Microsoft Sentinel Drives the Future of Cybersecurity at Tech Field Day
Tom Hollingsworth, Event Lead at Tech Field Day, shares his insights from the recent Tech Field Day Exclusive with Microsoft Security, where Microsoft showcased major updates to Microsoft Sentinel. The discussion highlighted Sentinel’s long-term data lake capabilities, its new Graph feature for visualizing threat relationships, and Microsoft’s push toward a unified, intelligent security platform. Hollingsworth noted how these advancements reinforce Microsoft’s commitment to empowering SOC teams, strengthening enterprise defenses, and setting the stage for future innovation across the Microsoft Security ecosystem.
Transcript
I'm Tom Hollingsworth event lead here at Tech Field Day and here are my takeaways from the Tech Field Day exclusive event with Microsoft Security. Hi everyone. Welcome to this episode of Tech Field Day takeaways.
We just had our special exclusive event with Microsoft Security focused on the latest announcements around Microsoft Sentinel, and it was really interesting to be able to get a look at all of the work that Microsoft has been putting into the security platform with the way that security has been going for the past several months. You might be remiss in thinking that a company like Microsoft thinks that MI security is not an important aspect of what they do, but nothing could be further from the truth. They've put a lot of effort into making sure that they have a robust platform that security analysts and users alike can rely on to keep them safe, not only the users and the analysts, but the data that they rely on to do their jobs.
Here are some of the takeaways that I got from this event. The first, The first is that Microsoft Sentinel may be a platform that's been around for a while, but there is a lot going on under the hood. The data lake aspect provides up to 12 years of data storage for security events.
If you combine that with the seen functionalities that are found in Microsoft Sentinel, security analysts can collect and correlate data at an unprecedented scale to ensure that no incident goes unnoticed. This gives the rest of the Microsoft security ecosystem the baseline for ensuring that users can stay safe from threats. That 12 year retention period also ensures that attempts to recon your enterprise don't escape notice.
It's hard to build a platform from scratch that includes all of these great features and that's one of the reasons why I think Microsoft has done so much to renovate what Microsoft Sentinel is under the hood. By adding all of these new features of which the data lake is just one, they are providing the kind of thing that users are going to be able to build their security strategy around going forward. And I know that SOC analysts love having access to all of these tools to make absolutely sure that everything is safe and secure.
One of the newest features of Microsoft Sentinel is graph. This is a function that helps visualize the relationships between seemingly unimportant things. If you want to think about it.
The ability to connect those dots allows your SOC analysts to trace how incidents organically happen. It also allows you to see how attackers think and respond to countermeasures. Graph behaves like they do.
It investigates links and follows the trail so that you know where your defenses are succeeding and where you need to focus your efforts. The context provided by the graph means that you always have a leg up on anyone trying to sneak past you too. Often we rely on things like static defenses to give us an idea of what's going on, but people don't think linearly like they used to.
Every landing spot is an opportunity to investigate new infection vectors or new footholds to be able to take and graph makes that investigation happen on a hot by hop basis. So you can see the way that people think when they're trying to attack your systems, move laterally and basically provide persistence once you know how they think. Once you can power graph with all of this data from Microsoft Sentinel in the data lake, you will be able to see through their eyes and know exactly what you need to be protecting.
The third thing that I took away from this event is the importance of a cohesive strategy around security. The delegates at the event were very impressed by the strides that Microsoft has been taking to unify their security platform with powerful data intelligence. The ability to provide information to stakeholders before and after a breach means that they understand the value of increasing the security posture of an enterprise.
Being able to ingest data from a variety of sources, including those that are not Microsoft, is valuable for large organizations that have a diverse technology stack. When you think about the way that platforms evolve over the years, sometimes it just feels like there are a collection of tools with no thought about how all of those pieces should integrate. And when you look at the breadth of technology that Microsoft offers on the security side, you know that having one repository where all of that data can land and then be spread out amongst all the other things is hugely valuable and that's what Microsoft Sentinel really is.
It is an opportunity for the collection and analysis of that data to provide actionable intelligence across the board. And when it comes to a company as large as Microsoft, that is hugely valuable for people in the industry because you don't wanna have to hunt through several screens or panes of glass to be able to understand what's going on in your environment. And that's doubly true if you are responding to an active incident right now.
I think this was a hugely successful event coming off of Microsoft Secure just a couple of weeks ago, and we are building towards Microsoft Ignite in November, so there are gonna be even more great things that are on the horizon that will be released soon. All of the delegates from this event had some great thoughts both in the event during the questions that they asked, as well as the round table discussion that we had, and there's more coming from all of the great content that we expect to see from them. We hope that you'll be able to watch these videos and leave comments.
And we also invite you to check out Microsoft Security, specifically Microsoft Sentinel on the Microsoft site. There's a wealth of information there and some great documentation about how to implement it and the pieces and parts under the hood that are important to your key decision makers. Thank you very much for watching this episode of the Tech Field Day takeaway series on the Tech Field Day plus YouTube channel.
If you enjoyed it, be sure to like, subscribe and share your thoughts on Tech Field Day exclusive with Microsoft Security. In the comments, make sure that you follow Tech Field Day on X Twitter, blue Sky and Mastodon for updates. And don't forget to check out all the presentation videos on the Tech Field Day website and on our YouTube channels.
Our next scheduled event is MI Tech Field Day Extra at NetApp Insight. com as well as our LinkedIn page and on Techstrong tv. We'll see you soon.