No more typing reviews! Try our Samantha, our new voice AI agent.
Solutions Architect at a tech vendor with 201-500 employees
Real User
Top 20
May 5, 2025
Creates value with advanced investigation capabilities while seeking improved integration with varied platforms
Pros and Cons
  • "A lot of the automation inside Sentinel comes with inside actually rolling out brand new Sentinel environments. We utilize that a lot and it might go beyond just Sentinel, for example, utilizing templates in Azure and templates elsewhere to actually deploy out."
  • "Microsoft Sentinel stands out mainly for its signal-to-noise reduction; LogRhythm required numerous AI rules to reach a similar level of noise reduction."
  • "My primary improvement request would be for auxiliary logs, as they represent our biggest need."
  • "The integration challenges arise from both sides; Google tends to be noisy, and we find only ten analytic rules out of the box, necessitating the use of Defender for Cloud for alerts, which indicates a need for better documentation during deployment."

What is our primary use case?

Our use cases include working with clients by installing it for them, deploying it within our own organization, and I personally utilize it as a Solutions Architect for demo purposes, etc. 

What is most valuable?

The features that I or my customers consider most valuable within Microsoft Sentinel include the ability to query, the integration with the rest of the Defender and the Microsoft suites, and the workbooks and dashboards.

The ability to query is valuable to us because it allows you to drill down to specific information that you need and even drill down further from there. It really helps you get at the information, especially from an investigative perspective, that you need. With the workbook dashboards, once you find a good information set or data set, let you flip that around and turn it into a dashboard so it can be repeatable and visible to other folks in the organization.

Microsoft Sentinel's ability to correlate data from multiple sources enhances our threat detection capabilities beyond what is a simple data lake solution by filtering out the noise and consolidating the signal down to a meaningful level that is easier to investigate and see. It allows us to truly see what is going on and gives us that focused visibility.

It does provide actionable data, not just visibility, as it can provide insights beyond what a normal data stream could give you.

The integration of security functionalities such as SIEM, SOAR, TIP, and UEBA in Microsoft Sentinel is well-executed, particularly the seamless integration of UEBA. However, there is confusion between UEBA and Defender for Identity that needs to be explored further. Microsoft has defined the XDR level, but from an MSSP perspective, the SOAR capability is integrated adequately, while customers might not fully utilize it yet due to marketing factors.

Creating an awareness campaign for these integrations would be beneficial.

The impact of Microsoft Sentinel on our advanced hunting abilities has been significant because it allows us to really hone in from an investigative perspective and dive deeper into investigations. Even without access to a customer's environment, we capture a lot of data and can drill down on specifics like when and from where emails were sent, what their content was, and so on. It provides us with a complete attack story and history.

Up until recently, the MITRE ATT&CK integration in Microsoft Sentinel was based on an older version, rendering it less meaningful, but now with the upgrade to the latest version, it allows us to map our threat intelligence efficiently to the MITRE framework, which has been beneficial.

I would highlight the new case management feature as great. Its presence gives Microsoft Sentinel an edge as many other SIEMs have had mature case management capabilities. Additionally, as it becomes part of the Defender portal, the journey and integration narrative between Sentinel and the complete Defender XDR should be better defined, especially since more customers opt for Sentinel only.

Having a great CX team within Microsoft enhances the experience, although having a distracted account manager lessens focus on critical details for customer needs.

A lot of the automation inside Sentinel comes with inside actually rolling out brand new Sentinel environments. We utilize that a lot and it might go beyond just Sentinel, for example, utilizing templates in Azure and templates elsewhere to actually deploy out. A good scenario is when customer environments have multi tenancy. Being able to roll out those additional tenants with the automation has been huge. We went from it taking 20 hours to build a tenant to a matter of two to four hours. That's a 75% savings. 

The SOC optimization is a big part of what we do. We have to manage our own costs, however, we have built in automations for reporting to trigger when data is exposed. I have one customer that had 225 GBs a day when onboarded, and now we're down to 110 GBs. As far as our reporting, it does help everything become more efficient.

What needs improvement?

My primary improvement request would be for auxiliary logs, as they represent our biggest need.

While we have automated deployments now, Microsoft Sentinel is fairly easy to deploy, although we face challenges with integrations related to AWS and GCP, particularly with Google.

The integration challenges arise from both sides; Google tends to be noisy, and we find only ten analytic rules out of the box, necessitating the use of Defender for Cloud for alerts, which indicates a need for better documentation during deployment.

The story between UEBA and Defender for Identity and Intra needs to be further explored and defined. There's some confusion on what is happening from a user and entity behavior. 

For how long have I used the solution?

I have been using Microsoft Sentinel on and off for two years.

Buyer's Guide
Microsoft Sentinel
August 2026
Learn what your peers think about Microsoft Sentinel. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
912,022 professionals have used our research since 2012.

What do I think about the stability of the solution?

Overall, I find Microsoft Sentinel to be pretty stable; in contrast, LogRhythm was less reliable and required consistent support for various components. We don't experience as many issues with the MMA agents and sensors in Sentinel.

What do I think about the scalability of the solution?

Microsoft Sentinel does possess scalability from smaller to larger organizations and has been improving in terms of multi-tenancy, particularly as we had built our own multi-tenant platform ahead of Microsoft's documentation release.

Larger organizations experience more complexity, often requiring more advanced support, and we occasionally find ourselves ahead in technology knowledge compared to the Microsoft team, leading to challenges with support response.

How are customer service and support?

From a partner perspective, our support experience with Microsoft has been decent. It can improve once we are fully validated as a named partner. Customer support has been adequate overall.

