Microsoft Sentinel Setup and Overview Hub¶
Atlanta, USA
Last updated: 2026-07-27
Cloud2BR OSS Learning Hub
Microsoft Sentinel¶
Build a security operations platform for collecting telemetry, detecting threats, investigating incidents, and coordinating response across cloud and hybrid environments.
What is Microsoft Sentinel?
Understand Sentinel's security information and event management (SIEM), security orchestration, automation, and response (SOAR), data, and incident-management boundaries.
FoundationArchitecture and workspace
Design workspace, tenant, network, retention, and access boundaries before ingestion.
DataData connectors
Connect only the signals that support a defined detection or investigation use case.
DetectionAnalytics rules
Create scheduled, near-real-time, and fusion detections with tested entity mappings.
InvestigationHunting and Kusto Query Language (KQL)
Turn hypotheses into reliable queries, notebooks, and custom detection content.
DeploymentDeployment checklist
Track evidence-backed readiness from pilot design through operating handoff.
Choose the first guide¶
| Need | Start with |
|---|---|
| Design an environment and workspace model | Architecture and workspace |
| Establish least-privilege operational access | Roles and role-based access control (RBAC) |
| Onboard Microsoft or third-party telemetry | Data connectors |
| Create or tune detections | Analytics rules |
| Build responder playbooks | Automation and playbooks |
| Plan costs, retention, and archival | Data lifecycle and cost |
Use the Hub¶
Start with architecture and roles, then onboard a small data set for a defined use case. Validate connector health, data quality, analytics, entities, incident routing, and automation with a controlled test before increasing scope. Each guide identifies boundaries, evidence, and operational ownership to make the rollout repeatable.
These guides are learning material. Confirm current support, pricing, and service behavior in Microsoft's official documentation before production use.