Describe the Capabilities and Benefits of Microsoft Management and Automation Products
Modern, internet-connected organizations are under constant threat – too many, in fact, to be able to process them effectively with security operations staff. People are good at focusing on a few activities but can quickly become overwhelmed by the speed at which threats may be manifested.
Organizations need to expand to using automation tools to help detect anomalous patterns and threats across their entire environment and scale their efforts. Microsoft offers two such products: Microsoft Sentinel and Microsoft 365 Lighthouse.
Microsoft Sentinel
Microsoft 365 Defender products can connect with Microsoft Sentinel. By doing so, all Microsoft 365 Defender incidents and alerts are sent to Sentinel so that security admins can have all the data in one place. Microsoft Sentinel is a cloud-native SIEM and SOAR product. A SIEM works by gathering and analyzing all relevant data points, detecting...