Support is more streamlined at the smaller end.

There's a need for higher-level knowledge in the support provided.

Which solution did I use previously and why did I switch?

Before Microsoft Sentinel, we used LogRhythm internally, and we also supported LogRhythm, AlienVault, and Splunk.

Microsoft Sentinel stands out mainly for its signal-to-noise reduction; LogRhythm required numerous AI rules to reach a similar level of noise reduction. Additionally, Microsoft is cloud-first compared to LogRhythm's on-prem setup, which required resources to navigate the cloud successfully. While AlienVault is simpler and good for small to medium clients, it lacks the deep automation and analytics Microsoft offers.

How was the initial setup?

I have deployed Microsoft Sentinel in various cloud environments and on-premises. Our focus typically lies with SMB, deploying it to organizations ranging from 50 users to about 2,000 users.

While we have automated deployments now, Microsoft Sentinel is fairly easy to deploy, although we face challenges with integrations related to AWS and GCP, particularly with Google.

What was our ROI?

I see ROI from using Microsoft Sentinel, particularly when transitioning from Splunk, yielding cost savings of about 100%. The reduction in billable events or messages per second can be between 25% to 45% with Sentinel, leading directly to cost reductions and enhanced time savings during investigations compared to the depth offered by tools like LogRhythm.

Which other solutions did I evaluate?

Specific SIEMs noted for their strong out-of-the-box reporting include LogRhythm, Splunk, Exabeam, and Securonix. Microsoft is actively working on improving out-of-the-box content and reports, while the ability to utilize KQL for reports, workbooks, and analytic rules is quite beneficial.

What other advice do I have?

For one customer, SOC optimization reduced their daily usage from about 225 gigs a day down to about 110 gigs a day.

Microsoft Sentinel doesn't impact our reporting directly. That said, it makes the end customer's compliance reporting process more efficient. I cannot provide a specific time saved number, but it does improve efficiency.

Technically, we expect to move about 45% of our log data to auxiliary logs since implementing Microsoft Sentinel. This expectation exists since auxiliary is still in preview and not fully functional yet. We would love to do it, however, in most environments we manage, the feature is still grayed out, making it unavailable. It is currently one of our biggest needs.

Microsoft Sentinel is perfect for mid-sized companies, however, it can also scale for smaller clients up to large enterprises due to its adaptability. Smaller customers may increasingly turn to the Defender Unified Security Operations platform for correlation instead of adopting Sentinel as a full SIEM.

On a scale of one to ten, the overall solution rating is nine.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer2811336 - PeerSpot reviewer
Senior VP, Strategy at a tech vendor with 51-200 employees
Real User
Top 10
Mar 24, 2026
External threat intel integration with Microsoft Sentinel
Pros and Cons
  • "The features of Microsoft Sentinel that I appreciate the most include the app integration."
  • "Microsoft Sentinel's ability to correlate data from multiple sources does not enhance our threat detection capabilities beyond what a simple data lake solution could offer, as we are a developer, so it is not necessarily applicable."

What is our primary use case?

My main use case for Microsoft Sentinel is being able to put external threat intel into Sentinel.

What is most valuable?

The features of Microsoft Sentinel that I appreciate the most include the app integration. I think it is straightforward; there were a couple of hiccups, but generally, it is very straightforward.

I do not consider it so much a benefit to our organization because it results in the use of our products. It is actually a benefit to Microsoft Sentinel customers, which we are a secondary beneficiary of.

What needs improvement?

For us, improving Microsoft Sentinel would involve tying its usage closer to email threat telemetry and making it easier for folks that either use Defender and email to use Sentinel.

For how long have I used the solution?

I have used Microsoft Sentinel for one year.

What do I think about the stability of the solution?

I do not have any experience with the stability and reliability of Microsoft Sentinel, other than technical support as a developer, and I have not experienced any downtime, crashes, or performance issues.

Which solution did I use previously and why did I switch?

Before adopting Microsoft Sentinel, we were supporting other solutions.

Which other solutions did I evaluate?

The other solutions we considered before selecting Microsoft Sentinel were based on market reach, feature set, and go-to-market opportunities, as we are a developer.

What other advice do I have?

Microsoft Sentinel does not give us a unified set of tools to detect, investigate, and respond to incidents, as we do not make use of those at this moment.

I do not know specifically about Microsoft Sentinel, but in general, I am a big supporter and believer in the effectiveness of AI and machine learning in enhancing threat detection and response.

Microsoft Sentinel's ability to correlate data from multiple sources does not enhance our threat detection capabilities beyond what a simple data lake solution could offer, as we are a developer, so it is not necessarily applicable.

The SOC optimization feature's impact on our organization's data management and cost efficiency is not applicable.

My advice to other organizations considering Microsoft Sentinel is that they ought to consider all solutions based on their needs. I do not have a particularly strong feeling one way or the other about Microsoft Sentinel, with a rating of zero out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 24, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Microsoft Sentinel
August 2026
Learn what your peers think about Microsoft Sentinel. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
912,022 professionals have used our research since 2012.
Director, Strategic Alliances at Armor Defense Inc.
Real User
Top 10
Apr 30, 2025
Empowers teams to triage security incidents faster and connect third-party log sources
Pros and Cons
  • "Microsoft Sentinel is cloud native, which is a significant advantage. The data connectors that provide the ability to connect third-party log sources are highly valuable."
  • "We have seen at least a 60% increase in efficiency with Microsoft Sentinel and the ability to reduce the MTTD down to under five minutes and MTTR down to under fifteen."
  • "Driving deeper integration with the Defender XDR portal within Microsoft Sentinel, which is being done, and continuing to increase the number of third-party data connectors available is important."
  • "Their support can be challenging at times, particularly around unique experiences or circumstances with Microsoft Sentinel."

