4.3. Capabilities of Microsoft Sentinel
💡 First Principle: As an environment grows, security signals pour in from dozens of separate systems — firewalls, identity logs, endpoint alerts, cloud posture findings — and no human can manually correlate all of them fast enough, so Microsoft Sentinel exists as a cloud-native platform that collects all of that data centrally, correlates it into meaningful incidents, and can automatically trigger a response.
Why care: an attack rarely shows up as one single, obvious alert — it's usually a pattern spread across multiple systems (an unusual sign-in here, a suspicious process there) that only becomes obvious when correlated together. Sentinel exists specifically to do that correlation at a scale and speed no manual process can match.
⚠️ Common Misconception: Thinking Sentinel is "just" a log search tool. The two subsections below unpack why it's both a SIEM and a SOAR platform in one.