Microsoft Azure Sentinel Cloud-Native Security Analytics Tool, Threat Experts Service Launched to Help Security Teams

Advertisement
By Jagmeet Singh | Updated: 1 March 2019 12:03 IST
Highlights
  • Microsoft Azure Sentinel is touted to reduce alert fatigue
  • It can analyse security data from Microsoft Office 365
  • Microsoft Threat Experts offers a one-click connect with security experts

Microsoft Azure Sentinel visualises security data using AI and supports open standards such as CEF

Microsoft on Thursday launched its cloud-native solution called Azure Sentinel that is touted to provide enterprises with intelligent security analytics at cloud scale. The new development, which comes as an advanced Security Information and Event Management (SIEM) tool, uses artificial intelligence (AI) and scalable machine learning algorithms to analyse and detect threats alongside offering a significant reduction in alert fatigue. The Redmond company also brought Microsoft Threat Experts as a service to provide managed hunting over anonymised security data to enterprises and businesses using Windows Defender Advanced Threat Protection (ATP). The new service is designed to help security teams easily hunt down and restrict human adversary intrusions and advanced attacks such as cyber-espionage.

Among the new enterprise-focused security offerings, Microsoft Azure Sentinel comes as a new SIEM tool to mitigate the risk of cyber attacks using AI. It also integrates data from Microsoft experts and third-party defenders and machine learning tools to provide security insights under one roof. Microsoft claims that early adopters have found that the Azure Sentinel tool "reduces threat hunting from hours to seconds."

A traditional SIEM system is designed to provide enterprises with real-time analysis of security alerts by collecting and aggregating log data from the application and network infrastructure. But since enterprises nowadays largely use cloud alongside their conventional technological deployments, a cloud-native solution like Azure Sentinel has become the need of the hour.

Advertisement

Microsoft says that using Azure at the backend, the new tool provides "limitless cloud scale and speed" to collect and analyse security data. It also supports open standards such as Common Event Format (CEF) and has broad partner connections, including Microsoft Intelligent Security Association partners such as Check Point, Cisco, F5, Fortinet, Palo Alto, and Symantec.

"Azure Sentinel blends the insights of Microsoft experts and AI with the unique insights and skills of your own in-house defenders and machine learning tools to uncover the most sophisticated attacks before they take root," explains Ann Johnson, Microsoft CVP, Cybersecurity Solutions Group, in a blog post.

Advertisement

Azure Sentinel is capable of analysing data from Office 365. This means enterprises can bring their Office 365 activity data to Azure Sentinel to detect security loopholes. Also, the new tool can be integrated with security solutions from various third-party vendors. There is also Microsoft Graph Security API support to let enterprises import their threat intelligence feeds and customise threat detection.

Microsoft claims that machine learning algorithms powering Azure Sentinel make it capable of offering up to 90 percent reduction in alert fatigue during evaluations. Furthermore, the tool provides graphical and AI-based investigation to make it efficient for security teams to understand the full scope of an attack and its impact.

Advertisement

Enterprise customers can get Microsoft Azure Sentinel in preview directly from the Azure portal.

In addition to the Azure Sentinel tool, Microsoft has brought the Threat Experts service that adds a human touch to the company's security offerings. The managed threat hunting service is a part of Windows Defender ATP and is designed to offer proactive hunting, prioritisation, and additional context and insights. It is essentially designed with two capabilities -- targeted attack notifications and security experts on demand.

Advertisement

On the part of security experts on demand, Microsoft Threat Experts lets security operation centres (SOCs) connect with Microsoft's in-house security experts directly from within Windows Defender Security Centre. There is an "Ask a Threat Expert" button to let security teams submit their questions from the product console.

The preview of Microsoft Threat Experts is available for Windows Defender ATP customers directly from the Windows Defender Security Centre. Once applied for the preview, Microsoft will reach eligible customers via email to confirm their participation.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. OnePlus 15R Confirmed to Come With 32-Megapixel Selfie Camera
  1. Kepler and TESS Discoveries Help Astronomers Confirm Over 6,000 Exoplanets Orbiting Other Stars
  2. Supernatural Thriller Jatadhara Arrives on OTT: Where to Watch Sonakashi Sinha-Starrer Film Online?
  3. OnePlus 15R Confirmed to Come With 32-Megapixel Selfie Camera, 4K Video Recording Support
  4. Rocket Lab Clears Final Tests for New 'Hungry Hippo' Fairing on Neutron Rocket
  5. Apple Rolls Out iOS 26.2 Update for iPhone With Liquid Glass Customisation, Changes to Apple Music, and More
  6. Aaromaley Now Streaming on JioHotstar: Everything You Need to Know About This Tamil Romantic-Comedy
  7. Astronomers Observe Star’s Wobbling Orbit, Confirming Einstein’s Frame-Dragging
  8. Galaxy Collisions Found to Activate Supermassive Black Holes, Euclid Data Shows
  9. JWST Detects Oldest Supernova Ever Seen, Linked to GRB 250314A
  10. Chandra’s New X-Ray Mapping Exposes the Invisible Engines Powering Galaxy Clusters
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.