What is our primary use case?

We're an MDR provider, so we utilize Microsoft Sentinel in deployments into our customers' environments to protect their environments and detect any type of security threats. We offer 24/7 support.

How has it helped my organization?

Microsoft Sentinel helps our company generate revenue directly from supplying these security services and managing them for our customers on a monthly basis. Along with the SOC services that we provide on top, there is a holistic coverage for customers.

It has enabled our team to triage security incidents faster and remediate them to get back to business quicker after customer incidents. Because we're able to reduce the number of incidents and the time per incident with Microsoft Sentinel, we can handle more incidents. Additionally, through rule tuning within Microsoft Sentinel, we reduce the number of incidents that have to be reviewed.

Microsoft Sentinel has increased efficiency and allowed our team to do more proactive work. We have seen at least a 60% increase in efficiency with Microsoft Sentinel and the ability to reduce the MTTD down to under five minutes and MTTR down to under fifteen.

A part of what we do within Microsoft Sentinel for our customers, and for ourselves, is the rule tuning. We're able to only ingest the logs that are going to provide additional security value. With that, we're able to utilize the SOC automation features. We're able to reduce the amount of log ingestion that takes place and reduce the customers' costs.

The integration of security functionalities, such as SIEM, SOAR, TIP, and EUBA, in Microsoft Sentinel is definitely beneficial. It's definitely a benefit of Microsoft Sentinel to be able to have a holistic deployment and a best-of-breed tool set that can integrate with each other. We can utilize the components from each of the tools to gain additional insight, additional access, and additional steps.

Microsoft Sentinel has not directly affected our compliance reporting, but it has been utilized for audit evidence collection to be able to do SOX compliance from Microsoft Sentinel logs.

Microsoft Sentinel has the ability to enhance some of the features that we already have. It allows our team to see some additional threat vectors.

The MITRE ATT&CK-based recommendations within Microsoft Sentinel are paramount for helping our customers understand where they're seeing threats and the part of the framework. We are able to catch threats faster instead of waiting for breach notifications. Microsoft Sentinel drastically reduces the impact of any type of breach.

What is most valuable?

Microsoft Sentinel is cloud native, which is a significant advantage. The data connectors that provide the ability to connect third-party log sources are highly valuable. The overall visibility that Microsoft Sentinel provides into the environments across multiple clouds and platforms on the ground is beneficial. It's a comprehensive solution and ties back into the Defender XDR holistic security platform.

A great thing with Microsoft Sentinel is that we have the ability to pull in third-party log sources as well as the Microsoft native logs. With that, we can create a complete story for the customers. We can see, with full transparency, the attack path and the movements that the bad actors have made. We can see not only what was impacted, but what has the potential to be impacted at a later date, and create additional hardening steps.

What needs improvement?

Driving deeper integration with the Defender XDR portal within Microsoft Sentinel, which is being done, and continuing to increase the number of third-party data connectors available is important. Multi-tenancy is also a current focus.

They should continue to integrate the components of Microsoft Sentinel and work to make a holistic component. They should continue to improve log ingestion across multi-cloud platforms.

For how long have I used the solution?

We've been utilizing Microsoft Sentinel for a little over three years.

What do I think about the stability of the solution?

It has been working very smoothly irrespective of different uses.

What do I think about the scalability of the solution?

We have been able to scale Microsoft Sentinel as our needs grow.

How are customer service and support?

Their support can be challenging at times, particularly around unique experiences or circumstances with Microsoft Sentinel. The documentation requires specific knowledge to locate. Once familiar with the system, it becomes very straightforward, though the documentation could be streamlined and made easier to navigate.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Before choosing Microsoft Sentinel, we had used QRadar. With Microsoft Sentinel, we're able to utilize multi-tenancy better. It's in a single instance within our environment, which doesn't necessarily correlate to transparency and data ownership for our customers. By allowing us to use Microsoft Sentinel within the customer's environments and utilize Lighthouse access to gain visibility into that, it allows our customers to have full transparency into what our team is doing, along with their existing staff, and it also retains data ownership for the customer.

How was the initial setup?

We were able to deploy Microsoft Sentinel through infrastructure as code, and we do a Terraform deployment which allows us to deploy and configure the main components of Microsoft Sentinel, all of them managed for our customers.

What was our ROI?

The biggest return on investment when using Microsoft Sentinel is customer stickiness, customer engagement, and the ability to leverage existing Microsoft investments that the customer already owns to be able to deploy Microsoft Sentinel in their environments.

What's my experience with pricing, setup cost, and licensing?

Pricing for Microsoft Sentinel could always be lower, but it's workable. The ingestion costs for the data analytics is usually the highest cost, but the licensing per Microsoft Sentinel is fairly straightforward and transparent.

Which other solutions did I evaluate?

We did consider other solutions before choosing Microsoft Sentinel. We wanted to make sure that we chose a cloud-native solution, and we feel that with the hyperscale data, it provides the best value for price by far.

What other advice do I have?

I would rate Microsoft Sentinel an eight out of ten. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partnership
PeerSpot user
senior cyber security at a tech services company with 201-500 employees
Real User
Top 10
Apr 9, 2025
Unified security operations streamline monitoring and incident management
Pros and Cons
  • "The best feature of Microsoft Sentinel is its ability to unify all dashboards or functions into one modern SecOps dashboard."
  • "The pricing tiers of Microsoft Sentinel should be improved. There are complexities in calculating the right pricing tier for different customers, which makes it difficult for me as a consultant during upfront pricing."

