Summary
In this chapter, we covered the integration of Azure Monitor with Microsoft Sentinel and other third-party SIEM and SOAR solutions. This included the configuration and setup of Microsoft Sentinel. Microsoft has provided the capability to integrate Azure Monitor with popular third-party SIEM and SOAR solutions, and we provided solutions and links to help with the integration process. The final section of the chapter provided steps to run Kusto queries with Log Analytics to review Azure AD activity, along with Azure AD workbooks for monitoring Azure AD activity.
The next chapter will provide practice questions to help you in your final preparation for the Identity and Access Administrator Associate exam.