Enabling and onboarding Microsoft Sentinel
At this point, all of the heavy prerequisite lifting is complete! You will be thrilled to know that enabling and onboarding Microsoft Sentinel is rather easy! It normally comes down to the planning and costing discussions you have already had, which makes this a bit more time-consuming.
To begin, we recommend leveraging the wide variety of connectors that Microsoft provides from its solutions, as well as gallery-based connectors (for example, Palo Alto Network Firewalls). This will be the quickest way to onboard your data source into Microsoft Sentinel.
Some recommended starting points are as follows:
- Microsoft 365 Defender (formerly Microsoft Threat Protection)
- Microsoft 365 data sources
- Office 365 data sources
- Microsoft Defender for Cloud Apps
- Microsoft Defender for Cloud
- Azure Active Directory Identity Protection
- Azure Activity
- Syslog
- Common Event Format (CEF) connectors
- REST APIs