Platform · Security
Microsoft Sentinel and Defender
Running inside Azure, Microsoft Sentinel collects security data from Microsoft 365, the Defender products, other clouds and third-party sources, while Defender XDR correlates attacks across endpoints, identities, email and cloud apps. SOC analysts investigate in both, querying with KQL, and the SC-200 exam certifies the work. Pricing follows ingested data, so connecting every log source without a plan quickly becomes expensive.
Maker's site: www.microsoft.com/security/business/siem-and-xdr/microsoft-sentinel-siem (opens in a new tab) (no commission).
Where it is used
The topics that name this platform, with the reason.
- SecuritySecurity operationsMicrosoft's SIEM and XDR.
- SecurityIncident response and forensicsDefender XDR is where response starts on Microsoft's stack; SC-200 tests it.
Fields: Cybersecurity
Courses in the directory
1 course is filed here; the top 1 by our ranking, details and the provider link on each course page.
Last reviewed 26 September 2026 · Getting Digital
