What is our primary use case?
I used Sentinel to collect logs from computers. We deployed Sentinel for a government department with a staff of 2,700. The IT and security teams used Sentinel. They are the only people who used the solution. We had a team of 15 to 20 people in IT. Five to six people needed to use it at most. The rest still use the Power BI dashboards because they get the alerts from Sentinel directly.
How has it helped my organization?
Sentinel would tell me if someone was trying to log into my tenancy and access my virtual machines, if someone was trying to hack into the network, and if there were account lockouts where accounts get logged out now and then for users. All these threats get reported by the domain controller. Once we enabled Sentinel, it picked up those logs from the domain controllers and gave me an in-depth report of where and when the accounts got locked and the reason why.
Sentinel saved us time. We only needed to know the queries if we wanted to search logs on our Windows servers. If you know how to run queries and what queries to run, it's a big time saver. It saved about 60% of our time when we needed it.
Moreover, Sentinel has decreased our time to detect and respond to threats. As it's centralized and it gets alerts very quickly. You can set up automated actions on those alerts, and once the alert is triggered, you can set up emails, where emails go out to the admins or security people, who can click on them as soon as they see them. Logs come from the servers almost in real-time within ten to 15 seconds. It saves a lot of time.
What is most valuable?
Sentinel gave us logs to tell us what's going right and wrong in your environment so we could secure the network. We also got multiple kinds of logs. By running some queries from the logs, we could find and fix the anomalies in the environment.
Sentinel's threat visibility was great at telling us if we had something going on in our environment. We had to set up alerts in our environment based on the logs. If we had the right alerts set up, we got notified about threats and where security was lacking, so we could also take care of that.
Sentinel's threat intelligence helped us prepare and take proactive steps for potential threats before they hit.
Having preparation before a threat has helped our security operations. When I was using it, I used to keep going into my dashboards and looking for any threats on a weekly basis, or maybe two or three times a week. Based on that, we would recommend certain changes to the server and infrastructure teams to block or allow some ports. Sentinel's threat intelligence helped plan security against risks.
What needs improvement?
I would like to see a better reporting work structure on the dashboard. It would be nice if Microsoft improved the workbook structure and the analytics. I had to import the Power BI and would be happy to use their transcripts.
For how long have I used the solution?
I used Sentinel for three to four months six months ago.
What do I think about the stability of the solution?
Sentinel is very stable, and there has been no outage.
What do I think about the scalability of the solution?
Scalability is not an issue because it's on the cloud and connected to the workspace and the logs. The logs could be coming from ten servers at the moment, and if we wanted ten more servers to be added, we could do that. And Sentinel doesn't care how many computers it's receiving the logs from. It is scalable.
How are customer service and support?
Microsoft support is amazing. Sometimes it's very good and very quick. And sometimes, we struggle. In the last one or two years, whatever I have logged with Microsoft, it's resolved 99% of the time. Sometimes there is a function or new feature to be added to the solution. I like their support.
How would you rate customer service and support?
How was the initial setup?
The initial setup was easy, but I had already done it a couple of times. There's just the component in Azure. If you have already configured login into your workspace, it's not difficult.
Deployment doesn't take more than an hour. It's less than an hour if you know what you're doing, and it hardly takes a few minutes. And if the monitoring agent is installed on all the servers, the data starts flowing in within ten to 15 minutes, and it's ready to go. Deploying the solution is a very small task, and one person can do it easily. It's a component added to the cloud, and once it's added, it starts working straight away.
What's my experience with pricing, setup cost, and licensing?
Sentinel's slightly on the expensive side. You're paying quite a bit if you enable it for your whole network. And then, it stores lots of data in the logs. It's suitable for large organizations but not very small organizations. However, there are no additional costs apart from the licensing fees.
What other advice do I have?
We have used a Microsoft security product in addition to Sentinel, Defender for Identity. We also get all the security scores, threats, alerts, and incidents in Defender for Endpoint. I did not have to integrate the products since my organization had already started using them before I joined. Still, it's not very difficult to integrate them into the environment with the Active Directory, with some basic technical knowledge required.
Sentinel was of some help in automating the finding of high-value alerts. I set up some alerts on my tenancy, tracking if someone was trying to log into my tenancy from anywhere outside my environment, and I was alerted as soon as they tried to log in. But since there was already automation in Azure, I did not use automation in Sentinel. Azure's automation is just like another older function we had in Defender. We could create a playbook with incident triggers. For example, I had alerts set up that if any account tries to log in more than five times, to send an email to the help desk or the IT team. Once the alerts are triggered, I could create custom actions based on them, similar to any other alerting system. However, I did not specifically use that since we already had an Azure alerting system.
Though I never explored the XDR dashboard, I connected it. Going back to log analytics and Sentinel, they both provide you with workbooks, but I'm not very happy with them. I have connected Log Analytics to the latest Power BI in my environment and run multiple queries from there. Based on that, we get everything in Power BI. We don't use the XDR dashboard for reporting because reporting in Azure or Sentinel is very basic. You can't customize much, and I don't like the uses related to workbooks.
Sentinel enabled us to ingest data from our entire ecosystem because we had connected Azure Log Analytics with Sentinel, and our Log Analytics workspace was getting data from all the servers, not only computers. But collecting data also involves a cost, where the more data you get, the more you pay. We had to maintain a balance there.
Sentinel helped us track threats, but not as an all-in-one solution. Defender is better in that regard because it can access all the environments and respond holistically from one place.
Given Sentinel's built-in SOAR, UEBA, and threat intelligence capabilities, Sentinel gives us value for money. It gives us a wide range of threat protection and connects to various data connectors as well.
Comparing Sentinel's cost and ease of use against stand-alone SIEM and SOAR solutions, Sentinel is cheaper because it's on the cloud, with data from Azure Log Analytics being the only thing we were paying for. The cloud version was cost-effective as compared to on-premise solutions.
Sentinel requires no maintenance as long as Microsoft doesn't change anything. They keep turning off legacy features, so you never know. They could send a message on Sentinel tomorrow, such as, "This feature is going to be turned off by March 2024." We had to move to something else.
Sentinel is nice to have. It's a good choice if you don't have any other solution. I recommend this solution because it alerts you to all the threats and problems in the network. It didn't save us money because enabling it is an additional cost because you're getting and storing more logs in the cloud. It's an additional feature.
I rate Sentinel a nine out of ten.
It's difficult to say whether to go for a best-of-breed or a best-of-suite strategy because everyone has a different approach. Some might want more than one vendor to make sure their environment is safe. At one point, you could go with about ten, but you don't know how many more you are going with. If I had to choose, I would stick to one.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure