Microsoft Sentinel Evolution Executive Session
Microsoft Sentinel is evolving from a market-leading Security Information and Event Management (SIEM) tool to a full-fledged, AI-driven security platform for Microsoft Security and its partners. The core of this evolution is to unify security operations within the Microsoft Defender portal, which will remain the primary interface for SOC analysts. Sentinel is being re-architected to serve as the underlying data and analytics engine for all Microsoft security products, including Defender, Entra, and Purview. This shift addresses the need to ingest and analyze massive volumes of security data from diverse sources affordably and efficiently, setting the stage for advanced AI capabilities and automated security agents. The goal is to eliminate the trade-off between comprehensive security coverage and budget constraints by creating a centralized, scalable foundation.
This new platform is built on several key innovations. The Sentinel Data Lake, now generally available, provides a low-cost tier for long-term data storage (up to 12 years), separating storage costs from compute costs. This makes it feasible for organizations to retain voluminous logs from network devices and other third-party sources that were previously cost-prohibitive. On top of this data lake, Microsoft is introducing new ways to interact with data, most notably the Sentinel Graph. This feature allows analysts to visualize relationships between assets, identities, and activities, helping them to understand complex attack paths and blast radiuses in a more intuitive way, because “attackers think in graphs.” The platform also includes a new MCP (Microsoft Copilot Protocol) server, which enables natural language queries and provides a framework for AI agents to discover and use security tools automatically.
Microsoft emphasizes that this is an open platform designed to support a thriving ecosystem and heterogeneous customer environments. With nearly 400 connectors, the platform is built to ingest and correlate data from third-party tools like CrowdStrike and Zscaler with the same fidelity as Microsoft’s native stack. The vision extends to AI-driven actions, like Attack Disruption, which will be expanded to take actions on third-party systems. This entire stack, from the data platform to the AI capabilities, is brought together in the new Microsoft Security Store. This marketplace allows customers to discover, purchase, and deploy curated security solutions and AI agents from both Microsoft and its partners, completing the transition to a unified, AI-ready security architecture.
Presented by Scott Woodgate, General Manager, Threat Protection, and Gideon Bibliowicz, Senior Director, Product Marketing. Recorded live at Tech Field Day Exclusive with Microsoft Security on October 9, 2025. Watch the entire presentation at https://techfieldday.com/event/mssec25/ or visit https://www.microsoft.com/en-us/security for more information.
Transcript
Hi everyone. We're here in Redmond, Washington. My name is Gideon, um, I run Sentinel on the business unit in Microsoft Security.
I'm Scott. Nice to meet everybody. So today, as Scott said, we want to give you an overview and answer some good questions around the evolution of Sentinel.
We started this journey, um, in July and followed up at Microsoft Secure on September 30th. So very, very recently. So it's good to kind of share this with you right after the event.
Uh, we're on the journey of evolving Sentinel from, uh, market leading sim to being a full fledged security platform from Microsoft Security and our partners. So we wanted to give you a little bit of a frame of why we're doing this, how are we thinking about this journey? And of course, as Tom said, please, uh, ask questions.
And then Abha and some other of our colleagues will walk you through some great demos. So with that, we wanted to kind of anchor the conversation or start it with just kind of level setting on Microsoft Defender. And I know it's a bit confusing when we want to talk about Sentinel and we start with Defender, but we want to kind of level set on the fact that for security operations, where we serve product value, innovation and services is Microsoft Defender in the Defender portal.
Over time, and this is work that Scott is leading at Microsoft, we're converging all of the security operations value in the Defender portal. So, for example, um, customers get Sentinel as a sim in the Defender portal. We have Security Exposure management as well, our proactive services for security in the Defender portal.
We're converging the cloud part of Defender, Microsoft Defender for cloud in the Defender portal. Uh, and we're adding a lot of value around threat intelligence as well. So Microsoft Defender is our primary product for security operations.
And then in Defender Portal is where our customers kind of go and get the value, uh, of these products in one place. We had Microsoft Sentinel as our market leader. Sim again served from the Defender portal.
And over time what we wanted to do is essentially expanded beyond being a sim. So you see here kind of the the journey a little bit of Microsoft Sentinel. Uh, Scott was actually one of the people who launched it back in 2019 as a cloud native sim.
Uh, over time the team has invested a lot, uh, in different advanced capabilities for sim like Soar Yuba Tip and others we're making, you know, a big investment over time in connectors to bring as much of the security data that customers need into Sentinel as a sim. Um, and today we have, you know, close to 400, uh, connectors and we'll continue to update on, on those numbers. And then there's been a lot of, uh, investment in generative AI capabilities.
How do we help customers do you know, more in less time? And using, of course, the new capabilities come our, uh, that are coming from generative ai. So within that, we have today, roughly, that's the public number, uh, 25,000 customers globally.
And that, you know, uh, number continues to grow of course. Uh, and then in July, what you're seeing on the right hand side, July 22nd, we announced public preview for the Sentinel Data Lake. So we essentially expanded what Sentinel is and we're, uh, we added, um, kind of a low cost data tier to Sentinel Sim and starting the journey of making it more of a security platform.
Uh, so that was July 22nd in public preview. And last week on September 30th, as Tom said, as part of Microsoft Secure, which was a digital event run by Microsoft, we announced that essentially we hit general availability with the Sentinel Data Lake, but we also added some great capabilities that are new in public preview, uh, completing kind of Sentinel as a security platform. And we'll go through them both in slides and then in demos and of course, answer your questions.
Some of those just at the high level is a new sentinel graph that helps customers, uh, human and of course in the present and the future. Also, agents traverse a security estate through a graph data modality. Uh, and then we have a new Sentinel MCP server, uh, with some initial set of tools that we're going to grow over time, enabling users, customers to access the data in a more kind of natural language type of way and setting the stage for agents, uh, to do the same.
So if we open the aperture a little bit, zoom out a little bit, so to speak, this is what we shared on September 30th. When you think about our portfolio, uh, we have the, of course, the Microsoft security product, Microsoft Defender for Security Operations, Microsoft Intra for Identity and Access Management, Intune for device management and purview for data security. These are the core capabilities, uh, of Microsoft security as we offer them today.
