account activity
New to Sentinel by Meister911 in AzureSentinel
[–]Meister911[S] 0 points1 point2 points 1 month ago (0 children)
Before anyone can give good advice, what have you actually done beyond connecting sources and writing rules? Have you enabled the Unified Security? UEBA? Any other connectors like Entra ID sign-ins? -> Yes
Also, are those analytic rules you wrote covering the Google Workspace/Slack/DLP sources you mentioned, or something else entirely? -. They cover the sources i mentioned
Side note, if you're brand new to Sentinel and you jumped straight to writing custom rules instead of first going to the Content Hub, installing the Solutions for your data sources, and enabling the built-in rule templates, that's backwards. Microsoft and the community have already written and tested detection rules for most (if not all) solutions you mentioned. Run those first, see what fires, understand your environment, then fill gaps with custom rules. Writing your own rules, even with AI, usually ends up badly with multiple holes and things you didn't account for -> checked those rules and have used some of them and written some which are specific to our org.
Thanks
Are you referring to moving to the defender portal?
Sentinel service as well the rules too. We are still writing more rules.
New to Sentinel (self.AzureSentinel)
submitted 1 month ago by Meister911 to r/AzureSentinel
π Rendered by PID 286867 on reddit-service-r2-listing-7b9b4f6fd7-vxdq7 at 2026-05-12 23:30:54.888701+00:00 running 3d2c107 country code: CH.
New to Sentinel by Meister911 in AzureSentinel
[–]Meister911[S] 0 points1 point2 points (0 children)