Cloud-native SIEM capabilities are available in Microsoft Sentinel SIEM.
Microsoft Sentinel platform
An intelligence layer that powers agentic security
- Embrace the agentic future with an AI-ready, data-first foundation. Turn telemetry into security graphs, standardize access for agents, centralize data in a data lake, and span security scenarios across Microsoft and non-Microsoft solutions.
- Microsoft tracks more than 78 trillion signals daily, helping security teams identify vulnerabilities with greater efficacy and stay ahead of today's cyberthreats.
- Connecting signals, decisions, and outcomes so your agents can focus on what matters, act with confidence, and drive issues to resolution.
Explore Microsoft Sentinel platform innovative capabilities
Cost-effective data lake
Graph-powered context
Intelligent Model Context Protocol (MCP) server
Native XDR integration
Enterprise-wide visibility
Dynamic, tailored recommendations
Generative AI-powered assistant for daily operations in security
Cyberthreat intelligence enhanced by third-party feeds
Explore plans and pricing
Microsoft Sentinel
platform
Pay-as-you-go
Microsoft Azure subscription required.
The Microsoft Sentinel platform pricing model offers flexible options to balance security coverage and costs to support diverse business use cases.
- Select between the analytics and data lake tiers.
- For a limited time, take advantage of the 50 GB promotion.1
Explore more resources
Frequently Asked Questions
Frequently Asked Questions
-
An AI-ready platform that delivers industry-leading security information, unified data lake, enriched graph-powered
visibility, and a collection of intelligent reasoning tools. -
Azure Sentinel was renamed Microsoft Sentinel to reflect the breadth of the product's capabilities and provide
protection across multiple cloud solutions. -
The Microsoft Sentinel data lake is built into your SIEM to lower long-term log retention costs and enable AI-powered
hunting across years of security data, all without the storage bill of traditional SIEMs.
It organizes data across assets, identities, activities, and threat intelligence for fast access. -
Built on Sentinel data lake and SIEM, Sentinel graph brings together posture, activity, threat intelligence, identity,
and device data into one view to analyze relationships and deliver rich context for action. This transforms how
defenders understand risks, connect the dots, and prioritize response. -
MCP is the Model Context Protocol that makes it simple for agents to access data and coordinate actions.
A Sentinel MCP server provides the intelligence layer to translate natural language into executable tasks that enable agents to act fast.
Protect everything
- [1]The promo can be used with existing or new purchases of Microsoft Sentinel. The promo may not be combined with other Microsoft Sentinel discounts.
Follow Microsoft Security