{"id":1089,"date":"2023-12-12T17:45:42","date_gmt":"2023-12-12T16:45:42","guid":{"rendered":"https:\/\/www.graber.cloud\/?p=1089"},"modified":"2023-12-12T17:45:48","modified_gmt":"2023-12-12T16:45:48","slug":"microsoft-sentinel-for-microsoft-365-a-must-have","status":"publish","type":"post","link":"https:\/\/www.graber.cloud\/en\/microsoft-sentinel-for-microsoft-365-a-must-have\/","title":{"rendered":"Microsoft Sentinel for Microsoft 365 &#8211; a must have!"},"content":{"rendered":"<p>Microsoft Sentinel is a cloud-native SIEM and SOAR solution. Microsoft 365 offers integrated security functions for Azure Active Directory (Entra), Microsoft Defender for Office 365, Microsoft Defender for Endpoint and Microsoft Cloud App Security. However, these features do not cover all possible attack vectors and vulnerabilities that hackers could exploit. In this blog post, I explore how Microsoft Sentinel extends the capabilities of Microsoft Defender XDR (and other Defender products).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Microsoft Defender XDR<\/h2>\n\n\n\n<p class=\"has-contrast-3-background-color has-background\">Note: Microsoft 365 Defender was rebranded at Microsoft Ignite 2023 and is now called Microsoft Defender XDR.<\/p>\n\n\n\n<p>Microsoft 365 Defender provides comprehensive protection against a wide range of attack vectors such as phishing, malware, ransomware, identity theft and data breaches. It uses artificial intelligence and machine learning to analyze vast amounts of signals in Microsoft services and third-party sources and automatically block or remove threats where possible. While Microsoft 365 Defender is a very valuable and powerful tool, the solution does not completely cover all possible attack vectors and vulnerabilities, as already described in the introduction. There is also potential for improvement in terms of efficient incident handling, automatic response and hunting. This is where Microsoft Sentinel comes into play.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Microsoft Sentinel<\/h2>\n\n\n\n<p>The SIEM solution \"Microsoft Sentinel\" collects data from various sources and analyzes it. The data comes from deployed Azure services, local systems and other cloud providers as well as Microsoft 365 Defender. Sentinel enables organizations to gain a holistic overview of the security landscape, identify anomalies and suspicious activities and conduct investigations with KQL-Queris. These functionalities help to automate the response to incidents using playbooks (logic apps) and to create user-defined alerts and appropriate dashboards (workbooks).<\/p>\n\n\n\n<p class=\"translation-block\">But now back to the actual topic. What is the effective benefit of linking my Microsoft 365 Defender with Microsoft Sentinel? As already mentioned several times, the functions of Microsoft 365 Defender do not cover all possible attack vectors and vulnerabilities. For example, lateral movement, cross-domain attacks or advanced persistent threats may not be detected.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Sentinel vs Defender<\/h2>\n\n\n\n<p>The following table provides a rough overview and a better understanding of how the functions of the two products differ.<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table><thead><tr><th>Capability<\/th><th>Microsoft 365 Defender<\/th><th>Microsoft Sentinel<\/th><\/tr><\/thead><tbody><tr><td><strong>Data sources<\/strong><\/td><td>Microsoft 365 data mainly &nbsp;<\/td><td>Microsoft 365 data and other cloud and on-premises data (any)<\/td><\/tr><tr><td><strong>Analytics rules<\/strong><\/td><td>Predefined rules only<\/td><td>Predefined rules, user-defined rules, and community rules (GitHub)<\/td><\/tr><tr><td><strong>Investigation<\/strong><\/td><td>Graphical interface and advanced hunting queries<\/td><td>Graphical interface and advanced hunting queries<\/td><\/tr><tr><td><strong>Response<\/strong><\/td><td>Predefined actions and automation &nbsp;<\/td><td>Predefined playbooks, user-defined playbooks and integration with other tools<\/td><\/tr><tr><td><strong>M365 Log Retention<\/strong><\/td><td class=\"translation-block\">7 - 180 days, max 30 days active (<a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/security\/office-365-security\/mdo-data-retention?view=o365-worldwide&amp;WT.mc_id=AZ-MVP-5004129\" target=\"_self\">depending on plan &amp; type<\/a>)<\/td><td>Active for 90 days (free of charge), up to 2 years. Additional 10 years of archiving possible.