Planning and configuring Azure Sentinel
The first steps you need to take when planning to use Azure Sentinel for your organization is to enable Azure Sentinel itself, and then connect it to your organization's data sources. Azure Sentinel has several native Microsoft connectors that enable integration with other Microsoft services, such as Azure Active Directory, Office 365, Microsoft Defender for Identity, Microsoft Cloud App Security, and many more.
It is also possible to configure Azure Sentinel to connect to non-Microsoft services, and use connection methods such as Syslog, REST API, or the Common Event Format (CEF).
Knowing what you are looking to achieve by deploying Azure Sentinel within your Microsoft 365 environment will help you to plan which connectors you need in order to achieve your objectives.
Once you know which data sources you need to connect to, you can connect to them and use several available workbooks that provide insights on your data.
So how...