Manage security alerts in Microsoft 365 security center(MTP), Sentinel or separately?

%3CLINGO-SUB%20id%3D%22lingo-sub-1670681%22%20slang%3D%22en-US%22%3EManage%20security%20alerts%20in%20Microsoft%20365%20security%20center(MTP)%2C%20Sentinel%20or%20separately%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1670681%22%20slang%3D%22en-US%22%3E%3CP%3EI%20am%20having%20some%20questions%20and%20would%20like%20to%20receive%20opinions%20that%20can%20contribute.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20the%20solutions%20in%20my%20environment%20and%20I'm%20in%20doubt%20about%20how%20to%20centralize%20everything.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20Azure%20Sentinel%20receiving%20the%20Defender%20Atp%2C%20MCASB%2C%20Azure%20ATp%2C%20Office%20365%20ATp%20logs%2C%20among%20others.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20also%20have%20MCAS%20integrated%20with%20Azure%20ATP.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20question%20is.%20Where%20should%20all%20technologies%20be%20centralized%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThat%20is%2C%20if%20I%20use%20Microsoft%20365%20Security%20Center%20to%20centralize%20Defender%20ATP%2C%20Azure%20ATP%2C%20MCAS%20and%20Office%20ATP%2C%20does%20it%20still%20make%20sense%20to%20receive%20these%20logs%20in%20Sentinel%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWould%20it%20be%20possible%20to%20integrate%20alerts%20generated%20in%20Sentinel%20with%20Microsoft%20365%20Security%20Center%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20I%20receive%20the%20solution%20logs%20on%20Sentinel%2C%20what%20would%20be%20the%20meaning%20of%20Microsoft%20365%20Security%20Center%3F%20Can%20I%20work%20with%20both%2C%20centralizing%20the%20solutions%20in%20both%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20know%20that%20there%20may%20not%20be%20a%20final%20answer%2C%20but%20I%20would%20be%20happy%20to%20get%20your%20position.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1830824%22%20slang%3D%22en-US%22%3ERe%3A%20Manage%20security%20alerts%20in%20Microsoft%20365%20security%20center(MTP)%2C%20Sentinel%20or%20separately%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1830824%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F733311%22%20target%3D%22_blank%22%3E%40luizao_lf%3C%2FA%3E%26nbsp%3BSimilar%20questions.%20Did%20you%20make%20any%20headway%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

I am having some questions and would like to receive opinions that can contribute.

 

I have the solutions in my environment and I'm in doubt about how to centralize everything.

 

I have Azure Sentinel receiving the Defender Atp, MCASB, Azure ATp, Office 365 ATp logs, among others.

 

I also have MCAS integrated with Azure ATP.

 

The question is. Where should all technologies be centralized?

 

That is, if I use Microsoft 365 Security Center to centralize Defender ATP, Azure ATP, MCAS and Office ATP, does it still make sense to receive these logs in Sentinel?

 

Would it be possible to integrate alerts generated in Sentinel with Microsoft 365 Security Center?

 

If I receive the solution logs on Sentinel, what would be the meaning of Microsoft 365 Security Center? Can I work with both, centralizing the solutions in both?

 

I know that there may not be a final answer, but I would be happy to get your position.

 

Thank you.

1 Reply

@luizao_lf Similar questions. Did you make any headway