<\/td><\/tr><tr><td><strong>Integration<\/strong><\/td><td>Mainly integrated with other Microsoft security solutions<\/td><td>Integrates with other Microsoft security solutions and third-party solutions.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>As can be seen from the table, Microsoft Sentinel offers more flexibility and functionality than the Microsoft 365 Defender standalone solution. This is the reason why Microsoft 365 Defender should be supplemented with Sentinel. The integration of Microsoft 365 Defender into Microsoft Sentinel offers the following advantages:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Improved transparency:<\/strong> Microsoft Sentinel can ingest data from Microsoft 365 Defender and correlate it with other sources to create a comprehensive picture of the threat environment. Organizations can also use Microsoft Sentinel to monitor the health and performance of their Microsoft 365 Defender components such as devices, users, mailboxes and applications.<\/li>\n\n\n\n<li><strong>Faster response:<\/strong> Microsoft Sentinel can trigger actions in Microsoft 365 Defender based on predefined or user-defined rules, such as isolating a compromised device, blocking a malicious email or resetting a user password. Organizations can also use Microsoft Sentinel to orchestrate complex response scenarios involving multiple teams and systems.<\/li>\n\n\n\n<li><strong>Less complexity:<\/strong> Microsoft Sentinel can simplify management by displaying all security data and alerts in a single window. Organizations can also leverage Microsoft Sentinel's built-in features such as connectors, workbooks, analytics and incidents to reduce manual configuration and maintenance efforts.<\/li>\n\n\n\n<li class=\"translation-block\">It provides ready-to-use templates for analysis rules that help <strong>detect suspicious activity and anomalies<\/strong> in the Microsoft 365 environment, such as account compromise, data exfiltration, phishing campaigns, ransomware attacks and more. You can also create your own user-defined rules or import rules from the community.<\/li>\n\n\n\n<li><strong>Investigate incidents via a graphical user interface: <\/strong>which display the relationships between entities and events. Advanced search queries can also be used to look for indicators of compromise in data sources. This helps to understand the scope and impact of the attack and to find the root cause and take action.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Additional costs<\/h2>\n\n\n\n<p>Microsoft Sentinel is an Azure solution based on the Log Analytics Workspace resource. Log data that is written to this workspace and therefore to Sentinel incurs additional costs. The costs are calculated from several factors.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Log Ingestion<\/li>\n\n\n\n<li>Log Retention<\/li>\n\n\n\n<li>Search Queries &amp; Jobs<\/li>\n<\/ul>\n\n\n\n<p>The costs are therefore largely dependent on how much log data is produced and how long it is stored (although it should be noted that 90 days of retention is free). The actual costs are therefore difficult to predict and caution is advised. However, there are various data types that do not incur any additional costs for Sentinel or Log Analytics Workspace and can be fed into Sentinel free of charge. These are the following connectors and data types.<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table><thead><tr><th>Microsoft Sentinel data connector<\/th><th>Free data type<\/th><\/tr><\/thead><tbody><tr><td><strong>Azure Activity Logs<\/strong><\/td><td>AzureActivity<\/td><\/tr><tr><td><strong>Microsoft Entra ID Protection<\/strong><\/td><td>SecurityAlert (IPC)<\/td><\/tr><tr><td><strong>Office 365<\/strong><\/td><td>OfficeActivity (SharePoint)<\/td><\/tr><tr><td><\/td><td>OfficeActivity (Exchange)<\/td><\/tr><tr><td><\/td><td>OfficeActivity (Teams)<\/td><\/tr><tr><td><strong>Microsoft Defender for Cloud<\/strong><\/td><td>SecurityAlert (Defender for Cloud)<\/td><\/tr><tr><td><strong>Microsoft Defender for IoT<\/strong><\/td><td>SecurityAlert (Defender for IoT)<\/td><\/tr><tr><td><strong>Microsoft Defender XDR<\/strong><\/td><td>SecurityIncident<\/td><\/tr><tr><td><\/td><td>SecurityAlert<\/td><\/tr><tr><td><strong>Microsoft Defender for