What is our primary use case?

I use Microsoft Sentinel for security incident management, monitoring, and incident tracking in the security environment. My clients use it to unify and monitor their entire ecosystem in the security sector using either Microsoft or other security products. This enables them to correlate all incidents and logs into Microsoft Sentinel.

What is most valuable?

The best feature of Microsoft Sentinel is its ability to unify all dashboards or functions into one modern SecOps dashboard. This integration means that I do not need to check multiple dashboards for security operations, offering seamless integration with the Microsoft ecosystem. The pre-built detection analytics and the ability to create custom detection rules more easily than some other solutions are also highly valuable. Additionally, the ability of Microsoft Sentinel to correlate data from multiple sources enhances threat detection capabilities.

What needs improvement?

The pricing tiers of Microsoft Sentinel should be improved. There are complexities in calculating the right pricing tier for different customers, which makes it difficult for me as a consultant during upfront pricing. Additionally, I would like to see more out-of-the-box data collectors to connect to proprietary systems in future versions.

For how long have I used the solution?

I have been working with Microsoft Sentinel for around two years.

What was my experience with deployment of the solution?

The cloud deployment of Microsoft Sentinel is very straightforward and one of the easiest I have worked with. It integrates quickly if all the requirements are prepared. This is different from other SIM solutions, which require more complex processes like preparing hardware and finding the right server size. In 10 to 15 minutes, it can be set up with a proxy server, and logs are automatically integrated, allowing for fast deployment without additional software installation.

What do I think about the stability of the solution?

Microsoft Sentinel is quite stable. However, some of the data connectors can become deprecated, requiring reconnection. I need to be aware of deprecated connectors as they may disconnect, but the data continues to be sent with a need for quick adaptation.

What do I think about the scalability of the solution?

Being a SaaS solution, the scalability of Microsoft Sentinel is robust. I do not need to manage resources, and the open infrastructure allows for scalable usage.

How are customer service and support?

As a consultant, I rate the quality of service for technical support a seven out of ten. The response is usually quick, especially through live chat, and further support is provided through email or remote assistance if needed.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have experience with other SIM solutions, including Azure and other major players in the security market. With Microsoft Sentinel, the ease of building detection rules and correlation queries is more straightforward than other tools like Splunk.

How was the initial setup?

The initial setup is very simple and fast with Microsoft Sentinel, requiring only a small virtual machine as a proxy server. There is no need for complex hardware setups, unlike other SIM solutions.

What was our ROI?

Calculating the ROI of Microsoft Sentinel can be challenging. If a customer is already using Microsoft’s ecosystem, the ROI can be positive due to seamless integration. For those without significant Microsoft usage, the cost may be high, leading to a lower ROI.

What's my experience with pricing, setup cost, and licensing?

The pricing tiers and associated complexities of Microsoft Sentinel can be cumbersome. Setting up the right cost model for customers is intricate, requiring careful consideration of various components and licensing tiers.

Which other solutions did I evaluate?

I have also worked with solutions like Splunk and other SIMs in the security market.

What other advice do I have?

There are some issues with data connectors being deprecated and the lack of immediate replacements being available. However, the solution remains user-friendly and efficient for those within the Microsoft ecosystem. Overall, I rate Microsoft Sentinel an 8.5 out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Architect at a wholesaler/distributor with 201-500 employees
Real User
Top 20
May 5, 2025
Centralized logging and integrations enhance threat detection and cost efficiency
Pros and Cons
  • "Microsoft Sentinel's ability to correlate data from multiple sources has enhanced my threat detection capabilities beyond what simple data lake solutions offer."
  • "The integration between them is good and straightforward, the documentation is excellent, and we do not have any problems."
  • "In terms of improvements, pricing, licensing, and overall cost could be better."

What is our primary use case?

Our use cases for Microsoft Sentinel are SIEM and logging for any activity. We have been having some issues and we are using this logging for that purpose.

I am using Microsoft Sentinel for threat intelligence and threat hunting, and it is definitely helping us.

We did not have centralized logging in place, and Microsoft Sentinel has definitely helped us instead of having to spin up our own centralized logging, which is not scalable. Microsoft Sentinel has many integrations that help us with threat hunting and reduce the amount of effort needed from our end.

How has it helped my organization?

We're using it for threat intelligence and threat hunting and it's definitely been helping. 

What is most valuable?

The most valuable feature I have found in Microsoft Sentinel is logging. Microsoft Sentinel collects everything, and it is a centralized place for logging management.

It performs its functions in an efficient way for me.

Microsoft Sentinel's ability to correlate data from multiple sources has enhanced my threat detection capabilities beyond what simple data lake solutions offer. You can tie in with Defender intelligence and that really helps us. We want to see all activity going on.

I evaluate the integration of security functionalities such as SIEM, SOAR, TIP, UBA, and Microsoft Sentinel as good. The integration between them is good and straightforward, the documentation is excellent, and we do not have any problems. I foresee it having a positive impact.

With regards to MITRE ATT&CK, the recommendations from Microsoft Sentinel are really helpful for us to go back and remediate any recommendations.

The SOC optimization feature has impacted our organization's data management and cost efficiency significantly. It brings substantial savings compared to using different products, such as Splunk for SIEM and having another product for gathering intelligence. With the Microsoft platforms that we have, the integration is straightforward, which is definitely a cost savings for us instead of trying to get different product lines from different vendors.