And then at the bottom, what you're seeing essentially is us, like I said earlier, positioning Sentinel and expansion of it from a SIM to a full fledged security platform and the capabilities that I just mentioned. So it's important to note, you know, as we bring the data that you see on the left hand side through these 300 plus close to 400 connectors today, the data, the graph capabilities, the MCP based capabilities are all designed to benefit the customers and users who are using our first party Microsoft security products you see at the top there, but also our ecosystem. And by that we mean the partners, the service partners, the ISVs.
We're building solutions based on this, uh, stack and offering value to their customers. And we're, we're gonna walk you through some examples of partners that we, uh, have done work, uh, with on this, and they're kind of committing to this vision of Sentinel as an evolved platform. And then you see on the right hand side, uh, the Microsoft Security store will again go into more detail on that.
But the Microsoft Security Store was launched on September 30th in public preview. Uh, and that's where security customers can go and get a curated experience of discovering security solutions and agents. They can purchase them, the transaction happens right there, and then they can, uh, deploy the solution or the service from either a Microsoft source or a third party source, which is a great part of kind of this whole platform view for, for us at Microsoft.
So hopefully you're seeing here that we're working and designing and building to serve through our Microsoft security first party products, but also through, um, building a thriving ecosystem around it. So I have a question before you continue. You started the conversation talking about, uh, how we access things through the Defender portal and in the September 30th announcement, and here we're talking about, uh, Sentinel becoming the sort of the security platform and it being AI driven and the security co-pilots.
Is the intent to transition from Defender being your primary interface to Sentinel and the security platform being your primary interface? Yeah, no, so it's a great question, by the way. So, uh, defender will continue to be our primary portal for security operations as we evolve Sentinel as a platform over time.
What we started to do last week, and we'll show you later on, and we're going to continue to do, is actually offer more of these capabilities in our other portals. So as the Sentinel becomes our platform, we started to, for example, to service graph based capabilities in purview, and we will continue and add those in intra and Intune over time. So, you know, while Sentinel, uh, started in defender, the Defender portal, our goal is actually, uh, to kind of expand services value, uh, agents running in these other portals supported by the data, the graph modality and the MCP capabilities in Sentinel.
I don't know if you wanted to add anything. Yeah, fun. Fundamentally taking some of the capabilities that a sim would have in turning them into platform capabilities.
And by being platform capabilities, they then become architectural pieces that live underneath, uh, the three Microsoft or four Microsoft portals. And, and also ISVs can build applications on top of it. So, you know, Java as a platform, Azure as a platform, Sentinel as a platform, you can do stuff on top of it, uh, first party applications like Defender and, and Intune do it, but third party ISVs can too.
Thank you. Awesome. And thank you for stopping me for questions.
That's helpful. So, um, if we kind of double click, you know, one click further. So you're seeing here a little bit of a architecture of the high level view we just showed you.
So you see at the bottom, you see the new Sentinel Data Lake, again now generally available. Um, and we have a few hundred customers already kinda who've tested it in, in public preview and are transitioning their security workloads to the GA bits you see there in, in a little bit of a simplified view that the data lake includes different stores. We have the asset store, uh, we had an asset based kind of graph and product in security exposure management, the GA back in November at Ignite last year.
And that's being consolidated into this architecture. We have the activity logs, of course, in an activity store comes from from Sentinel as a sim. We're adding a TI store where all the ti information, uh, and data will be part of the data lake.
And there's gonna be also a content store where when we, uh, store unstructured data that will be part, for example, of some data security investigations, uh, files, or any other information that we need to store in a content store, as I mentioned briefly. Um, once you have the data kind of ingested and centralized and normalized to one consistent schema in the, in the data lake, what enables us to do as Microsoft security is to kind of offer that data to the customer in different modalities. So you see there, for example, you know, of course tabular, uh, which has been around now, we, we can offer graph based modality and we'll show you some of the experiences in defender, exposure, management and purview that we're now able to surface.
Um, and we're gonna, as I said earlier, kind of expand, expanded across the portfolio and enable partners to use it. Um, and then vector embeddings, of course, uh, for, for AI based capabilities, we vectorize the data and that's gonna be part of, of the abilities, for example, of the MCP server that you're seeing, uh, right above it. So the data is centralized, normalized, using a consistent schema, uh, and open format data format.
And then we offer it in, in different modalities, uh, both for our first party experiences and our third party experiences on top of it. Uh, you see the MCP server announced, excuse Me if I may then, since, since you, you brought up schema. Hi, uh, Fernando Montenegro with the, the group, uh, I I love the, the, the, the visuals.
One of the questions i, I have is where are you in, uh, when you talk about platforms, where are you in relation to the broader ecosystem? My mind goes immediately to the, to all CSF right? To the, to the open cybersecurity schema framework.
How do you relate to that, uh, initiative? Yeah, so support of OCSF is absolutely part of our plan and our roadmap, Fernando, we're not there yet, but the team is actively working on it. And that's the plan.
Part of our design of this platform is to be an open platform. You'll see it in, um, you know, supporting OCSF, for example, uh, in the near future, and then also in kind of how we work with partners overall. Uh, we'll show you some examples that, um, you know, within Microsoft, we are having a lot of debate of, you know, how open we want to be as a platform, but the goal here is to essentially enable, uh, Microsoft Partners customers to collaborate on cyber defense and supporting OCSF to your question is, is part of the plan.
Perfect, thank you. Yeah, sorry, Justin Warren from Pivot nine, sort of a follow up question. You around the modalities, um, and, and the integration into other systems are, is the data available through all of those modalities?
So there might be some tabular data which I can then access using graph queries. Is, is that the intent of, of the platform? Yes, a hundred percent.
