supported
- Baselines user and entity behavior to flag anomalies.
- Dashboards & reporting — supported
- Compliance and operational reporting out of the box.
- Detection-as-code — not supported
- Manage detection rules in version control with CI.
Alternatives
Other Security Information & Event Management tools with overlapping capabilities, sized for similar teams.
Head-to-head comparisons
Source-linked comparisons featuring Microsoft Sentinel.
Appears in stacks
Real-world stacks that include Microsoft Sentinel.
AI product team
A product and platform team building generative-AI applications or agents with access to internal data and tools, supported by security, cloud, data, and governance partners.
Mid-market SOC
A 500-2,000-employee company with a small, dedicated security team of perhaps three to eight people running a real, if lean, security operations function — a mix of in-house analysts and outsourced help, moderate compliance pressure from customers and regulators, and a budget that has to stretch across the whole security program rather than concentrate on one area.