Reader small image

You're reading from  Mastering Microsoft 365 Defender

Product typeBook
Published inJul 2023
PublisherPackt
ISBN-139781803241708
Edition1st Edition
Right arrow
Authors (2):
Ru Campbell
Ru Campbell
author image
Ru Campbell

Ruairidh (Ru) Campbell is a Microsoft Security MVP and leads Microsoft consultancy at Threatscape. At Threatscape, Ru develops, delivers, and manages offerings and professional services for cybersecurity, compliance, identity, and management. In the cybersecurity community, Ru runs the Microsoft 365 Security & Compliance user group and his blog (campbell.scot), regularly speaks at other user groups and conferences, and contributes to well-known industry publications such as Practical 365. Ru holds 14 Microsoft certifications and a B.Sc. (Distinction) in computer networking from the University of the West of Scotland. Away from cybersecurity, he is a petrolhead who enjoys heavy metal and hiking around Scotland with his wife.
Read more about Ru Campbell

Viktor Hedberg
Viktor Hedberg
author image
Viktor Hedberg

Viktor Hedberg is a Microsoft Security MVP and senior consultant at Truesec. At Truesec, Viktor works with proactive security measures within the Microsoft sphere of technologies, by delivering workshops on best practices and by his deep technical expertise in these areas. In the cybersecurity community, Viktor runs his blogs at Truesec (Experts – viktor-hedberg). Alongside this, he is one of the hosts of the Swedish Windows Security user group, as well as a co-host of the Swedish podcast The Nerd Herd. He is a frequent speaker at both conferences and user groups around the world, focusing on matters of Microsoft Security. Viktor holds numerous Microsoft certifications, as well as being a Microsoft Certified Trainer. Away from cybersecurity, Viktor is a family man, spending most of his time with his wife and three kids, as well as enjoying football, both as a practitioner and as a fan. Heavy metal has been part of his life since his early teens.
Read more about Viktor Hedberg

View More author details
Right arrow

Microsoft Sentinel Integration

Microsoft Sentinel, previously called Azure Sentinel, is a cloud-based security information and event management (SIEM) and security orchestration automated response (SOAR) platform offered by Microsoft and managed as an Azure resource. You can think of Sentinel as an additional layer for a mature security operations center (SOC), where Microsoft 365 Defender telemetry, alerts, and incidents are combined with those from other services, such as other Microsoft data sources or third-party applications and appliances.

As Sentinel’s use grows, it’s important to learn about how it relates to and its integrations with Microsoft 365 Defender. So, in this chapter, you’ll learn about the following:

  • The relationship and differences between Sentinel and Microsoft 365 Defender
  • The different types of integrations available and enabling them

Let’s kick things off by reviewing how the two services differ and integrate...

Understanding Microsoft 365 Defender’s relationship with Sentinel

As explained in the introduction to this chapter, Sentinel allows for security response and incident management to many different services. This is achieved using data connectors.

Included in the Microsoft 365 Defender connector are the main services of MDE, MDI, MDO, and MDA. You’ll also find services not strictly under the Microsoft 365 Defender banner but that produce alerts there, such as Azure AD Identity Protection and Microsoft Purview DLP.

If you’re a Sentinel customer, enabling these integrations means you can stick with Sentinel as the go-to interface for alert and incident response, rather than having to jump between it and Microsoft 365 Defender’s queue. This improves your time to respond, as well as the benefits of a broader picture thanks to connectors. It also provides a means to improve your retention beyond Microsoft 365 Defender’s limit of 30 days for advanced...

Connecting Microsoft 365 Defender to Sentinel

To establish the connection between Microsoft 365 Defender and Sentinel, you need to complete some actions in Sentinel, which you can do in the Azure portal. You should be a Global or Security Administrator to complete these processes.

There are three types of integrations you can configure:

  • Incidents and alerts
  • Advanced hunting events
  • User and Entity Behavior Analytics (UEBA), based on MDI

Of these, incidents and alerts do not have an additional cost. These are the SecurityIncident and SecurityAlert data types, respectively. Advanced hunting and UEBA have a cost based on the amount of data and analysis, the details of which you should review independently, including using the pricing information provided in the Further reading section in this chapter.

We’ll begin the discussion on how to connect Microsoft 365 Defender to Sentinel with incidents and alerts.

Using incidents and alerts

In this section...