That's one of the intents from, you know, to your point, uh, Justin, from a data modality standpoint. So for example, we'll show you a demo, Abha will walk you through examples of where, let's say purview, a data security analyst does a data security investigation or insider risk investigation, and they use a quote unquote traditional view that is tabular based, but then they can choose to move to a graph based experience where they visually see the part of the security graph that is relevant to the investigation that they're conducting. And that enables them to traverse between machines, users identities, data reporters, stories, IP addresses, and really understand visually, um, what, what has happened, uh, what's the threat or what are some of the potential implications even So for us, yes, the answer to the direct answer to your question is, yes, we will offer this data in these different modalities.
The Sentinel platform will do that for you as a customer, and then we will enable different experiences based on this to enable different modalities of security work, if that makes sense. Okay. Thanks.
One more graph question if I may please. Um, sorry, I, I lost graph. Uh, what is the relationship between the, the graph models that you have now for Sentinel with the broader Microsoft graphs right around, uh, uh, Microsoft 365 and so on, right?
Uh, how do I, are they coming together and, and how is that, uh, what's the, the, the, the, the, the plan there? Yeah, so it's a great question and I invite Dan AB and Scott to, to chime in, but essentially think of this as a, our platform for security. So we focus on security scenarios and we help customers and partners bring in whatever data is relevant to their security work.
So for example, yes, there are M 365 audit logs and other types of logs that we will bring from, you know, a productivity graph or a platform graph in Azure. Uh, whatever data that is relevant will will be ingested here. And of course, the customer gets to decide what data they want to ingest and so forth.
Some data, for example, from M 365, we can auto-populate in our data lake and then in our graph. And there's work between, of course, internally, as you can imagine, between the security engineering group and the M 365 engineering group to, to support those scenarios. And many of them are already live in, in the data lake and the graph.
So it's not one and the same, but we are focused, if I would say, on the outcome. And as you know, Fernando, for security outcomes, almost any, any data we say, any data can be security data depending on the scenario. So we want to enable customers to do that.
Yeah, that's precisely why I asked, right? It's interplay between applications and, uh, anyway, go ahead. Thank you.
Great questions. All right. Um, so, you know, uh, I think we started to touch on the MCP server and the tools.
We announced public preview on September 30th, uh, where essentially enabling initial set of capabilities around natural language search. So, for example, people can use natural language to ask questions around what tables are available to me in the data lake. So instead of running queries to understand what data they can use, they can just ask a question and we'll show you some of the demos.
And then over time we will build a, a rich set of tools. Um, you know, we're coming up at Ignite, so late November, early December, we'll continue to add tools, uh, that will enable not only user experiences within our first party products, but also agents to run and use. The MCP server essentially has that catalog of tools or functions or services, uh, that those agents can auto discover, right?
So part of the magic of an MCP server and why so many in the industry are exploring the tech is because you can add tools behind the scenes, publish them to the catalog on the MCP server, and then agents automatically know that, you know, that could be used, you know, for whatever query or activity or job that we done that they're conducting. So it's an area, uh, where we kind of push the envelope with our engineering friends on going fast, launching relatively early, and learning and iterating and getting a lot of feedback from our customers. So we are exciting to go see that.
And then on top, you see essentially the, the, the SIM workloads that you're familiar with, I believe, uh, everything that Sentinel offers today, as we had talked about as a market leading sim detections hunting, Yuba soar, we're continuing to invest in Sentinel as a, as a sim it's a category we not only care deeply about, but we think is critical to what customers are trying to do in the security space. So you'll see us, um, come back and announce, you know, um, innovations and investments in Sentinel as a sim, but as you can see here, we're now kind of on the journey to expand it, as we said at the beginning, as a, as a security platform. So, just to interrupt for one second, um, just so I can kind of put it logically in my head, the expectation from your side is a SOC analyst would make use of the Defender portal still, but would also go into Microsoft Sentinel for additional, uh, information, or the information in Sentinel would be pushed to the Defender portal, so that would be their main go-to.
Yeah, so yes, so it's a, it's a great question and that's part of the, the journey we're on. So today I saw panelists will go to the Defender portal and they will have all the defender capabilities there that we started with, and they'll have access to Sentinel as a sim. That's where essentially they operate Sentinel as a sim As we expand Sentinel to become this underlying platform.
And Scott, uh, commented on earlier, then we will enable more and more capabilities for Sentinel and Defender users in the Defender portal, but we will also expand it to data security in Purview, which we already started identity and access management in Antra and so forth. So, yeah, So as an, so as a SOC analyst, I then have to join you on this journey to figure out, this is where I go for this information, this is where I go to do that. Is that right?
Like I'm, I'm not quite Understanding. Yeah, I'll, yeah. Sorry, I'll just jump in.
Yeah, Zoe, it was the second thing you said. Does that make sense? You, you go to Defender, everything's in defender, including the Sentinel information.
So, so you, you, there's no joining on a journey in the sense of there's not two different places to go. Right? Every, everything in the Sentinel platform that's relevant to a SOC analyst appears in Sentinel.
What Gideon was answering was actually beyond a SOC analyst. There are other personas like the data security person or the identity person that live in other portals, such ASRA or purview. And they will also be able to take advantage of platform capabilities that surface to them to do insider risk management with graphs or data security investigations with graphs.
But, um, our overall approach here is, is persona centric in portal, and the defender portal is where the security persona goes to take advantage of these services. Okay. And then when it comes to like being able to give, um, role-based access, it should be quite clear then if you're this type of use case, you're this kind of type of persona, this is the type of rights you need because you need access to this portal.
Um, if you're, that these are the rights you need 'cause you're in that portal and it's quite distinct, then Yeah, it's distinct by portal. And then of course within portal there are different roles that have different levels of access. And so there's an another double click in the, the level of granularity within the defender portal on what users you want to have with which permissions, but absolutely.
Okay. Hey, this is Taryn. Bryson, I've got a quick question on pricing and it's not specific, so, so don't get scared.
