Summary
In this chapter, you learned that Microsoft Sentinel is a SIEM and SOAR solution that improves the single-pane-of-glass desire of SOC teams. Where Microsoft 365 Defender goes deep for the services it is scoped to (MDE, MDO, MDI, MDA, and MDVM), Sentinel goes broad.
If your team already uses Sentinel, you now know the advantages of creating the sync between it and Microsoft 365 Defender, as well as how that sync operates, with bi-directional integration for improved response times and incident management. We covered the steps for creating the three types of integration (incidents/alerts, advanced hunting data, and UEBA) so that you can maximize your investment in the platform.
Sentinel’s SOAR capabilities offer a means to automate security incident response. In the next chapter, we’ll look at the APIs that allow programmatic access to Microsoft 365 Defender for additional automation and integration capabilities.