This is the Trace Id: 1b4251c0a20ada2debe06135921393b8
Skip to main content Microsoft Defender Microsoft Entra Microsoft Intune Microsoft Purview Microsoft Security Copilot Microsoft Sentinel SIEM Microsoft Sentinel platform View all products AI-powered cybersecurity Cloud security Data security & governance Identity & network access Privacy & risk management Security for AI Small and medium business Unified SecOps Zero Trust Pricing Services Partners Why Microsoft Security Cybersecurity awareness Customer stories Security 101 Product trials How we protect Microsoft Industry recognition Microsoft Security Insider Microsoft Digital Defense Report Security Response Center Microsoft Security Blog Microsoft Security Events Microsoft Tech Community Documentation Technical Content Library Training & certifications Compliance Program for Microsoft Cloud Microsoft Trust Center Security Engineering Portal Service Trust Portal Microsoft Secure Future Initiative Business Solutions Hub Contact Sales Start free trial Microsoft Security Azure Dynamics 365 Microsoft 365 Microsoft Teams Windows 365 Microsoft AI Azure Space Mixed reality Microsoft HoloLens Microsoft Viva Quantum computing Sustainability Education Automotive Financial services Government Healthcare Manufacturing Retail Find a partner Become a partner Partner Network Microsoft Marketplace Software companies Blog Microsoft Advertising Developer Center Documentation Events Licensing Microsoft Learn Microsoft Research View Sitemap

Cloud-native SIEM capabilities are available in Microsoft Sentinel SIEM.

Learn more
AI-READY SECURITY PLATFORM

Microsoft Sentinel platform

An AI-ready platform that delivers industry-leading security information, unified data lake, enriched graph-powered visibility, and a collection of intelligent reasoning tools.
Contact Sales
OVERVIEW

An intelligence layer that powers agentic security

  • Embrace the agentic future with an AI-ready, data-first foundation. Turn telemetry into security graphs, standardize access for agents, centralize data in a data lake, and span security scenarios across Microsoft and non-Microsoft solutions.
    A woman typing on a laptop.
  • Microsoft tracks more than 78 trillion signals daily, helping security teams identify vulnerabilities with greater efficacy and stay ahead of today's cyberthreats.
    A man holding a tablet.
  • Connecting signals, decisions, and outcomes so your agents can focus on what matters, act with confidence, and drive issues to resolution.
    A person sitting at a desk using a laptop with a white rectangular object nearby.
CAPABILITIES

Explore Microsoft Sentinel platform innovative capabilities

Cost-effective data lake

Unify and centralize security data with scalable, cost-efficient storage to enable advanced analytics, AI, and cyberthreat detection without compromising performance or budget.

Graph-powered context

Centralize visibility and context across use cases that go beyond the SOC with a security graph built right into the platform architecture.

Intelligent Model Context Protocol (MCP) server

Translate natural language into executive tasks with the intelligence and reasoning layer of the platform that enables agents to discover, invoke, and interact with each other.

Native XDR integration

Empower security leaders with native extended detection and response (XDR) integration, delivering unified visibility and control across SIEM and XDR to accelerate cyberthreat detection, streamline investigation, and drive operational efficiency at scale.

Enterprise-wide visibility

Gain comprehensive visibility across multicloud and multiplatform environments through more than 350 native connectors and no-code custom integrations.

Dynamic, tailored recommendations

Streamline your security operations and reduce costs with AI-driven SOC optimization—automating best practices, accelerating cyberthreat response, and helping your team focus on what matters most.

Generative AI-powered assistant for daily operations in security

Accelerate incident investigation and response with generative AI that understands your security data. Security Copilot summarizes incidents, generates Kusto Query Language (KQL) queries, and recommends next steps—reducing mean time to resolution (MTTR) and boosting analyst productivity.

Cyberthreat intelligence enhanced by third-party feeds

Deliver actionable threat intelligence by unifying Microsoft’s rich repository of threat signals—empowering your SOC to detect, investigate, and respond to cyberthreats faster using enriched context, STIX/TAXII support, and AI-driven insights.
The integrated SOC

Unified security operations

Anticipate and stop cyberattacks with an AI-driven defense that unifies prevention, detection, and response, all in
Microsoft Defender.
PRICING

Explore plans and pricing

Microsoft Sentinel
platform

Pay-as-you-go


Microsoft Azure subscription required.
The Microsoft Sentinel platform pricing model offers flexible options to balance security coverage and costs to support diverse business use cases.
  • Select between the analytics and data lake tiers.
  • For a limited time, take advantage of the 50 GB promotion.1
Microsoft Sentinel platform pricing is designed to optimize security coverage and costs, with flexible options based on the volume of data ingested, stored, and consumed.   
FAQ

Frequently Asked Questions

  • An AI-ready platform that delivers industry-leading security information, unified data lake, enriched graph-powered
    visibility, and a collection of intelligent reasoning tools.

  • Azure Sentinel was renamed Microsoft Sentinel to reflect the breadth of the product's capabilities and provide
    protection across multiple cloud solutions.

  • The Microsoft Sentinel data lake is built into your SIEM to lower long-term log retention costs and enable AI-powered
    hunting across years of security data, all without the storage bill of traditional SIEMs.
    It organizes data across assets, identities, activities, and threat intelligence for fast access.

  • Built on Sentinel data lake and SIEM, Sentinel graph brings together posture, activity, threat intelligence, identity,
    and device data into one view to analyze relationships and deliver rich context for action. This transforms how
    defenders understand risks, connect the dots, and prioritize response.

  • MCP is the Model Context Protocol that makes it simple for agents to access data and coordinate actions.
    A Sentinel MCP server provides the intelligence layer to translate natural language into executable tasks that enable agents to act fast.

A person sitting at a desk wearing headphones and using a computer with a yellow label on the screen.
Get started

Protect everything 

Make your future more secure. Explore your security options today.
  1. [1]
    The promo can be used with existing or new purchases of Microsoft Sentinel. The promo may not be combined with other Microsoft Sentinel discounts.

Follow Microsoft Security

English (United States) Consumer Health Privacy Sitemap Contact Microsoft Privacy Manage cookies Terms of use Trademarks Safety & eco Recycling About our ads