As we move closer to general availability (GA), you will see many changes in the Azure Sentinel. While true to the cloud, we release them as they are ready, the formal announcement will come with GA. This blog post lists some that may require your attention beforehand.
Those are already online today:
- We are replacing the current Dashboards with Workbooks, which offer many new features not available with the current dashboards. Note that dashboards will be removed from Azure Sentinel with GA. You will still be able to access them using the Azure portal outside of Azure Sentinel.
- The API to enable and disable Fusion in Azure Sentinel is going to be deprecated. We are making it easier to configure with an option in the UI, and it will be turned ON by default.
- As promised, the new Analytics screen includes a large number of rules out of the box in the "rules templates" tab. Apart from Fusion, those are not active by default. Make sure you apply those that are relevant to you using the "create rule" button for each template.
While still not available today, note that the method to deploy CEF connectors would also change and will be more straightforward. The change would not affect any existing CEF connector as it related only to the deployment process.
Microsoft Sentinel is a cloud-native SIEM, enriched with AI and automation to provide expansive visibility across your digital environment.
When evaluating various solutions, your peers value hearing from people like you who’ve used the product. Review Microsoft Sentinel by filling out a Gartner Peer Insights survey and receive a $25 USD gift card (for customers only). Here are the Privacy/Guideline links: Microsoft Privacy Statement, Gartner’s Community Guidelines & Gartner Peer Insights Review Guide.