How Microsoft Sentinel Is Redefining Security Operations – Tech Field Day Takeaways
Transcript
I'm Tom Hollingsworth, event Lead for Security here at Tech Field Day, and here are my takeaways for this special exclusive event with Microsoft Security. We had a great conversation with Microsoft Security around their Sentinel product. It is something that is being transformed to be a critical part of your security infrastructure.
I'd like to take a moment to talk about my three big takeaways from our conversation with Microsoft about what they're doing with Sentinel. My first big takeaway is the evolution of Sentinel from a SIEM to a unified operations platform, Microsoft is fundamentally re-architecting Sentinel. It has historically been a market leading seam or security and information event management tool, and it is becoming a full fledged security platform that powers the Microsoft Defender portal.
The goal is to eliminate the swivel chair problem. You know the one where analysts have to jump between different interfaces to get information. Sentinel functions are being converged into the Microsoft Defender portal, which serves as a primary interface for security operations.
Sentinel is becoming the underlying platform engine that supports other Microsoft portals as well. There are some additional capabilities that you'll see in Microsoft Purview for data security as well as Microsoft entra for identity management, and the platform is designed to be open. It supports OCSF and currently utilizes 350 different connectors to ingest data from third party sources like AWS, Google Cloud and CrowdStrike.
My second big takeaway is the data lake. A major technical and economic takeaway from this event was the introduction of the Sentinel Data Lake. It separates data storage from compute power in order to drastically reduce costs and increase data retention.
Previously, customers faced a choice between budget constraints and security visibility. Things like high volume logs were often way too expensive to ingest into a hot analytics tier. The new data lake functionality built into Sentinel offers a lower cost tier, which is about 6 cents per gigabyte compared to list prices of nearly $4 per gigabyte.
It also allows data to be ingested into the hot analytics tier that is automatically mirrored into the data lake at no additional cost that provides a single complete copy of the data. This architecture allows organizations to store their data for up to 12 years. That's very important for compliance and retro threat hunting capabilities.
While the data lake is really considered cold storage, it really supports some high powered analytics. Users can run high performance jobs using things like Apache Sparks and Jupyter Notebooks directly on the data lake for deep analysis, machine learning training, or historical data analysis. My third big takeaway from this special exclusive event was around graph based security and ag agentic ai.
Microsoft is introducing new data modalities and AI protocols to change the way that analysts investigate threats. They're moving beyond simple tabular data to more conversational interactions. The linchpin of this is the sentinel graph.
Think about the way your attackers think about your organization because they do think in graphs. It's mapping the relationships between assets, users, and data to visualize potential attack paths. It allows analysts to quickly calculate the blast radius of a compromised asset and also predict where an attacker could be moving next, based on things like permissions and network connections, the capability can be used for pre-B breach exposure management, such as identifying choke points and post breach investigation.
One of the big components that helps this is the MCP server. You're probably familiar with MCP, is model context protocol. It acts like a catalog that allows AI agents to automatically discover and interact with data tools.
This can enable things like natural language search, so analysts can ask questions like, tell me what tables are relevant to this password spraying attack. Rather than trying to remember the arcane SQL or other database query language to figure out how to get that data. It also enables Ag agentic workflows where AI can not only read the data but generate things like Python code, create playbooks, and potentially take actions on them.
This AI assisted process could be even be considered something like maybe Vibe hunting or vibe investigation. When I think about all of the things that Microsoft has introduced to Sentinel, I think about it as maybe a storefront. That's what Sentinel used to be.
It was fast and it was easy to access, but just like all storefronts, you, you had to rent space and it became very expensive. You could only keep your most critical high turnover items on the shelf, and if you had bulk items or inventory that wasn't moving, you basically had to get rid of it because you couldn't afford the shelf space. But now Microsoft has built this massive warehouse or data lake directly attached to the back of the store.
The storage here is well fairly cheap, and you can keep everything you might ever want to keep for 12 years. That Unified platform is a single office where you can oversee both the store and the warehouse. Sentinel Graph is kind of like a overarching blueprint that shows exactly where the doors connect to which rooms revealing how someone might break in to the loading dock, and then be able to reach things that are in the back office.
An MCP server is basically hiring a team of automated robots that will understand playing English when you tell them, Hey, go find everything in the warehouse related to that shipment from last Tuesday, and then they're gonna run into the warehouse, get all those boxes and probably even write a report for you. There are a lot of things that Microsoft is building on top of Sentinel now that they have a robust, very functional platform, and we are gonna be hearing more about them in 2026. As we continue to monitor these things, we hope that you'll head over to the tech field, a YouTube channel to check out the videos from this special Microsoft exclusive security event, and we hope to hear your comments and your perspectives on these technologies.
Thank you very much for watching this episode of Tech Field Day takeaways on the Tech Field Day plus YouTube channel. If you enjoyed it, please make sure you like, subscribe, and share your thoughts on Microsoft security in the comments. You can also follow Tech Field Day on X, Twitter, blue Sky and Mastodon for updates, and check out all of our presentation videos on the Tech Field Day website and our YouTube channels.
Our next event is AI Infrastructure Field Day, which is taking place January 28th through the 30th, 2026. Make sure you're tuned in live on our website, on our LinkedIn page, and on Techstrong tv.