Summary

In this chapter, you learned that Microsoft Sentinel is a SIEM and SOAR solution that improves the single-pane-of-glass desire of SOC teams. Where Microsoft 365 Defender goes deep for the services it is scoped to (MDE, MDO, MDI, MDA, and MDVM), Sentinel goes broad.

If your team already uses Sentinel, you now know the advantages of creating the sync between it and Microsoft 365 Defender, as well as how that sync operates, with bi-directional integration for improved response times and incident management. We covered the steps for creating the three types of integration (incidents/alerts, advanced hunting data, and UEBA) so that you can maximize your investment in the platform.

Sentinel’s SOAR capabilities offer a means to automate security incident response. In the next chapter, we’ll look at the APIs that allow programmatic access to Microsoft 365 Defender for additional automation and integration capabilities.

Questions

To test your understanding of integrating Microsoft 365 Defender with Microsoft Sentinel, take a shot at the following questions:

  1. A serious incident in your Microsoft 365 Defender portal is made up of 140 alerts. How would you expect Microsoft Sentinel to respond to this? Choose one.
    1. Sentinel will split the incident into two incidents
    2. Sentinel will have one incident with all alerts
    3. Sentinel will redirect you to Microsoft 365 Defender to see all the alerts
    4. Sentinel will hide alerts with a lower priority
  2. Which of the following components would not fall into scope for Microsoft 365 Defender’s connector to Sentinel? Choose all that apply.
    1. Azure Active Directory Identity Protection
    2. Microsoft Defender Vulnerability Management
    3. Microsoft Purview Data Loss Prevention
    4. Microsoft Defender for SQL
  3. You are using Microsoft Sentinel to create queries for your SOC team. Which of the following tables would be most appropriate to find out the severity of an alert as determined...

Further reading

There is a lot more to learn about general Microsoft Sentinel usage than we can cram into this book. Check out the following links for useful resources:

  • Rod Trent of Microsoft has championed KQL more than anyone. You can find his Must Learn KQL repository on GitHub, including purchase options for a hard copy book of the same name, to help you master KQL: github.com/rod-trent/MustLearnKQL.
  • Another must-visit GitHub repository is Matt Zorich’s, which is home to a massive list of his custom queries and the #365daysofKQL series: github.com/reprise99/Sentinel-Queries.
  • Want to join a community and learn, share, or practice the Sentinel query language? The KQL Café, run by Gianni Castaldi and Alex Verboon, hosts regular meetups to cover all things Kusto: kqlcafe.github.io/website.
  • For the most comprehensive book on Microsoft Sentinel you’ll find, check out Microsoft Sentinel in Action – Second Edition, from Packt Publishing: packtpub...
lock icon
The rest of the chapter is locked
You have been reading a chapter from
Mastering Microsoft 365 Defender
Published in: Jul 2023Publisher: PacktISBN-13: 9781803241708
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €14.99/month. Cancel anytime

Authors (2)

author image
Ru Campbell

Ruairidh (Ru) Campbell is a Microsoft Security MVP and leads Microsoft consultancy at Threatscape. At Threatscape, Ru develops, delivers, and manages offerings and professional services for cybersecurity, compliance, identity, and management. In the cybersecurity community, Ru runs the Microsoft 365 Security & Compliance user group and his blog (campbell.scot), regularly speaks at other user groups and conferences, and contributes to well-known industry publications such as Practical 365. Ru holds 14 Microsoft certifications and a B.Sc. (Distinction) in computer networking from the University of the West of Scotland. Away from cybersecurity, he is a petrolhead who enjoys heavy metal and hiking around Scotland with his wife.
Read more about Ru Campbell

author image
Viktor Hedberg

Viktor Hedberg is a Microsoft Security MVP and senior consultant at Truesec. At Truesec, Viktor works with proactive security measures within the Microsoft sphere of technologies, by delivering workshops on best practices and by his deep technical expertise in these areas. In the cybersecurity community, Viktor runs his blogs at Truesec (Experts – viktor-hedberg). Alongside this, he is one of the hosts of the Swedish Windows Security user group, as well as a co-host of the Swedish podcast The Nerd Herd. He is a frequent speaker at both conferences and user groups around the world, focusing on matters of Microsoft Security. Viktor holds numerous Microsoft certifications, as well as being a Microsoft Certified Trainer. Away from cybersecurity, Viktor is a family man, spending most of his time with his wife and three kids, as well as enjoying football, both as a practitioner and as a fan. Heavy metal has been part of his life since his early teens.
Read more about Viktor Hedberg