Um, we, at a previous company we deployed Sentinel and we were, we were largely an Azure shop, so we were about 95% in Azure with a very small on-prem footprint. And, uh, one of the things we found was ingesting Microsoft data or a, or more, I guess generally Azure data was, was, you know, fairly reasonable as these things go price wise. But once we started ingesting, you know, SNMP slog, whatever stuff from, from outside or from other sources other than than the Azure Cloud, um, or, or even on-prem Microsoft, it became, uh, quite expensive quite quickly.
And I'm kind of wondering if that's something you're looking to normalize. Um, you know, so because obviously as a security platform, you wanna be able to get everything you have so that you can an you can perform a better an analysis. Um, you, and, and if you don't have insight into that, that's fine.
I just, I had to ask the question. I can get, I can get it. Um, fir firstly with, with some buts, we don't price differentiate Microsoft stuff and non-Microsoft stuff.
That's not how our business model works. Um, there are some buts on that, which is, um, we do, we do give you some, um, E five benefits, uh, for certain things and then for certain Azure work stream and suite, um, they're free base work streams. But as a general statement, we are not, uh, making non-Microsoft stuff more, more expensive than Microsoft stuff.
Um, what we do see, however, is some, um, some streams are, uh, more voluminous than others in terms of data. Um, so for instance, if you're putting in network logs, network logs as a stream can be a lot of data. And, um, those types of streams may also not be used in every investigation all the time.
Um, and so in the old model, before you had a data lake, you had to put them in the equivalent of hot storage. 'cause that's all we had. Hot storage mean that that was very easy to run detections on them and get security value out of them very quickly.
But you are paying for a hot storage price in the new model here, we've made it much more affordable to store all of your data. Um, for us pricing in a certain region it's 6 cents, uh, per gig as opposed to list price of $4 something or other 6 cents, um, to get data in the data lake. So one of the core thesis of this approach was to make it extremely affordable to get data in the data lake and actually separate compute from data in a pricing perspective in the data lake, uh, to enable that.
Um, so the short version is we've seen lots of customers who wanted to put more data into their sims generally, but because sim architectures didn't have modern data lake architectures that separated, uh, storage and compute, they were limited on pricing in the industry in general, including us. Um, and this data lake will now enable you to literally store all the data you want. That's kind of the whole, one of the whole points is to create data gravity here, because if you think about it from an AI lens, the more data you have in there, the better off the AI is in doing its job.
Okay, thank you. Of course, yes. This is, uh, this is Marian Newsome.
I have a question about the vectorized data. You talked, what controls are in place to keep it from, um, having model drift or, uh, allowing other vectors? Yeah, and I don't know, um, Abha, if you're with us on the call there and you want chime in.
Yeah. Um, uh, good morning, Marian. Um, so we use, uh, you know, internally use models from, uh, Azure and Azure OpenAI to the data.
Um, so you know, it goes through all the standard checks, you know, responsible AI validations. So before we introduce any change, uh, we validate, you know, what models we are using before we try to change the model and make sure there is backward compatibility and the efficacy of the searches, uh, is meeting our prescribed bars before we make any changes. Thank you.
All right. These are some great questions. Just wanna make sure we've answered all of them.
All right. Okay, cool. And I think, uh, Taryn, your question earlier, I just wanna add, you know, if you, if you had a chance or you will have a chance to watch the events from from last week, uh, David Boda, the CSO of Nationwide Building Society out of the UK talked specifically about what you're kind of directing at, which is this is helping them kind of ease or completely eliminate the trade off between achieving a security outcome and their budget constraints.
So as Scott said, you know, when you want to ingest very, very voluminous kind of types of logs, uh, for new security outcomes, it was cost prohibitive for many customers. And now, you know, we're seeing customers making those trade-offs, including those high volume, uh, tables that you mentioned. So it's absolutely part of the design.
Um, so just broadly, um, when you think of your, the ecosystem integration, when we look at most SOCs today, they operate in hybrid environments. There's the opters, CrowdStrike, ServiceNow, et cetera. So as we can see from your roadmap, you're looking to build AI driven context, um, into Sentinel.
So will those insights work with the same fidelity when it comes to third party tools or for deep automation? Um, is there dependency on running a Microsoft native stack end to end? Yeah, no, so that's a great question and that's what we mean when we earlier said we want to be an open platform.
And that's how it's built and designed. So from ingesting the data, making it available in different modalities, serving it through an MCP protocol and so forth, what we may not make sure is customers don't have to be entirely on the Microsoft stack stack. And of course, customers have heterogeneous and security environments.
So we're, you know, doing a lot of work. Abak and his team are doing a lot of engineering work to enable exactly that. Part of it is those 350 400 connectors that we've had, you know, along our Microsoft security history and different products are being unified, consolidated, you know, being consistent.
So there's one connector per data source and customers can more easily than before in less time than before kind of brings that third party data. Uh, so a hundred percent, uh, for example, we had Zscaler join us last week, which was surprising to some people in the industry, but that's part of us kind of saying, Hey, yes, there are gonna be some, uh, quote unquote competition situations, but we understand that to really better serve the security outcomes of our customers, we need to do it exactly like you suggested, which is make it easier for, uh, customers to operate those heterogeneous security environments, if that makes sense. And we can go into more detail, uh, if you'd like, but that's the high level gist, unless we wanna add something.
Yeah, I, I'll add, and I think your answer was good for a platform answer and getting data in and, and honestly we've had that for a long period of time. You, you don't have a sim without being able to get CrowdStrike data in. 'cause it's a very important EDR for many customers just to pick a thing or, you know, email security or Proofpoint or pick your favorite of the 350 vendors.
I think your question though was, at least how I interpret it, was more at the AI layer, what do we do differently? And I would say today we do, um, correlation outta the box with detections that are, you know, custom detections, third party detections, Microsoft detections, all that works. We do have some secret source in Sentinel that's, um, and defender that's differentiating in the market.
Uh, we call it attack or disruption. It's like having a set of saw playbooks that Microsoft owns and runs that are actually, uh, machine learning models that are updated and run in real time. And what does attack disruption ultimately does is stop an attack in the middle of an attack, uh, because it recognizes a series of signals that recognizes, I've been phished, it recognizes my device has been taken over at patent matches off a couple of other people that might be in a similar situation, and then it shuts down my identity or shuts down my device, um, or other things.
