Event banner

AMA: Microsoft SIEM & XDR: unified security operations

Event Ended
Wednesday, Dec 06, 2023, 09:30 AM PST
Online

Event details

At Microsoft Ignite we announced that we are bringing our Microsoft Sentinel and Microsoft Defender XDR products together to deliver an optimized and unified security operations experience. We are combining the full power of these products into a single portal enhanced with more comprehensive features, automation, guided experiences, and Microsoft Security Copilot. Bring your questions to this Ask Microsoft Anything (AMA) as members of our Microsoft Security engineering team bring clarity and insights about this new experience.

This session is part of the Microsoft Security Tech Accelerator. RSVP for event reminders, add it to your calendar, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event.

 

Heather_Poulsen
Updated Dec 27, 2024

41 Comments

  • Can you explain a bit on Microsoft assessing a customer's backend? I understood that there is something of an impact assessment that is done by Microsoft to identity if there's anything that become problematic in the unification process. As an very early-day Sentinel customer we might have implemented things or way-of-working that requires us to reconsider things.
    • Char_Cheesman's avatar
      Char_Cheesman
      Bronze Contributor

      Thanks for participating in today's AMA: Microsoft SIEM & XDR: unified security operations! For reference, the panel covered this topic at around 21:00.

  • Murilo_Amorim's avatar
    Murilo_Amorim
    Copper Contributor
    Which license should I have for Security Copilot? is that a minumum users license required? Thank you
    • Char_Cheesman's avatar
      Char_Cheesman
      Bronze Contributor

      Thanks for participating in today's AMA: Microsoft SIEM & XDR: unified security operations ! For reference, the panel covered this topic at around 17:20.

  • Will things such as watchlists become available at the M365 Defender XDR side? If yes when?
  • Can you outline the milestones or moments in the unification process where existing functionality is impacted, so beyond the single-pane-of-glass where something really changes or is no longer available anymore (either on the M365 Defender side or on the Sentinel side)?
    • Char_Cheesman's avatar
      Char_Cheesman
      Bronze Contributor

      Thanks for participating in today's AMA: Microsoft SIEM & XDR: unified security operations ! For reference, the panel covered this topic at around 14:20.

  • Trevor_Rusher's avatar
    Trevor_Rusher
    Icon for Community Manager rankCommunity Manager
    Welcome to the Microsoft SIEM & XDR: unified security operations AMA and Microsoft Security Tech Accelerator. Let's begin! Please post your questions here in the Comments. We will be answering questions in the live stream—and others will be answering here in the Comments.
  • Trevor_Rusher's avatar
    Trevor_Rusher
    Icon for Community Manager rankCommunity Manager
    Welcome! The Microsoft SIEM & XDR: unified security operations AMA will start soon. What questions do you have for our experts? Post them now and we’ll use them to kick off the session!
  • RafaelRuales22's avatar
    RafaelRuales22
    Copper Contributor

    When will the Unified XDR + Sentinel portal be available (live) for GCC customers?

    • Char_Cheesman's avatar
      Char_Cheesman
      Bronze Contributor

      Thanks for participating in today's AMA: Microsoft SIEM & XDR: unified security operations! For reference, the panel covered this topic at around 03:50.

      • RafaelRuales22's avatar
        RafaelRuales22
        Copper Contributor
        Thank you @Charlize. Is there a link anywhere in the MS documentation that has the time frames, specifically mentioning GCC customers, for the deployment in General availability of this unified portal?
  • Amjad1935's avatar
    Amjad1935
    Brass Contributor
    Will you be adding the new look and feel of Defender XDR into your MS Customer Digital Experiences? It would be very useful to showcase all the new features you have added into XDR. A Security co-pilot within Defender XDR, Customer Immersion Experience would be very useful.
    • Char_Cheesman's avatar
      Char_Cheesman
      Bronze Contributor

      Thanks for participating in today's AMA: Microsoft SIEM & XDR: unified security operations ! For reference, the panel covered this topic at around 04:35.

  • Amjad1935's avatar
    Amjad1935
    Brass Contributor
    Will you be updating the Unified RBAC model to include Sentinel and Defender for Cloud as separate workloads? and secondly, is there a road map for Security copilot to support the Unified RBAC model?
    • Char_Cheesman's avatar
      Char_Cheesman
      Bronze Contributor

      Thanks for participating in today's AMA: Microsoft SIEM & XDR: unified security operations! For reference, the panel covered this topic at around 02:40.

    • GBushey's avatar
      GBushey
      Iron Contributor

      There are plans to add Sentinel and Defender for Cloud to URBAC, but no dates have been set. No insights into Security CoPilot

  • Questions about SIEM and XDR? Post them in advance here in the Comments so our panel can address them during this live AMA!

    • brennantom's avatar
      brennantom
      Copper Contributor
      Any bootcamp training on East Coast for new team members that want to dive deep?
Date and Time
Dec 6, 20239:30 AM - 10:00 AM PST