Microsoft Sentinel operates as a cloud-native SIEM and SOAR platform, primarily accessed and managed through the Azure portal. It provides a unified web interface for security operations teams to ingest security logs from diverse sources, detect threats using built-in and custom analytics, investigate incidents with contextual data, and automate response actions. The platform's browser-first design facilitates real-time security monitoring and incident management directly within a web environment, enabling security analysts to maintain continuous oversight of their organization's security posture without requiring client-side software installations.
Microsoft Sentinel Website Full Guide (2026)
Cloud-native SIEM and SOAR.
Updated Jul 18, 2026

Introduction
Key Features
Core Capabilities
Data Connector Gallery: Web interface for configuring ingestion from Azure services, M365, AWS, GCP, and on-premises source
Kusto Query Language (KQL) Editor: Browser-based environment for crafting complex queries against ingested security log
Analytics Rule Wizard: Guided web flow for defining custom detection rules based on KQL queries or built-in template
Incident Investigation Graph: Interactive web visualization for exploring relationships between alerts, entities, and events during an incident
Threat Intelligence Blade: Centralized web view for integrating and managing various threat intelligence feed
Additional Details
Playbook Designer (Logic Apps): Visual web canvas for building automated response workflows (SOAR playbooks)
Workbook Template Library: Pre-built and customizable dashboard templates for security monitoring and reporting, accessible via browser
Hunting Query Repository: Curated collection of KQL queries for proactive threat hunting, executable directly from the web interface
User and Entity Behavior Analytics (UEBA) Panel: Web-based insights into anomalous user and entity activitie
Watchlist Management Interface: Browser-accessible panel for creating and managing custom data lists for detection and hunting
Use Cases
Proactive Threat Hunting
Security analysts leverage the KQL query editor and hunting query repository within the Azure portal to proactively search for indicators of compromise (IOCs) and advanced persistent threats (APTs) across their ingested security data, identifying stealthy attacks before they escalate
Centralized Incident Management
SOC managers utilize the incident queue and investigation graph in the web interface to oversee active security incidents, assign tasks, track progress, and review the full context of an attack, ensuring timely and coordinated response effort
Automated Incident Response
Incident responders configure and deploy SOAR playbooks via the Logic Apps designer to automate repetitive response tasks such as blocking malicious IPs, isolating compromised hosts, or enriching incident data, accelerating mean time to respond (MTTR) directly from the browser
How to Use Microsoft Sentinel
Onboard Data Source
Navigate to the Azure portal, search for " ," then select "Data connectors." Choose relevant connectors (e.g., Azure Activity, Microsoft 365 Defender, Syslog) and follow the browser-guided setup to begin ingesting security log
Microsoft Sentinel Alternatives
Microsoft Intune
Cloud-based endpoint management.
Microsoft Defender
Security suite & antivirus.
Microsoft SharePoint
Web-based collaborative platform.
HoloLens
Mixed reality smartglasses.
About Microsoft Sentinel
Useful Links
1 totalVideo Mentions
Microsoft Sentinel Status
Service is operational