And that particular technology today is centered in Microsoft centric assets, but you will see announcements over the next short period of time where we'll extend that even that period, uh, technology so that we can go do things. And block, um, attack is moving forward to, um, what I think of as third party assets. So even at the highest level of very differentiated value, um, where we are stopping attacks in real time, um, using ai, we wanna be able to take actions on third party systems, not just our own systems.
'cause in those scenarios, we disable an identity or disable a device or disable access to something. So AB absolutely that's a core part of the plan across the full stack. Thank you.
That's, that's good context. I have, uh, I have one, one question since you, uh, you brought up, uh, a couple times now the AI side of things, which is, is obviously, you know, the direction the industry's moving, how are identity and access management's kind of key for, for, you know, doing any kind of ai? I mean, ideally, you know, smart people anyway are, are, you know, you, you're, you're making sure your data's not gonna get exfiltrated, et cetera.
What are you guys doing on your side as far as data processing when it comes to co-pilot and whatnot, specifically with this product? In other words, you know, co-pilot's analyzing, it's, it's doing kind of what it does. Uh, it, it's doing it presumably on your, you know, you know, on your, your servers, your cloud, whatever.
Um, how does, how is my data safe, I guess in this case is, is what I'm driving at? Yeah, I mean, ultimately security copilot works across your data. That is, is your data.
Um, we are not out there, um, sharing context across customers or other things like that. Um, so, so fundamentally architectural design is, is set up in a segmented way that enables that, I thought you're gonna ask me a question around agent ID and, uh, identity there for a minute because, um, certainly agents, you know, will, will work in a, a workforce similar to, it's similar to people in some degree. Uh, and certainly we think that agents will have IDs moving further forward and, and those ideas that are based in intra is, is a core construct just to, I can give you another different direction on your, on your question.
Perfect. Yeah, we're, I'm trying to start slow, so we'll get into, we'll get into some tougher stuff later. No, that's, that's, that's great.
That's great answer. Thank you. Awesome.
These are some great questions. Appreciate that. All right.
So we wanted to kind of share some of the use cases, examples. Uh, these are anonymous for now from our customers, but starting at Ignite, you'll see them, you know, on stage with us telling their stories. Um, and you can read through them and I'm gonna read it all, but you know, we, what we see here is a combination of security outcomes and cost efficiencies exactly to your question earlier, Teran.
So you see here on the left hand side, the ability to just re uh, reduce complexity, improve, you know, incident investigations once the data, as we said is centralized normalize in one place. So that's kind of the data lake with the different data modalities and having that unified model helps kind of simplify the security outcome. So, so that's always great for us to see.
And then you see here kind of, uh, the, the one in the middle exactly to your, also the other question, Aryn is customers seeing the opportunity to bring net new data that they couldn't do before the high volume data directly into the Sentinel data lake. And of course, that enables them to kind of investigate in a different way and kind of expand their security outcomes. Um, and that customer will probably be with us on stage, uh, at Ignite.
And then you see some of the, just the, the cost affordability on the right hand side, including kind of the longer term retention. So customers were pretty constrained with the length of the retention and how, how long back in time they can go and, and run queries and understand what has happened in their environment. With a Sentinel data lake, they can go up to 12 years, which most customers don't have to go all that far out, but they're, they're definitely having more flexibility right now, whether they need it for a year, two years, three years, whether security, compliance, governance, uh, outcomes.
So it's just for us great to see customers this early on, uh, seeing that value. Um, and you know, a BN Amro is one of the earlier Yeah. Quick question very, very briefly.
You brought up, uh, 12 years. I was just wondering why 12? Why not seven, why not five, why not 15?
What's the 12? Is it the Yeah, I wish I could, it was there. It's a great question, Fernando.
Um, was there a specific reason for 12? Yeah, so we, we were looking at, uh, you know, it's, it's a very nuanced answer to looking, we are looking at like, what are the different compliance requirements across the globe, you know, what does it mean for it in internally and from a Cox perspective, you know, underlying, of course, we are using technology from Azure data and Azure and, you know, what are their, uh, like in terms of scale and performance. So various factors came in to say, yep, like that number would help us meet most customer regulatory requirements, uh, and allow us to manage cost and deliver service that is performed As we, as we get closer to 12 years, we start to get close to the Unix bug of 2038.
How has that factored into your conversations? Uh, that's a great question. I don't know the answer, but, uh, I will follow up with my architects and get back.
Yes. I, I think it's, uh, yeah, we're getting to the time when it's worth, start thinking about that like many of us were around Y 2K. Yeah.
And, uh, have fun memories of those. Thank you. Sorry.
No, that's awesome. That's great. We have some new things to go investigate that's, thank you for that.
Hopefully, hopefully we get through quantum encryption before then. But Before you guys proceed, can you, um, sort of talk a little bit about the trade-offs of ingesting directly into the data lake versus ingesting into the analytics database first? Yeah, I can go.
Um, so the, the data lake has mentioned, uh, from a pricing perspective, we wanna make it super affordable. So we split, uh, ingestion from, uh, compute, which means it's very, very affordable to, um, put data in. Um, but you're not paying a price for both of those things at once.
Um, if you do compute on top of it, you do effectively pay as you go for the query work. Um, so there's always a trade off between simplicity and flexibility, um, in terms of, or lower price and, um, simplicity in terms of this thing, um, that's, that's a key trade off. You just need to understand.
Um, in terms of the data that you put in the data lake, um, there are limitations on what the system does with that data. So, for example, security detections and Sentinel run in the, uh, log analytics layer. They do not run in the data lake layer.
So if you wanna run security detections on your data, which is pretty important, you wanna do it in the log analytics. So now having said that, you can promote data, uh, if you can aggregate data fields and promote specific data from the data lake into, uh, the log analytics layer, so that data that is in that data lake layer can actually participate, but not all of the data literally, um, in the data lake layer can participate. So generally speaking, um, the zero to 30 days of data that I need for security analysis, um, the right place to put it is in, um, hot and then storage beyond those, uh, timeframes or, and or of voluminous logs would be in, uh, the data lake.
I'll also say the architecture of the product is designed so that as you ingest data through the connectors, if you are putting it in a hot, a copy is already copied into cold, um, into the data lake at the same time. So we, we, uh, give you that copy because there's some flexibility capabilities that we haven't got into yet, including being able to use a Apache Spark and a bunch of custom solutions. And we wanted to make sure that the data lake has the full set of data and the hot, uh, aspect is a subset of it.
But, but the core thing is the, the fundamental security detection value, um, that the Sentel SIM runs, uh, still continues to rely on on hot. Anything you wanna add to that abha? Yeah, and, uh, I would say, you know, once the data is in the lake as, uh, Scott mentioned, that becomes your full primary copy, and it's a single copy of data on top of which you can do multimodal analytics, as K was mentioning.
So by default, you can run KQ analytics on, on the lake, you can do Spark, and this is really of interest of, you know, customers who have invested in a security data science team. Now you can really use the power of Python and notebooks, and essentially you can do schedule jobs on top of it. So you get the best of both worlds where you can store all data cost effectively.
And then depending on your needs and depending on, you know, the maturity of your swap teams, you can do really deep analysis on the data using big data tools to derive insights. And then, as Scott mentioned, promote to your standard sentinel tier so your SOC workflows can be enriched with insights from the lake. And one thing I'll add, you know, Terran asked us earlier about pricing.
So just, uh, one detail is once you ingest into the analytics tier, and as Scott mentioned, we mirror that data, so to speak, into the data lake, that part of the data comes at no additional cost to the customer. So if you've already ingested data into the analytics tier, we'll mirror it and complete your copy of data in the data lake without charging the customer any additional cost. And so, sorry, I, I, I'm, I don't dive as much into the cost conversation, but one of the things I'm curious, uh, so you have the full data lake, which is, uh, hot and cold, Katie Perry references, uh, but then you have, um, the, the analytics on hot.
Are there any pricing considerations for me, performing independent analytics on the overall dataset and not looking at the hot? In other words, can I create, or would I be thinking about, okay, I'm not gonna touch the analytics I component of it, I'm gonna run everything on, on the cold data, on the main, on all of the dataset. Would there be a cost difference that I would be concerned about or, or thinking about?
I mean, uh, if it's considerably more affordable to put all the data in the data lake, um, if you are running, uh, Apache Spark and your own custom stuff, um, you can do all of that on top of the data lake. Uh, once again, one of the reasons why the, um, analytics tier above that has dollars associated with it is it does, you know, security detections, it does correlations. There's, uh, AI that builds on top of that.
There's a bunch of value that exists in the, um, the hot tier that does not exist in the base tier. But if all you wanted, if you were an ISV building an app and you wanted a data store, and on that data store, you wanted to do anything you wanted, like that use case is deliberately designed to just go do it in Day Lake can have fun. Perfect.
Thank you very much. Awesome. Thank you.
Fernando, This is, uh, Romeo Gardner, uh, with Nelo. Quick question. Uh, is that Data Lake available for Azure government or any other, uh, sovereign clouds?
I'm totally punting that one to Abhi. Yeah, uh, very much on the roadmap. Um, and you know, so, uh, we will make sure the data lake is available in all Azure regions and environments where Central is supported, which will include, uh, our government clouds and other regulated clouds that we support.
Awesome, Thank you. And timeline wise, it's basically, you know, uh, before, like we run in fiscal years, which is, you know, so this, we are in our FI 26 fiscal year, which will end of June, so we'll be in that timeframe before that, before the end of the fiscal. Oh, just to add a disclaimer for, for certain government clouds this the, be careful of answering the whole world's government cloud.
Yeah. I think the question is with US government. Yeah.
Yeah. Thank You. Awesome.
Okay. Uh, so we have this example we started to touch on, we don't have to spend a lot of time here, but of course AB and amro a large financial institution from Europe and everything we just talked about, uh, you know, they, they're seeing kind of the value, whether it's breaking down the silos of security data, scaling automation for security, and as Scott said, setting up, setting it up for, for AI and agents and expanding coverage. You know, that's what essentially we want to do.
We want to help customers kind of ease off that trade off that we talked about earlier. So, you know, a b and AM was one of the first one to say yes, put our name and logo side by side with View and Sentinel platform. So we want to, we want to share that, and we will do more of that customer use cases going forward.
Now, we were asked earlier about our partner, uh, ecosystem and how we make that work. Um, it's by design a big investment area for us, uh, starting from product design and architecture, uh, all the way to, you know, business development activities, go to market and marketing, um, as we did last week, this is part of an initial set of partners that are already working with us. Of course, different stages, different scenarios.
You see here some of the industry leading service providers in the cybersecurity space, um, and they're helping customers think about their data strategy with this new architecture, you know, how to bring the data into the data lake. Over time. We will, uh, enable data federation, so we'll enable customers to, uh, access data in place.
And, you know, these partners are thinking through that architecture and the design with their customers. Uh, and you see some of the names like Accenture and IBM and so forth, they have been with us, you know, almost from the get go. Uh, and they're very excited to kind of enable new services and new architectures, uh, for security, uh, with us.
And then you see here, obviously some of the, some of the great ISVs that are in the industry. Uh, last week we showcased Illumio as one of the first ISVs that built a full stack solution utilizing their ip, of course, for their scenarios and their customers, but building on the data in the Sentinel Data Lake, utilizing, uh, Sentinel Graph, building an agent with security co-pilot, and then publishing that to the security store that we will, uh, cover later. Um, and you see here some, like I mentioned earlier, some of the logos that are, you know, in kind of a, a competition situation with us, like Zscaler, but we believe that to really address security outcomes for joint customers, you know, this is how we have to go.
And as Scott said earlier, you know, data is the fundamental layer, but we will do more on the compute side, um, and the IP side in, in general to, to create that value. So these, uh, logos represent customers who have been working with Abhishek and as engineering team, uh, for months now. And some of them already have published solutions and, uh, offerings in the security store, and some are in the lab with us, uh, building those scenarios for, for our joint customers.