Endpoint<\/strong><\/td><td>SecurityAlert (MDATP)<\/td><\/tr><tr><td><strong>Microsoft Defender for Identity<\/strong><\/td><td>SecurityAlert (AATP)<\/td><\/tr><tr><td><strong>Microsoft Defender for Cloud Apps<\/strong><\/td><td>SecurityAlert (Defender for Cloud Apps)<\/td><\/tr><\/tbody><\/table><figcaption class=\"wp-element-caption\"><em>Source: <\/em><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/billing?tabs=classic%2Cfree-data-meters&amp;WT.mc_id=AZ-MVP-5004129#free-data-sources\"><em>https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/billing?tabs=classic%2Cfree-data-meters&amp;WT.mc_id=AZ-MVP-5004129#free-data-sources<\/em><\/a><\/figcaption><\/figure>\n\n\n\n<p>These connectors and data types can therefore be activated free of charge. However, marginal costs will still be incurred by the search queries used.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Personal conclusion<\/h2>\n\n\n\n<p>Microsoft 365 Defender supplemented with Microsoft Sentinel brings various advantages. If you limit yourself to the free data sources, you even get these advantages almost for free. The greater flexibility, the additional automation options, the longer retention period and the better and longer searchability of the log data (keyword active\/passive) that Sentinel brings with it indicate: In my opinion, Microsoft Sentinel should be activated for every Microsoft 365 environment in which security is of importance. Even if Sentinel is not yet actively used and managed. Because in the event of an incident, there are more options available than without it. Is Microsoft Sentinel a \"must have\" for Microsoft 365? For me, the answer to this question is yes.<\/p>","protected":false},"excerpt":{"rendered":"<p>Microsoft Sentinel is a cloud-native SIEM and SOAR solution. Microsoft 365 offers integrated security functions for Azure Active Directory (Entra), Microsoft Defender for Office 365, Microsoft Defender for Endpoint and Microsoft Cloud App Security. However, these features do not cover all possible attack vectors and vulnerabilities that hackers could exploit. In this blog post, I explore how Microsoft Sentinel extends the capabilities of Microsoft Defender XDR (and other Defender products).<\/p>","protected":false},"author":1,"featured_media":1092,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[7],"tags":[3,93,9,10,71,19],"class_list":["post-1089","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-azure","tag-defender-xdr","tag-microsoft-365","tag-office-365","tag-paas","tag-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Microsoft Sentinel for Microsoft 365 - a must have! - Cloud Business &amp; Technology<\/title>\n<meta name=\"description\" content=\"Microsoft Sentinel for Microsoft 365 - a must have! - by Yannic Graber - Blogpost available in german and english.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.graber.cloud\/en\/microsoft-sentinel-for-microsoft-365-a-must-have\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Microsoft Sentinel for Microsoft 365 - a must have! - Cloud Business &amp; Technology\" \/>\n<meta property=\"og:description\" content=\"Microsoft Sentinel for Microsoft 365 - a must have! - by Yannic Graber - Blogpost available in german and english.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.graber.cloud\/en\/microsoft-sentinel-for-microsoft-365-a-must-have\/\" \/>\n<meta property=\"og:site_name\" content=\"Cloud Business &amp; Technology\" \/>\n<meta property=\"article:published_time\" content=\"2023-12-12T16:45:42+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-12-12T16:45:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.graber.cloud\/wp-content\/uploads\/2023\/12\/Sentinel-M365-1024x531.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"531\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Yannic Graber\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@GraberYannic\" \/>\n<meta name=\"twitter:site\" content=\"@GraberYannic\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Yannic Graber\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/\"},\"author\":{\"name\":\"Yannic Graber\",\"@id\":\"https:\/\/www.graber.cloud\/en\/#\/schema\/person\/50b8d88e3d433af9d16d73f354d897fe\"},\"headline\":\"Microsoft Sentinel for Microsoft 365 &#8211; a must have!