What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft Sentinel is a cloud-native security information and event management (SIEM) service for collecting security data and supporting threat detection, investigation, hunting, and response across multicloud and multiplatform environments. It can provide data and SIEM context to Microsoft Security Copilot, which adds generative-AI assistance to supported workflows. Copilot is a separate Microsoft security product integrated with Sentinel—not an automatic capability included with every Sentinel deployment.

What Microsoft Sentinel does

Microsoft describes Sentinel as “a cloud-native SIEM solution that delivers scalable, cost-efficient security across multicloud and multiplatform environments.” Microsoft’s Sentinel overview describes a service for security data collection and operations, including threat detection, investigation, proactive hunting, and response.

Sentinel can collect data from Microsoft services and third-party sources. Organizations can use out-of-the-box connectors or custom integration routes, then apply security content and automation to work with the collected data. Microsoft’s overview lists 350+ out-of-the-box connectors; the page does not date that figure, so treat it as a claim on the current overview rather than a year-specific count. See Microsoft’s Sentinel overview and platform description.

SIEM capabilities and broader platform direction

Sentinel’s core SIEM role is to bring security signals together for detection, investigation, hunting, and response. Microsoft’s current product direction also presents Sentinel as extending beyond traditional SIEM with a data lake, graph capabilities, an MCP server, and developer tooling. These broader platform capabilities sit alongside—not in place of—the core SIEM functions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How Security Copilot works with Sentinel

Sentinel supplies security telemetry and SIEM context; Microsoft Security Copilot provides natural-language assistance for supported security workflows. Microsoft’s integration documentation describes using Sentinel data to analyze incidents and generate hunting queries. Generated queries and recommendations are assistance, not verified findings: analysts should review outputs and validate them against the underlying data before acting. Microsoft’s Security Copilot with Sentinel documentation describes the integration.

Copilot is integrated, not automatically included

Sentinel and Security Copilot are distinct products. The fact that Copilot can work with Sentinel data does not mean every Sentinel customer automatically has Copilot access or that every Copilot feature is available in every Sentinel experience. Availability, licensing, and feature status can vary; check Microsoft’s current product and licensing documentation for the intended deployment.

Standalone and Defender portal experiences

Microsoft documents Sentinel data use with Security Copilot in both standalone and Microsoft Defender portal experiences. In the documented standalone experience, the Microsoft Sentinel and Natural language to KQL for Microsoft Sentinel plugins are identified as preview features. Preview status can change, so confirm the current status before relying on those plugins for production workflows.

Setup guidance includes configuring a default Sentinel workspace and connecting that workspace to Microsoft Defender XDR to maximize integration. These steps are prerequisites described for the documented integration, not a claim that every Copilot scenario requires an identical configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sentinel solutions and extensibility

Organizations and partners can extend Sentinel through solution content. Microsoft distinguishes SIEM solutions, focused on detection, investigation, and automated response, from platform solutions designed for larger-scale analysis and AI-driven scenarios. Microsoft’s solution overview describes these solution types and their components.

Solution type Primary focus Examples of components
SIEM solution Detection, investigation, and automated response Connectors, analytics rules, hunting queries, parsers, workbooks, and playbooks
Platform solution Larger-scale analysis and AI-driven scenarios Copilot agents, MCP tools, custom graphs, and notebook jobs

These categories provide a practical way to evaluate an extension: determine whether the need is SIEM content for security operations or platform components for data and AI-oriented work. Data integration can also be native through a supplied connector or handled through a custom route, depending on the source and requirements.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What affects Sentinel cost

Sentinel’s published billing options include pay-as-you-go pricing based on data volume and commitment tiers. Microsoft’s billing documentation says commitment-tier pricing starts at 100 GB per day. This is a threshold for the tier structure, not a universal Sentinel price or a recommendation for a particular deployment. Check Microsoft’s billing documentation for the applicable region and current rates.

Total spend depends on data volume, selected pricing tiers, retention, and infrastructure. Analytics-tier retention beyond 90 days can add charges. Estimate costs from the data sources and retention period the organization actually needs, and check regional pricing before choosing pay-as-you-go or a commitment tier; there is no single price that applies to every Sentinel deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the Azure portal transition means

Microsoft states that after March 31, 2027, Sentinel will no longer be supported in the Azure portal and will be available only in the Microsoft Defender portal. Organizations currently operating Sentinel in Azure portal should plan for the portal transition and check Microsoft’s current migration guidance for updated dates and requirements. Microsoft’s Sentinel billing and portal guidance includes this transition information.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.