So just this slide is, is just to kind of underscore the point of we don't think this is a Microsoft security standalone journey. We really are investing in building the ecosystem and make it as rich as as possible. Uh, I don't know if there are any questions about that, but we, we wanna, I, I'm, my, my one question is, other than Zscaler, which is S-E-F-F-E, uh, where are you on stronger network security partnerships?
Yeah, so, you know, the nature of these BD engagements, and Scott can overrule me, but usually we, we can't comment, uh, on them until, you know, those are done. And, and we can disclose them publicly. But Fernando, like Scott said earlier, network logs and network security are one of the key scenarios for high volume logs, for example, that customers wanna bring in at a lower TCO.
So yes, we are working on those and as soon as we can share it, we will, we will share it. But I, I just add that Sentinel, uh, as a sim has, this is not the connectors for Sentinel as a sim, it has 350 of them. They include Barracuda, Fortinet, and, you know, Cisco, da da da.
And so you can imagine that we worked with all of those folks in the past and, and we recognize that, you know, Microsoft doesn't have as much first party presence in network security. And so it's really important for us to work with the network security vendors and, and move things forward. This is just a day zero getting started.
Perfect. Thank you very much. A hundred percent.
Great question, Fernando. Alright, so, you know, we talked about the data, we talked about the partners. Um, so one of the things we announced last week in public preview is a sentinel graph.
Um, and I think you know this, we've talked about this in many forms. We, we GAed uh, security exposure management back in November. And what we doing now is essentially extending and consolidating, as I said earlier, you know, the asset-based graph, activity-based graph and, and we'll announce more in the near future.
But the fundamental premise is attackers thinking graphs, uh, we see it with our customers. We have been public about previous, uh, attacks that Microsoft was the target of. And those attacks showed, uh, in space that attackers look at a, a target environment and they try to understand the dependencies between the different entities, the endpoints, the users, the data, um, and the network constructs.
So they can kind of go in, find a vulnerability, of course, exploit it sometimes in what we kind of loosely call a low and slow attack, which means they come in, they sit there for months on end, they're, they're kind of essentially aiming not to be, um, discovered, of course, but the different, uh, triggers in the system and then they traverse and they go, uh, and exploit the different vulnerabilities. So with exposure management back in November, we started with a pre breach scenarios of helping customers understand, you know, what are some potential attack paths that, uh, an attacker could exploit, but in doing it way before something ever happens, uh, what are some critical assets that the customer wants to prioritize? What are some single choke points for a potential attack path?
Um, but now that we are essentially consolidating this across all of our scenarios and across pre breach and PO post breach, that really opens the aperture on the types of scenarios and use cases that we can offer to our customers. So that data modality that you saw there, the graph data modality is the basic premise of this. And that enables us to do that, whether in first party experiences and of course, over time in more and more third party, uh, experiences.
So the Microsoft Sentinel graph, like, you know, I just said, enables this and we'll show you, uh, examples that of there's a threat. And then the, the defender now has the ability to essentially visually traverse a part of the graph for a specific scenario and do their job to be done, uh, more efficiently. So here you're seeing, uh, advanced hunting in Microsoft Defender, um, this is the actual product and a security analyst kind of sees the inve the, uh, hunting scenario, uh, in a visual way.
And they can, this is obviously a slide, uh, AEK will walk you through some, some demos, but the, the security analyst can traverse this graph. They can click on a certain entity in this graph and expand that area, uh, of the, of the investigation. Uh, and they can really understand things like, for example, you know, what is the blast radius of a certain attack, you know, what could happen, what could be impacted by a certain weakness being, uh, exploited by, by an attacker.
So this is a net new graph based experience that we launched last week. Uh, and of course it's been running out into customer environments. This is, um, another example, and this is where, as we said earlier, we're going beyond security operations specifically here.
This is Microsoft Purview. Microsoft Purview is our product, um, and console for data security. So here you're seeing a data risk graph.
So a data security analyst, uh, now can use a graph based experience in Microsoft purview, uh, to do their job to be done. So whether it's a data security investigation in this case, so there's a, a threat to, to a sensitive asset, uh, from a data standpoint, or if they're doing an insider risk investigation, uh, for example, then now we have these scenarios backed by the option to go to a graph based modality and do the investigation. Uh, based on, on that, And this is Romeo again, had a, had a quick question around, uh, the graph.
Are we looking at a scaled down version in terms of, uh, tracing out, uh, vulnerabilities or a, a path? And the reason I'm asking that question is I'm thinking about scaling that to multiple devices, multiple, uh, or hundreds or thousands that could be placed there and having somebody having to go through that and look at that data or that graph. Yes, a hundred percent.
So I'll start, but Scott and AB should please chime in on this one. You know, what we're seeing here, and maybe that's the source of your, your, your question, Romeo, is, you know, we're just seeing the part of the graph that is relevant to this specific investigation, right? But absolutely a graph is built for a customer environment across all of their security data, um, that can scale.
And Abha and team are continuously working to improve the, both the performance and the scale. But yes, the graph scales to, you know, millions of nodes and edges. Um, but for a job to be done for a certain per persona, and in this case a data security anana analyst, then we're seeing that part of the graph.
And, but they can traverse, you know, if, if, um, and this data security investigation, which is the scenario here, takes them to a certain part of the graph that is not shown here, yes, they can traverse it. Uh, and that'll scale to that. But hopefully I answered your, your question specifically.
You did. And is that, is that based off of real time or periodically off of ingested data? Yeah, Abian, do you wanna talk about the refresh frequency?
Yeah, I think, I think a great question is from you. So it's both, right? So the way it's being built is you get all the data into the lakes, you have all the assets, assets include everything from M 365, Azure, Intune, and Defender, or a very soon any third party source as well.
And then, so we are, we are computing the base asset graph on a periodic basis. Then we are ordering activities on top of that. So activities of course are real time as an incident happens, an event happens, and then we do delta changes on a periodic basis as new assets or users or devices get added or changed in an environment.