\",\"datePublished\":\"2023-12-12T16:45:42+00:00\",\"dateModified\":\"2023-12-12T16:45:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/\"},\"wordCount\":1126,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\/\/www.graber.cloud\/en\/#\/schema\/person\/50b8d88e3d433af9d16d73f354d897fe\"},\"image\":{\"@id\":\"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.graber.cloud\/wp-content\/uploads\/2023\/12\/Sentinel-M365.png\",\"keywords\":[\"Azure\",\"Defender XDR\",\"Microsoft 365\",\"Office 365\",\"PaaS\",\"Security\"],\"articleSection\":[\"Technology\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/\",\"url\":\"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/\",\"name\":\"Microsoft Sentinel for Microsoft 365 - a must have! - Cloud Business &amp; Technology\",\"isPartOf\":{\"@id\":\"https:\/\/www.graber.cloud\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.graber.cloud\/wp-content\/uploads\/2023\/12\/Sentinel-M365.png\",\"datePublished\":\"2023-12-12T16:45:42+00:00\",\"dateModified\":\"2023-12-12T16:45:48+00:00\",\"description\":\"Microsoft Sentinel for Microsoft 365 - a must have! - by Yannic Graber - Blogpost available in german and english.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#primaryimage\",\"url\":\"https:\/\/www.graber.cloud\/wp-content\/uploads\/2023\/12\/Sentinel-M365.png\",\"contentUrl\":\"https:\/\/www.graber.cloud\/wp-content\/uploads\/2023\/12\/Sentinel-M365.png\",\"width\":3855,\"height\":1998},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.graber.cloud\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Microsoft Sentinel for Microsoft 365 &#8211; a must have!\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.graber.cloud\/en\/#website\",\"url\":\"https:\/\/www.graber.cloud\/en\/\",\"name\":\"Cloud Business &amp; Technology\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.graber.cloud\/en\/#\/schema\/person\/50b8d88e3d433af9d16d73f354d897fe\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.graber.cloud\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/www.graber.cloud\/en\/#\/schema\/person\/50b8d88e3d433af9d16d73f354d897fe\",\"name\":\"Yannic Graber\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.graber.cloud\/en\/#\/schema\/person\/image\/\",\"url\":\"\/wp-content\/uploads\/2020\/03\/Techdata-Yannic_Graber_downsized.jpg\",\"contentUrl\":\"\/wp-content\/uploads\/2020\/03\/Techdata-Yannic_Graber_downsized.jpg\",\"width\":264,\"height\":267,\"caption\":\"Yannic Graber\"},\"logo\":{\"@id\":\"https:\/\/www.graber.cloud\/en\/#\/schema\/person\/image\/\"},\"description\":\"Experienced technical cloud consultant, certified Azure solutions architect and MCT, focusing on Microsoft Cloud related topics. As a graduate business informatics specialist HF, I consider both the technology and economics. Born in Lucerne, Switzerland and still living there.\",\"sameAs\":[\"https:\/\/www.graber.cloud\",\"https:\/\/www.linkedin.com\/in\/ygr\/\",\"https:\/\/x.com\/GraberYannic\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Microsoft Sentinel for Microsoft 365 - a must have! - Cloud Business &amp; Technology","description":"Microsoft Sentinel for Microsoft 365 - a must have! - by Yannic Graber - Blogpost available in german and english.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.graber.cloud\/en\/microsoft-sentinel-for-microsoft-365-a-must-have\/","og_locale":"en_GB","og_type":"article","og_title":"Microsoft Sentinel for Microsoft 365 - a must have! - Cloud Business &amp; Technology","og_description":"Microsoft Sentinel for Microsoft 365 - a must have! - by Yannic Graber - Blogpost available in german and english.","og_url":"https:\/\/www.graber.cloud\/en\/microsoft-sentinel-for-microsoft-365-a-must-have\/","og_site_name":"Cloud Business &amp; Technology","article_published_time":"2023-12-12T16:45:42+00:00","article_modified_time":"2023-12-12T16:45:48+00:00","og_image":[{"width":1024,"height":531,"url":"https:\/\/www.graber.cloud\/wp-content\/uploads\/2023\/12\/Sentinel-M365-1024x531.png","type":"image\/png"}],"author":"Yannic Graber","twitter_card":"summary_large_image","twitter_creator":"@GraberYannic","twitter_site":"@GraberYannic","twitter_misc":{"Written by":"Yannic Graber","Estimated reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#article","isPartOf":{"@id":"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/"},"author":{"name":"Yannic Graber","@id":"https:\/\/www.graber.cloud\/en\/#\/schema\/person\/50b8d88e3d433af9d16d73f354d897fe"},"headline":"Microsoft