No more typing reviews! Try our Samantha, our new voice AI agent.

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Microsoft Sentinel has improved efficiency, reducing incident response time by 40 to 50% and allowing faster detection of threats.
The integration capabilities of Microsoft Sentinel with other Microsoft products and external systems enhance its threat detection and response capabilities.
The automation features of Microsoft Sentinel, including built-in SOAR capabilities, reduce manual workload and improve response times to incidents.
Microsoft Sentinel offers powerful data correlation and analysis, enabling effective threat investigation and compliance reporting.
Microsoft Sentinel is cost-effective, providing ROI by reducing infrastructure costs and offering extensive integration options without enormous upfront costs.

CONS

Microsoft Sentinel's cost should be reduced, as it is considered quite expensive, particularly when additional features and services increase the overall expense.
Customers encounter integration challenges with third-party systems, lacking sufficient native connectors and sometimes causing discrepancies in data management.
The complexity of using KQL poses a challenge; a more user-friendly or alternative query language is necessary to accommodate users who are not proficient in KQL.
Microsoft Sentinel's automation capabilities need enhancement, including better integration with security products to facilitate use by IT administrators.
Technical support can be improved, specifically in responsiveness and understanding of features, as clients often face delays and obstacles in receiving effective solutions.
 

Microsoft Sentinel Pros review quotes

Kallamuddin Ansari - PeerSpot reviewer
Cyber Security Consultant at ProTechmanize
Jan 17, 2026
Microsoft Sentinel delivers ROI mainly by reducing response time, improving analysis efficiency, and simplifying audits.
reviewer2811318 - PeerSpot reviewer
Vice President, Sales, Cybersecurity at a computer software company with 51-200 employees
Mar 24, 2026
I have seen tons of ROI with Microsoft Sentinel; that's the backbone for our security solution.
Ryan Goodwin - PeerSpot reviewer
Executive VP, Technology at Thrive
Nov 20, 2025
Being able to dictate and train efficiently and in a streamlined way is probably the most value proposition we have for something in this category.
Learn what your peers think about Microsoft Sentinel. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
894,998 professionals have used our research since 2012.
Abhinandan Yadav - PeerSpot reviewer
Network Security Engineer at Arrow PC Network Pvt Ltd
Apr 17, 2026
With Microsoft Sentinel, I have seen clear improvement in efficiency and productivity, such as a 40 to 50% reduction in incident response time.
reviewer2811372 - PeerSpot reviewer
CEO at a tech vendor with 1-10 employees
Mar 24, 2026
For us, at least, the price point is justified, and we have not had any issues.
David Mejak - PeerSpot reviewer
Cloud Solution Architect at MicroAge
Nov 19, 2025
Microsoft Sentinel does give me a unified set of tools to detect, investigate, and respond to incidents, and this unified approach is important to me because in today's world with numerous tools available, it's quite important.
reviewer2811306 - PeerSpot reviewer
Infosec at a government with 10,001+ employees
Mar 24, 2026
Microsoft Sentinel provides me with a unified set of tools to detect, investigate, and respond to incidents, which is something I greatly value.
reviewer2778465 - PeerSpot reviewer
Senior System Administrator at a university with 5,001-10,000 employees
Nov 19, 2025
Microsoft Sentinel flags when admin credentials log in from an unusual location, automatically alerting the security team so they can investigate.
Juan Panas - PeerSpot reviewer
Director de Microsoft y Transformación Digital at Compucad
Nov 6, 2025
The ability of Microsoft Sentinel to correlate data from multiple sources greatly helps our threat detection capabilities because correlation enables faster threat detection, even proactively.
DB
Associate technical desktop support at Digitaltrack soluctions Pvt. ltd
Apr 30, 2026
Microsoft Sentinel has positively impacted my organization by improving visibility across all security logs, reducing incident response time through automation, and enabling faster threat detection, which has strengthened our overall security posture and reduced the manual workload for the SOC team.
 

Microsoft Sentinel Cons review quotes

Kallamuddin Ansari - PeerSpot reviewer
Cyber Security Consultant at ProTechmanize
Jan 17, 2026
Cost management is still one of the biggest pain points.
reviewer2811318 - PeerSpot reviewer
Vice President, Sales, Cybersecurity at a computer software company with 51-200 employees
Mar 24, 2026
Microsoft Sentinel can be improved in that the way it is built today means if you have a third party and you pay for ingestion, this is different than how some of the traditional SIEMs work.
Ryan Goodwin - PeerSpot reviewer
Executive VP, Technology at Thrive
Nov 20, 2025
Our SIEM is only as good as the information we are ingesting. We are all human and we forget to ingest things.
Learn what your peers think about Microsoft Sentinel. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
894,998 professionals have used our research since 2012.
Abhinandan Yadav - PeerSpot reviewer
Network Security Engineer at Arrow PC Network Pvt Ltd
Apr 17, 2026
Microsoft Sentinel can be improved in a few areas, such as enhancing the speed, simplifying the UI, improving faster query performance, providing better out-of-the-box rules, reducing alert noise, and facilitating easier integration setup with more plug-and-play connectors.
reviewer2811372 - PeerSpot reviewer
CEO at a tech vendor with 1-10 employees
Mar 24, 2026
I think any feature which can further help streamline the different security products Microsoft offers would be beneficial.
David Mejak - PeerSpot reviewer
Cloud Solution Architect at MicroAge
Nov 19, 2025
The costs and pricing of Microsoft Sentinel are expensive. That's my biggest complaint, especially from customers who are concerned about the significant expense.
reviewer2811306 - PeerSpot reviewer
Infosec at a government with 10,001+ employees
Mar 24, 2026
However, I do have challenges with KQL, and I believe they could work on making the language more user-friendly.
reviewer2778465 - PeerSpot reviewer
Senior System Administrator at a university with 5,001-10,000 employees
Nov 19, 2025
The SOC optimization feature of Microsoft Sentinel does not appear applicable at the moment in terms of data management and cost efficiency.
Juan Panas - PeerSpot reviewer
Director de Microsoft y Transformación Digital at Compucad
Nov 6, 2025
Microsoft Sentinel should continue adding support for several other security brands because sometimes you have a firewall from a different brand and if you cannot correlate or integrate that seamlessly, it creates multiple points of checking information, which diminishes efficiency.
DB
Associate technical desktop support at Digitaltrack soluctions Pvt. ltd
Apr 30, 2026
Microsoft Sentinel could be improved by making the UI more intuitive, simplifying KQL queries for easier use, improving cost visibility and optimization controls, and enhancing performance and query speed when handling large volumes of data.