Summary
This chapter introduced Microsoft Sentinel, which is a cloud-based SIEM tool that allows you to analyze large amounts of data from both Microsoft and third-party sources. We discussed how to enable Microsoft Sentinel and connect it to a new or existing Log Analytics workspace. We also learned how to set up and configure Microsoft Sentinel playbooks, which use triggers and actions to send alerts on a multitude of events.
In the next chapter, we will discuss the principles of MDA. We will learn how to configure MDA, create snapshot Cloud Discovery reports, discover custom cloud apps, and add them to Cloud App Discovery. In addition, we will learn how to use App Connectors to enable visibility and control over the apps we connect to and apply policies to them, and how to interpret and analyze alerts, reports, and dashboards.