Understanding Microsoft 365 Defender’s relationship with Sentinel
As explained in the introduction to this chapter, Sentinel allows for security response and incident management to many different services. This is achieved using data connectors.
Included in the Microsoft 365 Defender connector are the main services of MDE, MDI, MDO, and MDA. You’ll also find services not strictly under the Microsoft 365 Defender banner but that produce alerts there, such as Azure AD Identity Protection and Microsoft Purview DLP.
If you’re a Sentinel customer, enabling these integrations means you can stick with Sentinel as the go-to interface for alert and incident response, rather than having to jump between it and Microsoft 365 Defender’s queue. This improves your time to respond, as well as the benefits of a broader picture thanks to connectors. It also provides a means to improve your retention beyond Microsoft 365 Defender’s limit of 30 days for advanced...