Instiq
Chapter 4 · Manage Security Operations·v2.0.0·Updated 6/28/2026·~9 min

What's changed: Deepened AZ-500 Chapter 4 (ja figures; comparison tables/scenarios/FAQ/traps/deep paragraphs in all sections)

4.2Microsoft Sentinel (SIEM / SOAR)

Key points

Understand Microsoft Sentinel, a cloud-native SIEM (security information and event management) and SOAR (automated response). It ingests broadly via data connectors, detects threats with analytics rules, and responds automatically with playbooks.

Looking at individual logs alone can’t reveal organization-wide attacks. Sentinel is a cloud SIEM/SOAR that correlates, detects, investigates, and auto-responds across many sources.

4.2.1Sentinel building blocks

Diagram showing data connectors (Entra, Office 365, Defender, various cloud/on-prem) ingesting logs into Microsoft Sentinel on Log Analytics, analytics rules correlating to create incidents, investigation (hunting, entity correlation), and playbooks (SOAR automated response via Logic Apps) executing.
Microsoft Sentinel flow
  • Data connectors: ingest diverse sources—Entra, Microsoft 365, Defender, other clouds/on-prem.
  • Analytics rules: correlate ingested logs to detect threats and create incidents.
  • Investigation/hunting: entity correlation on incidents and proactive threat hunting with KQL.
  • Playbooks: automated response (SOAR) via Logic Apps—automate notifications, ticketing, isolation, etc.
Exam point

Common on AZ-500: cloud-native SIEM = Microsoft Sentinel, ingest diverse sources = data connectors, correlate and create incidents = analytics rules, automated response (SOAR) = playbooks (Logic Apps). Note Sentinel runs on a Log Analytics workspace.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.