The impact that Microsoft Sentinel has had on our organization's advanced hunting capabilities is significant. We depend on centralized logging for partnering with other providers, and we also use CrowdStrike. For threat hunting, we have seen issues where there were lateral movements, and for identifying those malicious sources and containing them, it has been definitely helpful.

What needs improvement?

In terms of improvements, pricing, licensing, and overall cost could be better.

For how long have I used the solution?

We've used the solution for one and a half months. 

What do I think about the stability of the solution?

I assess the stability and reliability of Microsoft Sentinel as good. We have not had any issues.

What do I think about the scalability of the solution?

Microsoft Sentinel scales as our needs grow without any problems. We are a very small organization, so it fits our needs.

How are customer service and support?

I would evaluate the customer support and technical support I received from Microsoft as very good. It is very responsive, and I really appreciate the documentation that is available online.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

In the past, with a different organization, I used Splunk prior to using Microsoft Sentinel. The interface is not as simple as Microsoft Sentinel; it has its own query language, and Microsoft Sentinel is more straightforward. We also use CrowdStrike. 

How was the initial setup?

The deployment was straightforward. 

What was our ROI?

We have seen an ROI. Essentially, we didn't have centralized logging before. This has helped us substantially. Spinning up your own centralized logging is not really scalable. It's helped with threat hunting and has reduced the amount of effort on our end. 

What's my experience with pricing, setup cost, and licensing?

The pricing is a bit high.

Which other solutions did I evaluate?

Splunk was the other solution I was evaluating prior to picking Microsoft Sentinel.

I decided to go with Microsoft Sentinel as opposed to Splunk. Splunk has gone through a change. It has just been acquired by Cisco, and we do not know how the experience is going to be. There could be a transformation in their product line.

What other advice do I have?

On a scale of one to ten, I would rate Microsoft Sentinel as a product overall as nine.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Ivan Angelov - PeerSpot reviewer
Project Executive at synergyc
Real User
Top 5
Mar 20, 2025
Threat detection and response capabilities enhance investigation processes
Pros and Cons
  • "The most valuable features for us include threat collection, threat detection, response, and the knowledge base for investigation."
  • "However, we are not using it for some features, mainly for cost-related reasons and our company policy."

What is our primary use case?

My security team has been using Microsoft Sentinel for around two years. We also have Bastion and SolarWinds as part of our monitoring tools. We use a three-way tool, alongside Microsoft Sentinel, in our environment.

What is most valuable?

The most valuable features for us include threat collection, threat detection, response, and the knowledge base for investigation. These are the three separations in the tool that we are currently using.

What needs improvement?

My team enjoys using Microsoft Sentinel. However, we are not using it for some features, mainly for cost-related reasons and our company policy. We choose other solutions for basic monitoring due to better cost opportunities. There could be improvements in those areas, but these are based on management decisions.

For how long have I used the solution?

We have been using it for approximately two years.

What do I think about the stability of the solution?

In the past two years, our team hasn't encountered any issues with the stability of Microsoft Sentinel from an operations perspective. We rate it an eight, as no escalations have been made for Microsoft Sentinel.

What do I think about the scalability of the solution?

I cannot provide a specific number for scalability, as I wasn't part of the scaling team. We did use an external vendor, I-Tracing, for assistance.

How are customer service and support?

When my team needs to escalate issues to Microsoft, especially for Microsoft Sentinel, the response is fast through their French entity. We would rate technical support an eight.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We used Bastion before Microsoft Sentinel. We still use Bastion in some regions for end-to-end security and SolarWinds for monitoring. We switched to Microsoft Sentinel for specific security cases.

How was the initial setup?

Initially, we had dedicated training from a UK trainer who worked with our team for three months. The cloud, DevOps, and security teams wrapped up training quickly, especially within the EMEA region. No major issues were encountered during the adoption.

What about the implementation team?

We had a dedicated trainer from the UK who worked with our security level one and two teams during the initial setup. The DevOps team had some delays, but these were likely operational specifics.

What was our ROI?

I'm not on top of the full business case, but from a support and licensing perspective, it's fine. Microsoft Azure was not fitting for short-term cost savings but promised a better ROI over three to five years for medium to large companies.

What's my experience with pricing, setup cost, and licensing?

I haven't seen the full business case, but the cost for support and licensing is justified with what we receive. Microsoft Sentinel offers more capabilities than Bastion, with a more intuitive experience.

Which other solutions did I evaluate?

We evaluated Bastion and SolarWinds.

What other advice do I have?

My CISO wanted to get more with less money. Short-term, Microsoft Sentinel might not fit the budget, but long-term it makes sense, especially for medium to large companies. I rate Microsoft Sentinel an eight out of ten, offering a better experience than our previous solution.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Chief Operating Officer at a tech services company with 51-200 employees
Real User
Top 20
May 5, 2025
Managed security service scales operations efficiently and saves costs through advanced integrations
Pros and Cons
  • "Microsoft Sentinel's ability to correlate data from multiple sources has improved our capability significantly."
  • "In New Zealand, there are customers that run dual stack, running Microsoft but also competitor products, EDR software, cloud security software, and other tooling. While it's improved over the last four or five years, there's still more work that can be done to integrate better outside of the Microsoft ecosystem."

What is our primary use case?

As a managed security service provider, we have a managed security service that we provide to customers, and our managed services are often built on Microsoft Sentinel.

How has it helped my organization?

