Chapter 10: Using Azure Sentinel to Monitor Microsoft 365 Security
Azure Sentinel is a cloud-based security information and event management (SIEM) tool that enables the analysis of vast quantities of data both within Microsoft 365 and from external sources using artificial intelligence technology. Azure Sentinel allows you to gather data, detect potential threats, and then investigate and respond to those threats. In this chapter, we will show you how to plan and configure your Azure Sentinel instance, explain the process of using Azure Sentinel playbooks, and finally how to monitor and manage Azure Sentinel on an ongoing basis.
After reading this chapter, you will be able to access and enable Azure Sentinel in the Azure portal, set up a Log Analytics workspace, and connect to Microsoft and third-party data sources. You will learn how to use playbooks to automate responses to security issues and understand how to manage and monitor Azure Sentinel on an ongoing basis.
In this...