So it's both a periodic refresh and then an overlay of real time events on top of the graph. Awesome. Thank you.
Awesome. This is Marian. So, uh, on the graph, since it moves from, uh, defender into Sentinel, how do you, uh, validate the accuracy of those AI kind of derived relationships?
So can a SOC team actually audit, uh, a link or an action to see where it was made in that relationship? Uh, yes, ma. And so we have essentially, uh, like for each of the nodes and edges, uh, we describe what the property of those nodes and edges are, which are used to essentially create that association and all the raw logs that are used as kind of with the insured in the layer cake architecture earlier, all the raw logs, the raw events in the asset store.
And the activity store is always available. So the customer can go and look at, you know, what was the actual event that happened. Uh, and then, uh, very soon we'll let the customers create their own custom gap because it's possible that, hey, we could have not detected an, uh, a relationship between say, you know, uh, Gideon's device and Scott's device.
But if the customer has prior context about their environment, they understand their business context better, they will be able to enrich and add their own relationships in the graph as well. They'll be able to make those custom relationships custom Relationships. Yes.
Thank you. Yes. So we started now with, as said, these new experiences in defender exposure management purview, uh, last week, and then very, very soon Maryanne Will, will, uh, talk about custom graphs and the ability of customers and partners to do that.
Absolutely. Ooh, nevermind. I, I was thinking about, um, sorry about this.
I was thinking about the ability to limit, uh, what someone has access to view in terms of a relationship, almost role-based. And I believe that should be possible. Yep.
Yep. Okay. All right.
So we wanna cover this, and I also wanna be cognizant, uh, and keep us on track as far as, uh, time. But as we mentioned earlier in the session, uh, last week, we also announced and, and reached public preview where with our MCP server for Sentinel, um, again, this is the ability to have this protocol for agents to automatically understand, you know, what data and tools they have, uh, available to them to complete a certain task or job to be done. Um, and enable agents, but also users within different experiences to use natural language and access the data better, understand the data, better understand, you know, which tables are available to them for a specific scenario.
And it could be in security operations with the vendor identity and access measurement and etra, uh, and so forth. And it also enables us to kind of allow customers to build, for example, agents in kind of low-code, no-code scenarios like they can now do in security copilot, but they can also do it in vs code and other environments as well. So part of this is also back to the question about this being an open platform and us enabling customers to do this in different environments where they're used to do it.
They can, from their preferred developer environment, they can essentially add the Sentinel MCP server, uh, as, as a protocol and an accent point. And that's how their agents, for example, will, will be able to utilize all the capabilities and the data, uh, that is available to them in the data lake in a much more natural, simple, uh, way. And, and Abha will walk you through a demo of this um, as well.
So, uh, and maybe this is a good slide to kind of, um, end this part of the session today. Um, if we step back a little bit and, um, you know, we can maybe spend more time in a this, in, in the future to kinda walk through the security store in more detail, but it's available online. You can find it easily through search and access it.
Essentially the stack and how we're making it kind of designed for AI scenarios and agent scenarios is we have the Sentinel platform capabilities that we kind of covered today at the high level. We have security copilot, uh, integrated, embedded within it and within our first party, uh, products, as you already know. And then all those solutions, you know, from Microsoft and from our ecosystem can be published in the security store where customers, again can, can discover, purchase, configure, uh, and deploy those either solutions or, um, or agents.
So kind of this is the security stack for the ai, uh, era and some of the partners we showed you, uh, earlier. And of course, some of our customers have already built solutions, uh, based on this, on this stack. And, and Abha could walk you through some, some related demos, if that makes sense.
So maybe, uh, Tom, uh, I'm looking at the time here. Maybe it's good to see if there are any kind of last questions and then we'll transition, uh, this to the next speaker. Yeah, I think we've got time for maybe one or two more questions.
So delegates now's the time. So you, uh, this is really, uh, uh, I, I love the idea of the security store and the AI stack more broadly. Can you comment on how you are discussing things with customers who are having a deeper conversation with Microsoft around the Azure AI Foundry, for example, right?
How are you, uh, uh, are, are, how are you part of those conversations? What are you looking to get from additional Microsoft telemetry into the Sentinel ecosystem? Right?
So it, it's, it's a two part question, right? One is on the technical side of the data, like how are you working with the rest of the, the Microsoft data, but the other is what has been your experience in terms of getting Sentel aligned to those broader AI projects, if that makes sense? Yes.
Uh, Abhi, do you wanna take the technical aspect that Fernando touched on? Yeah, I think, uh, we showed per in the, in the, um, market slide that Gideon showed you, Gideon showed you purview. And so purview is our offering that provides capabilities, uh, along with, you know, some for different activities for security for ai.
So for example, if you are building agents on copilot studio or M Square copilot or AI Foundry, being able to collect their logs, audit their logs, you know, uh, put it put guard base and enforcement on that is enabled by purview and the logs for that will be available in Sentinel, uh, for you to be able to do, you know, further logging compliance requirements or other analysis that's on the, on the technical side of the house. Um, probably didn't quite understand the, the ecosystem question, but I'll let Scott Gideon take a stab at that. Yeah, I mean, I'm not sure I paused it perfectly, but the, obviously Foundry is a, a great place for models and base AI and there's more to come there in terms of how we work with Foundry, um, in scenario use cases.
There's, you know, AI for security and security for AI are the two pivots that I have. Um, obviously there's AI that's used in Azure for many, many things. Um, and then there's specialization of that AI in security.
Um, and so this is all about specialization of that AI for the security use case specifically. Um, now you can use any number of ais on top of our MCP server. You can pick any AI you want.
We are not restricted to security copilot. You can certainly use security copilot, but you can use any AI you want, um, to interact with our MCP server. And you can open up Visual Studio and, and rock on, on, on low code, no code, or you can use whatever your favorite tool is, whatever your favorite AI is to, to piece them all together, if that answers your question.
So we're very open at that level.