Blog Post

Microsoft Sentinel Blog
4 MIN READ

What’s new in Microsoft Sentinel: August 2026

spalani's avatar
spalani
Icon for Microsoft rankMicrosoft
Aug 31, 2026

Welcome back to What's new in Microsoft Sentinel. This August, Sentinel innovation kicks off with the AI-powered playbook generator, generally available to all Sentinel customers in the Microsoft Defender portal. Meanwhile, User and Entity Behavior Analytics (UEBA) anomalies enter public preview on the Behaviors layer, with coverage across Fortinet, AWS GuardDuty, Check Point, and Zscaler. In Sentinel data lake, nested API support in the Codeless Connector Framework (CCF) enters public preview to connect data sources whose APIs span multiple calls, and multi-account data ingestion is now generally available for Auth0, CrowdStrike, and Salesforce. Finally, the free Microsoft Threat Intelligence connector for unified SecOps, marking the final phase of MDTI convergence, is now generally available in the Defender portal.

Read on for the details, and explore our resources at the end to go deeper.

Sentinel innovations:

Sentinel SIEM

AI-powered playbook generator expanded to all Sentinel customers in the Defender portal [Generally Available]

Go from intent to action faster with the AI-powered playbook generator. It is available to all Sentinel customers using the Defender portal with no Security Copilot enablement or additional cost required. Describe the response you want in natural language and generate an editable, code-based playbook complete with tests, documentation, and a visual flow.

Figure 1: Automatically-created visual flow diagram of the playbook.

To get started, confirm you have Automation Playbooks Unified RBAC Read and Write permissions, then select Automation > + Create > Playbook Generator. Read our blog to learn more.

UEBA Anomalies are now built on top of Behaviors, along with expanded coverage through new data sources [Public Preview]

Understand what happened and why it matters in one place. Sentinel adds UEBA anomaly insights and explainable context directly to the Behaviors layer, while expanding coverage across Fortinet, AWS GuardDuty, Check Point, and Zscaler data. This helps you identify unusual activity across identity, network, and cloud environments, reduce investigation time, and focus on the highest-risk behaviors. Enable the Behaviors layer, connect supported data sources, and explore the Insights column in the BehaviorInfo table to get started. Read our blog to learn more and watch our training video for a guided walkthrough.

Sentinel data lake

Nested API support in Codeless Connector Framework [Public Preview]

Nested API support in the Sentinel Codeless Connector Framework (CCF) handles the list-then-detail pattern common across ISV log sources, where a single polling cycle spans multiple dependent API calls. An initial call returns a list of records such as alert IDs or case references, and one or more follow-up calls fetch the full detail for each record in that list. This means you can connect data sources whose APIs are naturally paginated across multiple calls and ingest complete records into Sentinel without building custom middleware or restructuring your endpoints. The pattern is also available through the Visual Studio Code (VS Code) extension for Sentinel connectors, which gives you a guided way to build, test, and package connectors that orchestrate chained requests. Read our blog to learn more, or try it with mock data in our Nested API Lab.

Multi-account ingestion for Auth0, CrowdStrike, and Salesforce [Generally Available]

Sentinel data connectors for Auth0, CrowdStrike Falcon, and Salesforce Service Cloud now support multi-account ingestion — powered by the Codeless Connector Framework (CCF). You can now connect and monitor multiple accounts or tenants from a single, unified connector configuration — no scripts, no hacks.

🔑 Auth0 — Multi-tenant identity monitoring

Security teams managing multiple Auth0 tenants can now ingest logs from all of them into a single Sentinel workspace. Get complete visibility into authentication events, anomalous login patterns, and policy violations across every tenant without switching contexts.

🦅 CrowdStrike Falcon — Consolidated endpoint telemetry

Organizations running multiple CrowdStrike tenants (e.g., across M&A entities or regional subsidiaries) can now stream detection alerts, threat intelligence, and endpoint telemetry from all tenants into Sentinel. One workspace. Full coverage.

☁️ Salesforce — Cross-org security insights

Enterprises with multiple Salesforce orgs can now centralize audit logs, login history, and API activity across all orgs. Detect insider threats, unauthorized access, and compliance gaps without stitching data together manually.

Get started with multi-account ingestion by finding your supported Sentinel data connector.

Microsoft Threat Intelligence connector [Generally Available]

The final phase of Microsoft Defender Threat Intelligence (MDTI) convergence is generally available in the Defender portal, giving you real-time Microsoft threat intelligence across detection, investigation, response, hunting, and automation at no additional cost. The result is a unified SecOps experience that reduces fragmented context and tool handoffs, and creates a clear path from threat signal to informed action. Microsoft Threat Intelligence data that previously required the Premium MDTI connector is available through the free Microsoft Threat Intelligence connector in Sentinel, enabling free and premium indicator feeds through one setup. MDTI APIs are also included for Sentinel customers without a separate license, and the API surface is unchanged, so no migration action is required. Read the blog to learn more.

Additional resources

Blogs and documentation:

Upcoming webinars:

Stay connected

Check back each month for the latest innovations, updates, and events to ensure you’re getting the most out of Microsoft Sentinel. We’ll see you in the next edition!

Updated Aug 28, 2026
Version 1.0