Back

What is Azure Sentinel?

Going to the cloud doesnt mean freedom from security issues Cloud services are targets just as much as onpremises systems As they grow in populari...

6 min read
Published on Apr 15, 2019
azure-sentinel

Going to the cloud doesn’t mean freedom from security issues. Cloud services are targets just as much as on-premises systems. As they grow in popularity, dishonest people see opportunities to steal information and resources from complacent users. Organizations that rely on cloud services need security measures for them.

A large business typically has many services to keep track of, any of which could be exposed to threats. It needs a way to identify issues throughout its infrastructure. The protective systems need to catch all serious problems, but they have to be smart enough not to flood administrators with false alarms. Azure Sentinel, a new service currently in preview, is a SIEM which provides integrated security management enhanced by artificial intelligence.

An Azure-Native SIEM

What is a SIEM? The term stands for Security Information and Event Management. It’s the name for software that provides a unified overview of security status in an infrastructure. Information comes from many sources, primarily system logs, and is organized into views that cover everything. Indeed, the functionality includes event collection, reporting of issues, and mapping of diverse information sources to consistent terminology.

Azure Sentinel is a SIEM which is native to Azure. Microsoft announced the preview release at the end of February 2019. It’s available to anyone with an Azure account. Other cloud SIEM tools exist, but this one comes from the people who know Azure best. The Microsoft SIEM integrates with many Azure services. Pricing is similar to other Azure services; there’s no up-front cost, and the amount billed for it depends on usage.

Use of Sentinel is free during the preview period, but there could be charges for services it invokes, such as playbooks.

Sentinel isn’t limited to monitoring the Azure cloud. It can collect log information from any source, including other clouds and on-premises systems. Thus, this allows full coverage of hybrid and multi-cloud infrastructures.

As of this writing, Azure Sentinel is in the preview, and it’s not recommended for production environments. Indeed, no SLA is available. This is a time for trying it out and getting experience with it, to be ready for the official release.

The Dashboard

From the administrator’s viewpoint, the epicenter of Sentinel is the dashboard. It provides many ways of looking at the security situation. The toolbar gives information about the number of events and alerts over a time period, as well as the number of new, investigated, and closed events.

Below the toolbar, a number of views are available. The administrator can get a geospatial view of potentially malicious incidents on a world map. Indeed, built-in dashboards include Azure AD logs, firewall information, insecure protocols, Azure activity, and much more.

Creation of custom dashboards is straightforward, and their creators can share them using role-based authorization. Thus, people with different roles in IT may have access to all dashboards or just the ones relevant to their jobs.

Software Integration

Sentinel is built on Azure Log Analytics. It collects information from various security logs and turns the information into a manageable form. The strongest initial emphasis is on Microsoft 365.

The services Sentinel collects information from or soon will be able to, include Azure Identity Protection, Microsoft Cloud App Security, Advanced Threat Protection, and Azure Information Protection. Integration with some third-party tools, such as Cisco ASA and various firewalls, is already available, and more will come.

Adding custom connectors isn’t too hard. Azure can deal with any input in Syslog format or Common Event Format. Its REST API makes it convenient to connect other data sources.

Correlating Events With Machine Learning

Sentinel makes information more manageable with machine learning, including built-in ML and an optional module called Fusion. Third parties can add “build-your-own” ML. They recognize patterns which are especially suspicious, such as logging in from an unusual IP address followed by a massive file download.

Using these features, Sentinel takes its large volume of incoming information and correlates it into cases. A “case” is a group of related alerts that all point to the same problem. Thus, presenting information as cases reduces “alert fatigue”, where administrators receive many redundant alerts.

Automation and Orchestration

A warning of a problem is useful only if it gets a prompt and effective response. Sentinel supports automated threat responses in the form of “playbooks”. Playbooks, built on Azure Logic Apps, set up a series of procedures to run when the situation warrants it. Administrators can run playbooks manually or set up triggering events to launch them. A playbook can take actions such as opening a ticket, sending an SMS or email alert, or disabling an account. Pre-defined playbooks are available for common situations. Administrators can create their own using the Logic App tools.

