Event banner
AMA: Microsoft SIEM & XDR: unified security operations
Event details
At Microsoft Ignite we announced that we are bringing our Microsoft Sentinel and Microsoft Defender XDR products together to deliver an optimized and unified security operations experience. We are combining the full power of these products into a single portal enhanced with more comprehensive features, automation, guided experiences, and Microsoft Security Copilot. Bring your questions to this Ask Microsoft Anything (AMA) as members of our Microsoft Security engineering team bring clarity and insights about this new experience.
This session is part of the Microsoft Security Tech Accelerator. RSVP for event reminders, add it to your calendar, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event. |
41 Comments
- sarabischof
Microsoft
Enhance what you know and have learned through skilling modules and learning paths – visit Microsoft Learn for more!
- sarabischof
Microsoft
If you don’t have one yet, create your Tech Community profile today!
- Dean_GrossSilver ContributorFor MSSPs that are using Lighthouse to access their clients Sentinel Workspace, what do they need to do to access this new combined experience in M365 XDR?
- GBushey
Microsoft
As of right now, the use of multiple Sentinel instances will not work with M365 XDR. We are working to get that resolved.
- Char_CheesmanBronze Contributor
In addition to the questions posted on this page, we also answer questions posted in reply to the event on LinkedIn and Twitter. Here are the questions we answered today:
- QUESTION -- We need to separate visibility on Sentinel vs XDR in the portal. Is that possible? Some users for example should not be able to see Sentinel data from 3rd party sources. - answered at 01:20.
- QUESTION -- Does onboarding to Unified portal bring changes to our connected workspace? - answered at 06:40.
- QUESTION -- Does the unification merge XDR Custom Detections and Analytics rules into one feature? If not, how does it work now? - answered at 11:20.
- Trevor_Rusher
Community Manager
That concludes the live stream for the Microsoft SIEM & XDR: unified security operations AMA. We’ll continue to answer your questions here in the chat for the rest of the hour and follow up after as needed. Up next: Leveraging Microsoft Entra ID (Azure AD) to counter Token Theft.
If you missed the live broadcast, don’t worry—you can watch it on demand. And we’ll continue to answer questions here in the chat through the end of the week. There's more great content in store at the Microsoft Security Tech Accelerator! What do you like about the event so far? Share your feedback and help shape the direction of future events on the Tech Community!
- Duncan de WaalBrass Contributor@preeti thanks - my previous question was also a bit in the context that ingesting data into Sentinel is expensive when talking about several TB a day (even when using cheaper Tiers etc). I hope to believe that what is underneath XDR is more cost efficient (kusto clusters or whatever) @julian thanks for explaining these are two different pieces of value.
- GBushey
Microsoft
There has not been any change to the underlying storage mechanism of any of the products, only the UI.
- ahmadmozaffar99Copper ContributorI have a question regarding the API, currently the the Defender incidents/alerts API can be accessed through the Defender XDR endpoints and through Microsoft Graph API, which one will be recognized and what do you recommend to go for? The other question is Sentinel API feels more mature, like the filtering of the incidents and everything works so well but Defender is very limited will the Defender or Graph will support all the OData filtering options like the Sentinel API?
- GBushey
Microsoft
The API ecosystem is still be worked on. There will be announcements regarding APIs in the future.
- MrsKellyC
Microsoft
Great questions! There is only a few more minutes left in the session so please make sure to ask your questions before the session ends. - ItunicornCopper Contributor
Will the Advanced hunting shortcuts and other interface features in Sentinel advanced hunting be available XDR?
- GBushey
Microsoft
Can you clarify what you mean by "Sentinel advanced hunting"? Are you talking about threat hunting, notebooks, something else?- ItunicornCopper ContributorAn example in Sentinel Advanced Hunting "crtl+enter" starts a new line with the pipe, in XDR "ctrl+enter" runs the query. I am learning KQL using Kusto Explorer and Sentinel query interface shortcuts are closer to Kusto Explorer than XDR. Hope that makes sense.
- Duncan de WaalBrass ContributorWill there be a moment where custom log sources can be onboarded (like firewall logs) on the Defender XDR side so without having the need for Sentinel at all? Or should I see it more that Sentinel will become a sub-feature of XDR that is taking care of all those external (non-Microsoft) log sources?
- GBushey
Microsoft
Sentinel will still have a purpose in the M365 XDR offering as it provides features not found in other products included in M365 and can gather information from different sources.