Our managed SOC is based on Microsoft Sentinel, and a key benefit is that we've been able to take customers' investments, especially in E5 licensing, and make that investment stretch further than they would have had they gone to a competitor's product. This helps organizations drive and uplift their cyber resilience in a cost-effective manner.

For us, customer retention is key, and we can articulate value about the services we provide because the backend services and Microsoft Sentinel itself do the job for us. The benefit lies in customer retention, keeping our costs down, and providing value to customers by making every dollar they invest go further.

What is most valuable?

Microsoft Sentinel was the first real cloud-native SIEM solution, and it integrates into an ecosystem around Microsoft and the entire stack with all of the other vendor products. I appreciate that we can get the free ingestion from the Microsoft ecosystem into Microsoft Sentinel, which works really for us.

Microsoft Sentinel's ability to correlate data from multiple sources has improved our capability significantly. We have used other SIEM products and data lake products outside of Microsoft Sentinel, and it's evident that what you get out of Microsoft Sentinel and the ability to enrich the data with threat intelligence and correlate over various sources provides better detection capabilities, better response times, and more assurance of security. In the five years that we've had the product in market as a managed service offering, we've not missed anything, demonstrating a strong track record.

The automation feature in Microsoft Sentinel has been amazing and has significantly affected our team's efficiency in handling security incidents. As a managed security partner, we've effectively been able to triple our customer base but only had to increase headcount by 15% to 20%. The built-in integrations and automation allow us to scale and have more coverage and greater capabilities without the corresponding increase in headcount.

The integration of security functionalities such as SIEM, SOAR, TIP, and UEBA in Microsoft Sentinel is robust. The ecosystem is very integrated together within Microsoft.

Microsoft Sentinel's SOC automation and optimization feature has significantly impacted our company's data management and cost efficiency. We operate as a provider, using the product both ourselves and for our customers. We've completed substantial optimization work around ingestion and cost optimization, and some of our customers have saved up to 300% to 400% compared to their original budgets.

Microsoft Sentinel has had an exceptional impact on our company's and customers' advanced hunting abilities. The integrations and automations natively built into the system help us perform retrospective threat hunting. We now have the capability of utilizing threat intelligence provided by the government in New Zealand, allowing us to take indicators of compromise and pass them directly into Microsoft Sentinel and the Defender suite, which moves us from a reactive to a proactive security stance.

The time saved per incident in Microsoft Sentinel has reduced by more than half compared to five years ago. We're able to handle more customers and incidents simultaneously, with detection and remediation times decreasing. With the investments we're making around Microsoft Security Copilot and AI, that efficiency is expected to improve further.

Using the MITRE ATT&CK framework has enhanced our security posture by providing a way to align to a framework that helps contextualize and explain why security threats are relevant and how they can manifest in the environment. It offers a common language for our analysts to communicate across all of our customers on the service, focusing on the TTPs that threat actors would use to undertake an attack or compromise in the customer's environment.

What needs improvement?

The three challenges we have are outside of the Microsoft ecosystem. In New Zealand, there are customers that run dual stack, running Microsoft but also competitor products, EDR software, cloud security software, and other tooling. While it's improved over the last four or five years, there's still more work that can be done to integrate better outside of the Microsoft ecosystem.

Microsoft Sentinel is on the right track in terms of improvements. Being part of a Microsoft partner security association in New Zealand gives us access to information about product roadmaps and developments. The only recommendation, rather selfishly as an MSSP, is for a model where MSSPs can take Microsoft Sentinel and deliver it at scale to customers under a licensing construct.

To improve Microsoft Sentinel further, providing better options for long-term retention and storage of non-Microsoft logs is important for our customers. There is always a cost element there, and for us as an MSSP partner, being able to differentiate our service using the platform through a licensing construct specifically for MSSP partners would be beneficial.

For how long have I used the solution?

We've been using Microsoft Sentinel ever since it came out in Purview, approximately five years now.

What do I think about the stability of the solution?

Microsoft Sentinel has been amazing in terms of stability and reliability, as we haven't had any issues with it.

What do I think about the scalability of the solution?

While Microsoft Sentinel scales effectively from a technical standpoint, it could be improved in terms of being more suited for MSSP partners with regard to licensing construct.

How are customer service and support?

I have never had to use Microsoft Sentinel's customer service or technical support officially, however, the teams I have reached out to have been excellent. I've never received any bad responses or feedback.

How would you rate customer service and support?

Positive

What was our ROI?

I have definitely seen a return on investment when using Microsoft Sentinel, though it's difficult to quantify in dollar terms, considering security cannot be given a precise value. 

From a risk perspective, it's about mitigating risk, and as mentioned earlier, we haven't missed many things since we've had the offering in market—only a couple of minor incidents.

What's my experience with pricing, setup cost, and licensing?

I was more familiar with Microsoft Sentinel's pricing, setup costs, and licensing many years ago, and in my current role, I'm not as involved with these aspects.

What other advice do I have?

On a scale of one to ten, this solution rates as a nine.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Systems Emgineer at a non-profit with 1-10 employees
Real User
Top 10
Dec 16, 2024
The solution's security automation streamlines alerts and reduces false positives
Pros and Cons
  • "Microsoft Sentinel has helped by streamlining our security. We have a nine-member network team, with three members managing security for the city, and Sentinel allows us to operate an unofficial SOC."
  • "There is room for improvement in terms of integrations. We have some tools, such as our off-site Meraki firewalls, that have not fully integrated with Sentinel. We lack integration for Syslogs into Sentinel."
  • "There is room for improvement in terms of integrations."