Sentinel for Microsoft 365 &#8211; a must have!","datePublished":"2023-12-12T16:45:42+00:00","dateModified":"2023-12-12T16:45:48+00:00","mainEntityOfPage":{"@id":"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/"},"wordCount":1126,"commentCount":1,"publisher":{"@id":"https:\/\/www.graber.cloud\/en\/#\/schema\/person\/50b8d88e3d433af9d16d73f354d897fe"},"image":{"@id":"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#primaryimage"},"thumbnailUrl":"https:\/\/www.graber.cloud\/wp-content\/uploads\/2023\/12\/Sentinel-M365.png","keywords":["Azure","Defender XDR","Microsoft 365","Office 365","PaaS","Security"],"articleSection":["Technology"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/","url":"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/","name":"Microsoft Sentinel for Microsoft 365 - a must have! - Cloud Business &amp; Technology","isPartOf":{"@id":"https:\/\/www.graber.cloud\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#primaryimage"},"image":{"@id":"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#primaryimage"},"thumbnailUrl":"https:\/\/www.graber.cloud\/wp-content\/uploads\/2023\/12\/Sentinel-M365.png","datePublished":"2023-12-12T16:45:42+00:00","dateModified":"2023-12-12T16:45:48+00:00","description":"Microsoft Sentinel for Microsoft 365 - a must have! - by Yannic Graber - Blogpost available in german and english.","breadcrumb":{"@id":"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#primaryimage","url":"https:\/\/www.graber.cloud\/wp-content\/uploads\/2023\/12\/Sentinel-M365.png","contentUrl":"https:\/\/www.graber.cloud\/wp-content\/uploads\/2023\/12\/Sentinel-M365.png","width":3855,"height":1998},{"@type":"BreadcrumbList","@id":"https:\/\/www.graber.cloud\/microsoft-sentinel-for-microsoft-365-a-must-have\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.graber.cloud\/en\/"},{"@type":"ListItem","position":2,"name":"Microsoft Sentinel for Microsoft 365 &#8211; a must have!"}]},{"@type":"WebSite","@id":"https:\/\/www.graber.cloud\/en\/#website","url":"https:\/\/www.graber.cloud\/en\/","name":"Cloud Business &amp; Technology","description":"","publisher":{"@id":"https:\/\/www.graber.cloud\/en\/#\/schema\/person\/50b8d88e3d433af9d16d73f354d897fe"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.graber.cloud\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":["Person","Organization"],"@id":"https:\/\/www.graber.cloud\/en\/#\/schema\/person\/50b8d88e3d433af9d16d73f354d897fe","name":"Yannic Graber","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.graber.cloud\/en\/#\/schema\/person\/image\/","url":"\/wp-content\/uploads\/2020\/03\/Techdata-Yannic_Graber_downsized.jpg","contentUrl":"\/wp-content\/uploads\/2020\/03\/Techdata-Yannic_Graber_downsized.jpg","width":264,"height":267,"caption":"Yannic Graber"},"logo":{"@id":"https:\/\/www.graber.cloud\/en\/#\/schema\/person\/image\/"},"description":"Experienced technical cloud consultant, certified Azure solutions architect and MCT, focusing on Microsoft Cloud related topics. As a graduate business informatics specialist HF, I consider both the technology and economics. Born in Lucerne, Switzerland and still living there.","sameAs":["https:\/\/www.graber.cloud","https:\/\/www.linkedin.com\/in\/ygr\/","https:\/\/x.com\/GraberYannic"]}]}},"_links":{"self":[{"href":"https:\/\/www.graber.cloud\/en\/wp-json\/wp\/v2\/posts\/1089","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.graber.cloud\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.graber.cloud\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.graber.cloud\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.graber.cloud\/en\/wp-json\/wp\/v2\/comments?post=1089"}],"version-history":[{"count":5,"href":"https:\/\/www.graber.cloud\/en\/wp-json\/wp\/v2\/posts\/1089\/revisions"}],"predecessor-version":[{"id":1096,"href":"https:\/\/www.graber.cloud\/en\/wp-json\/wp\/v2\/posts\/1089\/revisions\/1096"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.graber.cloud\/en\/wp-json\/wp\/v2\/media\/1092"}],"wp:attachment":[{"href":"https:\/\/www.graber.cloud\/en\/wp-json\/wp\/v2\/media?parent=1089"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.graber.cloud\/en\/wp-json\/wp\/v2\/categories?post=1089"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.graber.cloud\/en\/wp-json\/wp\/v2\/tags?post=1089"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}