What is Microsoft Sentinel?
Microsoft Sentinel (formerly known as Azure Sentinel) is Microsoft's cloud-native SIEM solution. Sentinel collects logs and security events from your entire IT environment: Microsoft 365, Azure, servers, firewalls, VPN and third-party systems. The platform then analyses it all together and raises the alarm when patterns look like an attack. Because Sentinel runs as a service in Azure, even smaller Danish businesses can get the kind of monitoring that used to require your own data centre and a large security team. The product is documented on Microsoft Learn.
What is a SIEM system?
SIEM stands for Security Information and Event Management. The core idea: all of your systems produce logs: who signed in, which file was opened, which connection was established. Each log is harmless on its own, but a SIEM gathers them in one place and correlates them: a sign-in from a foreign country, followed by a new mail rule and a large download, is together a clear warning sign that none of the systems would catch alone. Without a SIEM, that kind of thing is typically only discovered after the damage is done. The Danish Centre for Cyber Security highlights logging and detection as key defensive layers; see cfcs.dk.
Sentinel vs. traditional SIEM
A traditional SIEM is installed on your own servers: you have to size the hardware, upgrade the software and guess at future log volumes before you buy. Sentinel turns the model around. It is cloud-native, requires no infrastructure and is operational in days rather than months. You pay for the data you ingest, no more and no less, and Microsoft continuously delivers built-in rules, threat intelligence and AI-based analysis. For an SMB, this means the barrier to entry is time and skills, not a server room.
What does Microsoft Sentinel cost?
Sentinel is billed on consumption: the price follows the volume of log data you send in and retain, typically measured per gigabyte per day. There are also tiered commitment levels where the unit price drops the more data you commit to. What matters for the budget is therefore not the list price, but which log sources you choose to ingest. A well-designed setup sends the security-relevant logs to Sentinel and leaves noisy, cheap logs in ordinary storage. This is where good advice makes the difference between a sharp tool and a runaway bill.
What is a SOC?
A SOC (Security Operations Center) is the team that monitors the alerts and responds to them, because SIEM is only the tool. Without people who assess, prioritise and act on Sentinel's incidents, even the best setup ends up as an alarm nobody listens to. Smaller businesses typically solve this by letting a partner take on the SOC role. Read more about the threats in our entry on cybersecurity.
How MI Support IT can help
As a certified Microsoft partner, we design and implement Sentinel with the right log sources, often with Microsoft Defender as the first data source, and help with the ongoing monitoring. Read more about IT security and Microsoft Azure, or contact us for an assessment of your needs.