What is our primary use case?

We use Microsoft Sentinel as our main SIEM suite alerts and automation rules. It feeds everything into Sentinel Logs and Realities for security purposes.

How has it helped my organization?

Microsoft Sentinel has helped by streamlining our security. We have a nine-member network team, with three members managing security for the city, and Sentinel allows us to operate an unofficial SOC. 

It makes investigations easy. We were spending a lot of time manually investigating and resolving false positives. Once Sentinel was fully integrated and we suppressed those false positives, our SOC environment greatly improved. 

What is most valuable?

The most valuable feature of Sentinel is the automation. Creating automation rules helps eliminate false positives, which is crucial due to the high amount of noise in security. Sentinel integrates with Microsoft Defender XDR as a single security hub. Sending our alerts from XDR into Sentinel has made it a decent transition to one solution.

We can easily build reports based on Sentinel alerts and logs. Around 80 percent of our logs go into Sentinel. The solution has improved our threat-hunting by enabling us to run KQL queries. If we learn something through threat intelligence, we can run a query to see if our environment is affected.

Sentinel MITRE ATT&CK recommendations strengthen our security posture. For a small security team like ours, the automation and integrated technologies increase our service efficiency.

What needs improvement?

There is room for improvement in terms of integrations. We have some tools, such as our off-site Meraki firewalls, that have not fully integrated with Sentinel. We lack integration for Syslogs into Sentinel.

What do I think about the stability of the solution?

Sentinel's stability is great. I don't see us changing Sentinel as our SIEM in the near future.

What do I think about the scalability of the solution?

Sentinel's scalability is excellent. As our organization uses Microsoft Azure and Defender, everything grows together, and we can integrate various features seamlessly.

How are customer service and support?

Customer service and support for Sentinel have been very responsive. Working with a Sentinel engineer helped us tune settings effectively.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup process involved working with a Microsoft Expert, which helped in achieving an effective setup.

What about the implementation team?

The implementation team was a Microsoft Expert, providing substantial support in tuning Sentinel post-deployment.

What was our ROI?

The management has expressed that the return on investment has been favorable, especially due to the reduction in security investigations. However, specific metrics were not shared with me.

What's my experience with pricing, setup cost, and licensing?

We already had the necessary licensing for Sentinel, so we didn't need to to spend extra money. 

Which other solutions did I evaluate?

We considered Splunk and ano Splunk and another unnamed product, but Splunk was a notable option.

What other advice do I have?

I Sentinel nine out of 10. Our licensing strategy and the positive impact on investigations indicate a good return on investment.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Chief Commercial Officer at defend
Real User
Top 20
May 5, 2025
Managing operations with a unified security pane while benefiting from cost efficiency
Pros and Cons
  • "Microsoft Sentinel has improved cost efficiency, which is one of the key areas we're able to win business against the ability to have threat intelligence."
  • "It's a great product."
  • "It would be nice to be able to leverage more AI to handle more data and recovery aspects in the future."

What is our primary use case?

Our use case for Microsoft Sentinel is having a more holistic view by having all security events in one place.

How has it helped my organization?

We were likely the first partner in New Zealand. We've been able to manage the path forward early on and have helped small businesses adopt a really scalable solution.

It's one of the key areas we've focused on. We love the ability of having reliable threat intelligence.

What is most valuable?

Microsoft Sentinel's ability to integrate with other Microsoft products has been beneficial to our team's operations. We like the best of ecosystem versus the best of breed approach. We can have everyone have the same skillsets and not have individuals specialized. It's much more holistic. 

The threat detection has been useful. We like having everything managed by one solution. It simplifies everything. 

The automation feature helps with efficiency, specifically around security. 

It has good integration with other security features. It's a great product. The ease of use and ease of management are great. 

It's allowing us to have one Microsoft security pane of glass.

Microsoft Sentinel has improved cost efficiency, which is one of the key areas we're able to win business against the ability to have threat intelligence.

What needs improvement?

To improve Microsoft Sentinel specifically, giving us different functionality to handle tasks would be really amazing. I don't have any issues with what's currently available.

It would be nice to be able to leverage more AI to handle more data and recovery aspects in the future. 

For how long have I used the solution?

I've used the solution for the last five years. 

What do I think about the stability of the solution?

Regarding the stability of Microsoft Sentinel, there haven't been any significant issues. There may have been one or two minor incidents over time, yet nothing substantial.

What do I think about the scalability of the solution?

The scalability is very good. Our largest customer has 55,000 seats. Others have 100 to 200 seats. 

How are customer service and support?

We've had a good experience with Microsoft support.

Which solution did I use previously and why did I switch?

We decided early on we weren't going to partner with a lot of vendors. We liked what Microsoft was going to do with a best-of-ecosystem approach instead of best of breed. 

How was the initial setup?

The initial setup is pretty easy. 

What was our ROI?

I have definitely seen a return on investment in the past five years. We attribute our growth to Sentinel. It became a product that everyone suddenly wanted. 

What's my experience with pricing, setup cost, and licensing?

My experience with the pricing setup has been positive.

Which other solutions did I evaluate?

There were a couple of other products available, however, we were quite certain we were going to go with Microsoft Sentinel.

What other advice do I have?

The reason why having a best-of-ecosystem is crucial for our customers is that it eliminates the need to set up multiple different products, so it was really attractive to have everything in one place.

