Skip to content
← Back to the guide

Microsoft Sentinel for Microsoft 365

4slides. Screenshot a slide, download it as a PNG, or use your browser's Print → Save as PDF for a LinkedIn-ready multi-page carousel — each slide becomes one page.

M
solvingmicrosoft365.com
1 / 4

Microsoft Sentinel for Microsoft 365

How Microsoft Sentinel ingests Microsoft 365 signals and extends Defender XDR into a full SIEM.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/microsoft-sentinel-for-microsoft-365

Slide 1Download PNG
M
solvingmicrosoft365.com
2 / 4
01

Is Microsoft Sentinel free for Microsoft 365 data?

Ingestion of some Microsoft 365 data — Office 365 audit (Exchange, SharePoint, Teams) via the Microsoft 365 connector, and Defender XDR alerts — is free; Entra sign-in and audit logs, Defender raw event tables, and ever…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/microsoft-sentinel-for-microsoft-365

Slide 2Download PNG
M
solvingmicrosoft365.com
3 / 4
02

Do I need Sentinel if I have Defender XDR?

Defender XDR correlates Microsoft signals and is enough for many organisations. Sentinel adds long-term retention, non-Microsoft data sources (firewalls, cloud providers, SaaS), custom analytics, SOAR playbooks, and a S…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/microsoft-sentinel-for-microsoft-365

Slide 3Download PNG
M
solvingmicrosoft365.com
4 / 4
03

What is the first thing to connect to Sentinel?

The Defender XDR connector (incidents and, if you want them, raw tables), the Entra ID connector (sign-in and audit logs), and the Microsoft 365 connector — then enable the analytics rules and workbooks that come with t…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/microsoft-sentinel-for-microsoft-365

Slide 4Download PNG

Auto-generated from Microsoft Sentinel for Microsoft 365. This page is not indexed and isn't part of the guide itself.