Welcome back to What's new in Microsoft Sentinel. This August, Sentinel innovation kicks off with the AI-powered playbook generator, generally available to all Sentinel customers in the Microsoft Defender portal. Meanwhile, User and Entity Behavior Analytics (UEBA) anomalies enter public preview on the Behaviors layer, with coverage across Fortinet, AWS GuardDuty, Check Point, and Zscaler. In Sentinel data lake, nested API support in the Codeless Connector Framework (CCF) enters public preview to connect data sources whose APIs span multiple calls, and multi-account data ingestion is now generally available for Auth0, CrowdStrike, and Salesforce. Finally, the free Microsoft Threat Intelligence connector for unified SecOps, marking the final phase of MDTI convergence, is now generally available in the Defender portal.
Read on for the details, and explore our resources at the end to go deeper.
Sentinel innovations:
Sentinel SIEM
AI-powered playbook generator expanded to all Sentinel customers in the Defender portal [Generally Available]
Go from intent to action faster with the AI-powered playbook generator. It is available to all Sentinel customers using the Defender portal with no Security Copilot enablement or additional cost required. Describe the response you want in natural language and generate an editable, code-based playbook complete with tests, documentation, and a visual flow.
Figure 1: Automatically-created visual flow diagram of the playbook.To get started, confirm you have Automation Playbooks Unified RBAC Read and Write permissions, then select Automation > + Create > Playbook Generator. Read our blog to learn more.
UEBA Anomalies are now built on top of Behaviors, along with expanded coverage through new data sources [Public Preview]
Understand what happened and why it matters in one place. Sentinel adds UEBA anomaly insights and explainable context directly to the Behaviors layer, while expanding coverage across Fortinet, AWS GuardDuty, Check Point, and Zscaler data. This helps you identify unusual activity across identity, network, and cloud environments, reduce investigation time, and focus on the highest-risk behaviors. Enable the Behaviors layer, connect supported data sources, and explore the Insights column in the BehaviorInfo table to get started. Read our blog to learn more and watch our training video for a guided walkthrough.
Sentinel data lake
Nested API support in Codeless Connector Framework [Public Preview]
Nested API support in the Sentinel Codeless Connector Framework (CCF) handles the list-then-detail pattern common across ISV log sources, where a single polling cycle spans multiple dependent API calls. An initial call returns a list of records such as alert IDs or case references, and one or more follow-up calls fetch the full detail for each record in that list. This means you can connect data sources whose APIs are naturally paginated across multiple calls and ingest complete records into Sentinel without building custom middleware or restructuring your endpoints. The pattern is also available through the Visual Studio Code (VS Code) extension for Sentinel connectors, which gives you a guided way to build, test, and package connectors that orchestrate chained requests. Read our blog to learn more, or try it with mock data in our Nested API Lab.
Multi-account ingestion for Auth0, CrowdStrike, and Salesforce [Generally Available]
Sentinel data connectors for Auth0, CrowdStrike Falcon, and Salesforce Service Cloud now support multi-account ingestion — powered by the Codeless Connector Framework (CCF). You can now connect and monitor multiple accounts or tenants from a single, unified connector configuration — no scripts, no hacks.
🔑 Auth0 — Multi-tenant identity monitoring
Security teams managing multiple Auth0 tenants can now ingest logs from all of them into a single Sentinel workspace. Get complete visibility into authentication events, anomalous login patterns, and policy violations across every tenant without switching contexts.
🦅 CrowdStrike Falcon — Consolidated endpoint telemetry
Organizations running multiple CrowdStrike tenants (e.g., across M&A entities or regional subsidiaries) can now stream detection alerts, threat intelligence, and endpoint telemetry from all tenants into Sentinel. One workspace. Full coverage.
☁️ Salesforce — Cross-org security insights
Enterprises with multiple Salesforce orgs can now centralize audit logs, login history, and API activity across all orgs. Detect insider threats, unauthorized access, and compliance gaps without stitching data together manually.
Get started with multi-account ingestion by finding your supported Sentinel data connector.
Microsoft Threat Intelligence connector [Generally Available]
The final phase of Microsoft Defender Threat Intelligence (MDTI) convergence is generally available in the Defender portal, giving you real-time Microsoft threat intelligence across detection, investigation, response, hunting, and automation at no additional cost. The result is a unified SecOps experience that reduces fragmented context and tool handoffs, and creates a clear path from threat signal to informed action. Microsoft Threat Intelligence data that previously required the Premium MDTI connector is available through the free Microsoft Threat Intelligence connector in Sentinel, enabling free and premium indicator feeds through one setup. MDTI APIs are also included for Sentinel customers without a separate license, and the API surface is unchanged, so no migration action is required. Read the blog to learn more.
Additional resources
Blogs and documentation:
- Investigate anomalies on UEBA behaviors in Microsoft Sentinel | Microsoft Learn
- UEBA behaviors layer pricing model in Microsoft Sentinel | Microsoft Learn
- Turn Complexity into Clarity: Introducing the New UEBA Behaviors Layer in Microsoft Sentinel | Microsoft Community Hub
- Microsoft Sentinel’s AI-driven UEBA ushers in the next era of behavioral analytics | Microsoft Community Hub
- Create pull codeless data connectors using nested API polling | Microsoft Learn
- View threat intelligence in entity pages in Microsoft Defender - Microsoft Defender XDR | Microsoft Learn
- Microsoft Threat Intelligence in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learn
Upcoming webinars:
- Sep 2: Microsoft Security Immersion Event: Agent Hackathon
- Sep 8: Security Immersion Event: Into the Breach
- Sep 8–9: Microsoft Virtual Training Day: Predict and Defend Against Cybersecurity Threats
- Sep 22: Tech Brief: Modernize security operations with a unified platform
- Sep 23: Microsoft Security Immersion Event: Shadow Hunter
Stay connected
Check back each month for the latest innovations, updates, and events to ensure you’re getting the most out of Microsoft Sentinel. We’ll see you in the next edition!
Microsoft Sentinel is an industry-leading SIEM & AI-first platform powering agentic defense across the entire security ecosystem.