AzureTracks

Practical Azure and Microsoft 365 security walkthroughs

Microsoft Sentinel

  • Saturday Heat – Bonus Walkthrough!

    Saturday Heat – Bonus Walkthrough!

    There is too much heat this week for me. I took the opportunity to try & find some distraction for you too! In this Saturday bonus article, we will build several practical security queries progressively. We will begin by reviewing raw Microsoft Entra sign-in data, add filters, summarize the results, extract values from dynamic fields,…

    Read article

  • Microsoft Sentinel Baseline Deployment: From Zero to Operational SOC – Summer Bonus!

    Microsoft Sentinel Baseline Deployment: From Zero to Operational SOC – Summer Bonus!

    Microsoft Sentinel is powerful—but it can’t manage itself. Manual operations like onboarding data connectors, validating ingestion, monitoring workspace health, and auditing configuration changes quickly become a burden. This bonus article walks through building automation around your Sentinel foundations, so you can: Keep your workspaces healthy Ensure configuration compliance Alert on critical changes Free SOC engineers…

    Read article

  • Microsoft Sentinel Baseline Deployment: From Zero to Operational SOC – Part 3 of 3

    Microsoft Sentinel Baseline Deployment: From Zero to Operational SOC – Part 3 of 3

    Sentinel does not fail because it lacks detections. It fails because alerts overwhelm analysts, automation hides context, and governance is treated as an afterthought. In this series-finale post, we establish a production operational baseline: analytics rules, incident handling, automation boundaries, and long-term governance. This is where Sentinel becomes usable—not just enabled. There is no secret…

    Read article

  • Microsoft Sentinel Baseline Deployment: From Zero to Operational SOC

    Microsoft Sentinel Baseline Deployment: From Zero to Operational SOC

    SIEM best practices are clear: connect data intentionally. In this post, we build a baseline ingestion strategy that prioritizes high-value telemetry, aligns with Zero Trust, and avoids the “enable everything” trap.

    Read article

  • Microsoft Sentinel Baseline Deployment: From Zero to Operational SOC

    Microsoft Sentinel Baseline Deployment: From Zero to Operational SOC

    Microsoft Sentinel can be enabled in minutes. A good Sentinel deployment takes planning. Most Sentinel pain does not come from missing detections or weak analytics. It comes from architectural shortcuts taken on day one: poorly scoped workspaces, uncontrolled access, unpredictable ingestion costs, and a lack of governance before the first alert ever fires. In this…

    Read article

  • Azure Updates – Number 133 – March 21, 2026

    Azure Updates – Number 133 – March 21, 2026

    A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.

    Read article

  • Azure Updates – Number 129 – January 24, 2026

    Azure Updates – Number 129 – January 24, 2026

    A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.

    Read article

  • Using Microsoft Defender Threat Intelligence in Sentinel for Advanced Threat Detection

    Using Microsoft Defender Threat Intelligence in Sentinel for Advanced Threat Detection

    It’s a special Christmas AzureTracks article this year! Cyber threats don’t take holidays—but your SOC can with the right tools. Discover how Defender Threat Intelligence + Sentinel helps identify emerging and persistent threats with real-time IoCs and AI-powered analytics. Will you find who ate Santa’s cookies and catch the Christmas culprit?

    Read article

  • Azure Updates – Number 128 – December 13, 2025

    Azure Updates – Number 128 – December 13, 2025

    A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.

    Read article

  • Future-Ready SOCs: Microsoft Sentinel Data Lake Powers AI-Driven Security

    Future-Ready SOCs: Microsoft Sentinel Data Lake Powers AI-Driven Security

    As 2025 wraps up, Microsoft Sentinel takes center stage with a major innovation announced at Ignite: Sentinel Data Lake. This feature is designed to unify security signals, reduce SIEM costs, and enable AI-powered threat detection at scale. In this article, we’ll explore what Sentinel Data Lake means for SOC operations, why it matters, and how…

    Read article