Deep Investigation

An exciting feature of Sentinel is the ability to do “hunting” and deep investigations of issues.The process starts from the Cases page on the dashboard. Cases can be filtered by criteria such as status and severity. The page for a single case gives information about the alerts it’s built out of. It shows triggered alerts reasonings. Thus, the administrator looking at it can assign the case to someone or click the “Investigate” button to get more information. It’s also possible to run a playbook to initiate a standardized procedure for processing the case.

The investigation page shows the information as a graph. The nodes on the graph identify entities, such as incidents, computers, and users. The admin can click on any entity to get more information about it and see connections to related entities.

The hunting capability consists of a search and query tool that goes through the data sources. It uses the Azure Log Analytics query language. A large number of predefined queries are provided. As a few examples, they can look for attempted access to disabled accounts, modifications of privilege groups, failed logins, anomalous DNS requests, and so on.

Next Steps

By Microsoft’s own statement, Sentinel isn’t ready for production environments yet. However, it provides additional motivation to adopt or increase use of Azure Log Analytics. Sentinel builds on that service, so organizations that use it will be in a good position to add its higher-level features when they’re available. Learning about the features and trying them out in a test infrastructure will let administrators be ready when Sentinel is available for heavy-duty use.

Agile IT can provide onboarding or full management of your security environment. Learn more about Agile Security or request a quote:

This post has matured and its content may no longer be relevant beyond historical reference. To see the most current information on a given topic, click on the associated category or tag.

Related Posts

Understanding DFARS Compliance

DFARS Compliance: A Guide to Federal Cybersecurity Requirements

Learn about DFARS compliance and how it ensures the security of federal data. Explore key requirements, NIST 800-171 alignment, and tips for achieving compliance.

Feb 3, 2025
7 min read
Office 365 License Comparison: Business Plans Vs. E5, E3 and E1

Master Microsoft & CIS Benchmark Best Practices to Secure Your Environment

Discover how to implement Microsoft & CIS Benchmark best practices to strengthen your business security and protect your environment from evolving threats with expert guidance.

Jan 28, 2025
7 min read
Screen Capture Protection in Windows 365

How to Enable Screen Capture Protection in Windows 365 for Enhanced Security

Learn how to enable and use screen capture protection in Windows 365 to secure sensitive information and prevent unauthorized captures, enhancing your organization's data security.

Jan 21, 2025
7 min read
Office 365 Collaboration Tools

Office 365 Collaboration Tools: Are They Right for Your Organization?

Explore how Office 365's collaboration tools can enhance your organization's productivity and security.

Jan 12, 2025
6 min read
NIST 800 171 vs NIST 800 53

NSA Cybersecurity Collaboration: No-Cost Services Available to DoD Contractors

Learn how NSA cybersecurity collaboration provides no-cost services to DoD contractors, helping enhance security and compliance with advanced cyber protections.

Jan 10, 2025
6 min read
When is a New CMMC Assessment Needed

Understanding When and Why You Need a New CMMC Assessment

Learn when to schedule a new CMMC assessment, what triggers reassessments, and how changes in scope, contracts, or compliance impact your certification process.

Jan 6, 2025
9 min read

Ready to Secure and Defend Your Data
So Your Business Can Thrive?

Fill out the form to see how we can protect your data and help your business grow.

Loading...
Secure. Defend. Thrive.

Let's start a conversation

Discover more about Agile IT's range of services by reaching out.

Don't want to wait for us to get back to you?

Schedule a Free Consultation

Location

Agile IT Headquarters
4660 La Jolla Village Drive #100
San Diego, CA 92122

Secure. Defend. Thrive.

Don't want to wait for us to get back to you?

Discover more about Agile IT's range of services by reaching out

Schedule a Free Consultation