Logo of Microsoft Sentinel

Microsoft Sentinel

Website LinkedIn Twitter

Last updated on

Company health

Employee growth
3% increase in the last year
Web traffic
11% decrease in the last quarter

Ratings

G2
4.4/5
(290)

Microsoft Sentinel description

Microsoft Sentinel is a cloud-based security platform that helps businesses of all sizes protect their data and systems. It offers a single view of security events across your entire organization, making it easy to detect and respond to threats. Sentinel uses artificial intelligence to analyze data and identify threats, and it can automate common security tasks to save you time and resources.


Who is Microsoft Sentinel best for

Microsoft Sentinel is a cloud-native SIEM and SOAR platform designed for businesses seeking a comprehensive security solution. Users praise its seamless integration with Microsoft products and robust threat detection capabilities. However, some find the pricing challenging and the interface complex. It's ideal for organizations already invested in the Microsoft ecosystem.

  • Best for medium to large businesses.

  • Ideal for technology and financial services.


Microsoft Sentinel features

Type in the name of the feature or in your own words tell us what you need
Supported

Microsoft Sentinel offers real-time monitoring through data collection, near-real-time analytics, hunting livestream, and alert notifications.

Supported

Microsoft Sentinel integrates with SIEM, ITSM, and other security platforms using data connectors and playbooks.

Supported

Microsoft Sentinel uses analytics rules to detect threats and generate alerts, which are aggregated into incidents. Automation rules can trigger playbooks for automated responses and notifications.

Supported

Sentinel allows searching logs using various criteria, including time range and log type.

Supported

Microsoft Sentinel offers near real-time alerting with a delay of approximately two minutes.

Supported

Microsoft Sentinel simplifies security management with unified visibility, threat intelligence, and integration with Azure Active Directory.

Qualities

We evaluate the sentiment that users express about non-functional aspects of the software

Value and Pricing Transparency

Strongly negative
-0.79

Customer Service

Rather positive
+0.45

Ease of Use

Rather positive
+0.47

Reliability and Performance

Strongly positive
+0.77

Ease of Implementation

Neutral
+0.21

Scalability

Rather positive
+0.69

Microsoft Sentinel reviews

We've summarised 287 Microsoft Sentinel reviews (Microsoft Sentinel G2 reviews) and summarised the main points below.

Pros of Microsoft Sentinel
  • Seamless integration with Microsoft products
  • Excellent threat detection and automated incident response capabilities
  • Scalable and flexible cloud-native solution
  • Easy to use and implement, especially in Azure environments
  • Provides a unified and comprehensive view of security across the organization
Cons of Microsoft Sentinel
  • Can be expensive, especially for startups
  • The user interface can be complex and new users may require training
  • Integration with non-Microsoft solutions can be challenging
  • Requires learning Kusto Query Language (KQL)
  • Can generate false positives if not properly configured

Microsoft Sentinel pricing

The commentary is based on 52 reviews from Microsoft Sentinel G2 reviews.

Microsoft Sentinel's pricing model, based on data ingestion, is a frequent concern. While users appreciate its value, the cost can be unpredictable and potentially high, especially for smaller organizations or those with fluctuating data volumes. Some find it expensive compared to other SIEM solutions.

Users sentiment

Strongly negative
-0.79

Microsoft Sentinel alternatives

  • Logo of SentinelOne Singularity
    SentinelOne Singularity
    More suitable for organizations of all sizes including small businesses. Has stronger momentum based on employee growth. Users highlight the intuitive interface and speed, while some mention difficulties with user management and occasional performance issues. A Microsoft Sentinel competitor and alternative.
    Read more
  • Logo of Microsoft Defender for Cloud
    Microsoft Defender for Cloud
    Better for securing cloud resources across multiple platforms, including AWS and GCP, not just Microsoft Azure. Focuses on vulnerability management, threat protection, and compliance across cloud environments. Caters to organizations of all sizes seeking enhanced cloud security posture management.
    Read more
  • Logo of Druva Data Resiliency Cloud
    Druva Data Resiliency Cloud
    Better for small businesses and those focused on ease of use and data resiliency. Stronger focus on backup and recovery, ransomware protection, and compliance. More affordable for smaller organizations. A Microsoft Sentinel competitor and alternative.
    Read more
  • Logo of Torq
    Torq
    Better fit for organizations focused on automating security workflows. Caters to a wider range of industries including Consumer Goods, Education, and Government. Has significantly more momentum in terms of employee growth. A Microsoft Sentinel competitor and alternative.
    Read more
  • Logo of Lacework
    Lacework
    Has less momentum and a lower average rating.
    Read more
  • Logo of Symantec SASE Framework
    Symantec SASE Framework
    More focused on password security using location-based credentials. Better for small to medium businesses across various industries, especially e-commerce, retail, media, and telco. Growing faster regarding website traffic but has declining employee growth. Offers real-time protection and integrates with other security tools.
    Read more

Microsoft Sentinel FAQ

  • What is Microsoft Sentinel and what does Microsoft Sentinel do?

    Microsoft Sentinel is a cloud-native SIEM and SOAR platform that uses AI to analyze security data across an organization. It helps detect, investigate, and respond to threats efficiently, offering features like real-time monitoring, automated incident detection, and simplified security management.

  • How does Microsoft Sentinel integrate with other tools?

    Microsoft Sentinel integrates with a wide range of security tools, including SIEM, ITSM, and other security platforms. It uses data connectors and playbooks to facilitate these integrations, enabling streamlined security management and automated incident responses.

  • What the main competitors of Microsoft Sentinel?

    Top alternatives to Microsoft Sentinel include Splunk, IBM QRadar, Securonix, Exabeam, and Rapid7 InsightIDR. These competitors offer similar SIEM and SOAR capabilities for threat detection, investigation, and response.

  • Is Microsoft Sentinel legit?

    Yes, Microsoft Sentinel is a legitimate and safe cloud-based security information and event management (SIEM) platform from Microsoft. It offers robust threat detection, investigation, and response capabilities. It's especially well-suited for organizations already invested in the Microsoft ecosystem.

  • How much does Microsoft Sentinel cost?

    I couldn't find pricing details for Microsoft Sentinel. Contact Microsoft directly for product pricing and to determine if Microsoft Sentinel is worth the investment for your needs.

  • Is Microsoft Sentinel customer service good?

    Microsoft Sentinel's customer service receives mixed reviews. While some users praise the helpful and readily available support, others have experienced slow response times and unhelpful redirects. Overall, the experience seems to vary.


Reviewed by

MK
Michal Kaczor
CEO at Gralio

Michal has worked at startups for many years and writes about topics relating to software selection and IT management. As a former consultant for Bain, a business advisory company, he also knows how to understand needs of any business and find solutions to its problems.

TT
Tymon Terlikiewicz
CTO at Gralio

Tymon is a seasoned CTO who loves finding the perfect tools for any task. He recently headed up the tech department at Batmaid, a well-known Swiss company, where he managed about 60 software purchases, including CX, HR, Payroll, Marketing automation and various developer tools.