isvs
40 TopicsAccelerate connectors development using AI agent in Microsoft Sentinel
Today, we’re excited to announce the public preview of a Sentinel connector builder agent, via VS code extension, that helps developers build Microsoft Sentinel codeless connectors faster with low-code and AI-assisted prompts. This new capability brings guided workflows directly into the tooling developers already use, helping accelerate time to value as the Sentinel ecosystem continues to grow. Learn more at Create custom connectors using Sentinel connector AI agent Why this matters As the Microsoft Sentinel ecosystem continues to expand, developers are increasingly tasked with delivering high‑quality, production‑ready connectors at a faster pace, often while working across different cloud platforms and development environments. Building these integrations involves coordinating schemas, configuration artifacts, Azure deployment concepts, and validation steps that provide flexibility and control, but can span multiple tools and workflows. As connector development scales across more partners and scenarios, there is a clear opportunity to better integrate these capabilities into the developer environments teams already rely on. The new Sentinel connector builder agent, using GitHub Copilot in the Sentinel VS code extension, brings more of the connector development lifecycle -- authoring, validation, testing, and deployment into a single, cohesive workflow. By consolidating these common steps, it helps developers move more easily from design to validation and deployment without disrupting established processes. Read the full announcement here: Accelerate connectors development using AI agent in Microsoft Sentinel Original Publication: Microsoft Security Community Blog, March 30th, 202661Views0likes0CommentsEmpower Real-Time Security with Microsoft Sentinel’s CCF Push Feature
In today’s rapidly evolving threat landscape, organizations need security solutions that deliver actionable insights in real time, not minutes or hours after the fact. Microsoft Sentinel continues to expand its capabilities, driven by a commitment to empower customers and partners with cutting-edge tools for proactive defense. Today, we are excited to announce the public preview of our latest innovation, the Sentinel Codeless Connector Framework (CCF) Push feature. CCF Push addresses a critical need: enabling seamless, automated, and immediate delivery of security data to Sentinel, so teams can respond to threats as they happen. What Is CCF Push and Why Does It Matter? Microsoft Sentinel connectors generally follow two patterns. In the polling pattern, partners and customers expose their web‑facing REST API endpoints and use our traditional CCF connectors to poll those endpoints at intervals to gather data for ingestion into Sentinel. In the push pattern, partners and customers send data directly to a Sentinel workspace. Our new CCF Push capability was built to streamline and accelerate time to adoption for this second pattern. Read the full announcement here: Empower Real-Time Security with Microsoft Sentinel’s CCF Push Feature Original Publication: Microsoft Sentinel Blog, February 12th, 202637Views0likes0CommentsAdvancing print readiness across the Windows on Arm ecosystem
Momentum across the Windows on Arm ecosystem continues to build as more commercial and retail customers adopt Arm-based Windows devices for everyday work. Customers are realizing tangible benefits such as improved performance per watt, longer battery life, quieter devices, and more consistent responsiveness across native Arm64 application workflows. As adoption grows, however, success depends not only on application availability, but on the readiness of foundational systems that customers rely on regardless of device or architecture. Printing, deeply embedded in business operations, remains one of the critical workflows that must keep pace. Microsoft’s Modern Print Strategy provides an important foundation for this transition, modernizing printing on Windows through standardized protocols, inbox class drivers, and extensible Print Support Apps. This approach aligns closely with the needs of Windows on Arm by reducing complexity and enabling consistent, secure printing across architectures. At the same time, Microsoft recognizes that many commercial customers depend on established print workflows, and that hardware partners continue to support these needs through universal and native print drivers. Together, these models enable both software developers and hardware partners to extend reliable print solutions to Windows on Arm, consistently and reliably. Below is a snapshot of print companies that have recently delivered or expanded solutions supporting Windows on Arm, demonstrating how the modern print ecosystem is evolving to meet customer expectations as Windows devices and the workloads they power continue to modernize ... Read the full announcement here: Advancing print readiness across the Windows on Arm ecosystem Original Publication: Microsoft Windows IT Pro Blog, May 6th, 202642Views0likes0CommentsBehind the Build with Gigamon: Enriching Microsoft Sentinel with Network-Derived Telemetry
Behind the Build is an ongoing series spotlighting standout Microsoft partner collaborations. Each edition dives into the technical and strategic decisions that shape real-world integrations—highlighting engineering excellence, innovation, and the shared customer value created through partnership. Security teams today operate across an expanding set of signals, spanning identity, endpoint, cloud and application environments. Yet many organizations still lack sufficient visibility into how systems communicate across their infrastructure, creating gaps in detection, investigation, and response. In this edition of Behind the Build, I spoke with Srinivas Chakravarty, vice president, cloud ecosystems at Gigamon, about how Microsoft and Gigamon collaborated to bring network-derived telemetry into Microsoft Sentinel, helping customers enrich security investigations with deeper runtime context and AI-driven insights. The Evolution of Network Intelligence and Why It Matters For more than twenty years, Gigamon has helped organizations access and operationalize network traffic across complex environments. Today, the Gigamon Deep Observability Pipeline, helps enable organizations to extract actionable network-derived telemetry across hybrid infrastructure, encrypted traffic, containers, and modern application environments. That foundation makes the Gigamon Deep Observability Pipeline a strong complement to Microsoft Sentinel. Microsoft Sentinel brings together security telemetry from across the enterprise—including identity, endpoint, cloud, application, and network data sources—while Gigamon contributes enriched network-derived telemetry that provides additional runtime context into how systems, applications, and services communicate. Together, these signals can help organizations gain deeper insight for threat detection, investigation, and response. As Srinivas put it: “You have logs, you have metrics, you have traces, but network telemetry completes the picture.” Together, these data sources provide deeper context for threat detection, investigation, and AI-driven analysis. Read the full announcement here: Behind the Build with Gigamon: Enriching Microsoft Sentinel with Network-Derived Telemetry Original Publication: Microsoft Sentinel Blog, June 30th, 202679Views0likes0Comments