I'd rate the solution ten out of ten. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
IT Architect at a real estate/law firm with 10,001+ employees
Real User
Dec 18, 2023
It's a plug-and-play solution, so you can start seeing benefits quickly using the out-of-the-box analytics rules and use cases
Pros and Cons
  • "The SOAR playbooks are Sentinel's most valuable feature. It gives you a unified toolset for detecting, investigating, and responding to incidents. That's what clearly differentiates Sentinels from its competitors. It's cloud-native, offering end-to-end coverage with more than 120 connectors. All types of data logs can be poured into the system so analysis can happen. That end-to-end visibility gives it the advantage."
  • "I would like Sentinel to have more out-of-the-box analytics rules. There are already more than 400 rules, but they could add more industry-specific ones. For example, you could have sets of out-of-the-box rules for banking, financial sector, insurance, automotive, etc., so it's easier for people to use it out of the box. Structuring the rules according to industry might help us."

What is our primary use case?

We use Sentinel for our SOC operations. We set up analytics rules and SOAR playbooks. Sentinel covers our entire security operation. It is deployed across multiple locations and covers around 4,000 users.

Sentinel gives us alerts, identifies vulnerabilities, and helps us remediate issues. Some of it is automated, but we also do manual remediation through the ticketing process. We have integrated Sentinel with ServiceNow, so the alerts are routed to the engineers.

How has it helped my organization?

Sentinel has reduced our mean time to resolution, one of our KPIs, by about 30 to 40 percent and enabled us to identify vulnerabilities faster. The co-pilot capability saves us a lot of time, too. We're also doing mapping with the MITRE framework, improving our MITRE coverage. We started to see results after the initial deployment and configuration. It took about two or three months. It's an ongoing process, but we realized the benefits within three months. 

The solution correlates signals from native and third-party sources into a single incident. Before implementing Sentinel, we used multiple tools to investigate and remedy vulnerabilities. Having that single pane of glass has significantly increased the efficiency.

Sentinel has improved our overall visibility. We get data about user behavior and correlate it. It also gives us alerts about network vulnerabilities. Having a single pane of glass and one consolidated security tool allows us to capture multiple layers, from the endpoints to the servers. One solution gives us visibility into all the layers. 

What is most valuable?

The SOAR playbooks are Sentinel's most valuable feature. It gives you a unified toolset for detecting, investigating, and responding to incidents. That's what clearly differentiates Sentinels from its competitors. It's cloud-native, offering end-to-end coverage with more than 120 connectors. All types of data logs can be poured into the system so analysis can happen. That end-to-end visibility gives it the advantage.

Sentinel's AI and automation capabilities make our SOC team's job easy. When logs come into Sentinel, the AI engine analyzes, contextualizes, and correlates them. The AI is correlating the data from multiple log sources and giving us alerts. We depend on that. We also perform automated remediation based on our SOAR playbooks. 

What needs improvement?

I would like Sentinel to have more out-of-the-box analytics rules. There are already more than 400 rules, but they could add more industry-specific ones. For example, you could have sets of out-of-the-box rules for banking, financial sector, insurance, automotive, etc., so it's easier for people to use it out of the box. Structuring the rules according to industry might help us. 

They could also add some more connectors. Sentinel has 120 connectors, including most of the essential data ones, but they could add some more legacy connectors.

For how long have I used the solution?

I have used Microsoft Sentinel for three years.

What do I think about the stability of the solution?

Our SOC team relies on Sentinel from end to end, and it has been quite stable. It's always up, and we've never had any issues with the connectors.

What do I think about the scalability of the solution?

Scalability isn't a problem because we have an Azure environment, and Sentinel is native.

How are customer service and support?

I rate Microsoft support nine out of 10. They resolve our tickets within an acceptable time frame. That is pretty much okay for us.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Initially, we used Splunk, but I've mostly worked on Sentinel at this company. It was a company decision. Splunk works well in an on-premise or legacy environment, but our entire digital estate shifted to the cloud, so it makes more sense to move to Microsoft Sentinel because we moved to Azure.

How was the initial setup?

Our deployment went smoothly. We spent about three or four months setting up the entire thing, and it all went according to plan without any undue complications. About three months of that was the configuration phase, and we had a transitional month before starting operations. 

The implementation steps included enabling Sentinel, setting up Log Analytics Workspace, and connecting the data connectors. After that, the logs started flowing in. Next, we created the analytic rules and remediation use cases. The deployment team included seven full-time staff. After deployment, Sentinel requires some ongoing maintenance when we add new analytics rules or log sources. We have one engineer responsible for that.

What was our ROI?

We see an ROI. Our efficiency increased once we created the initial set of analytics rules and SOAR automation, and we review our automation use cases every six months to find more ways to save money. It comes out to roughly a 10 percent return annually on a three-year contract.

What's my experience with pricing, setup cost, and licensing?

I am not involved on the financial side, but from an enterprise-wide use perspective, I think the price is good enough. We have bundled pricing with Azure Monitor Log Analytics. We would be using Log Analytics Workspace even if we didn't have Sentinel, and we would need to pay a separate license for IBM QRadar or Splunk. It optimizes costs when we use both in our digital estate. 

Which other solutions did I evaluate?

We considered IBM QRadar. 

What other advice do I have?

I rate Microsoft Sentinel eight out of 10. It's a plug-and-play solution, so you can start seeing benefits quickly using the out-of-the-box analytics rules and use cases. Of course, you need more time to create custom use cases and playbooks, but it's simple to get started. It might be challenging to migrate from a legacy system because you may have trouble connecting to the old data, but this is the best tool for a greenfield deployment. 

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Microsoft Sentinel Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Microsoft Sentinel Report and get advice and tips from experienced pros sharing their opinions.