Microsoft Sentinel
Microsoft Sentinel is Microsoft's cloud security information and event management (SIEM) and security orchestration (SOAR) service, built on top of a Log Analytics workspace. The Azure Enterprise Baseline can onboard it to the security workspace in acme-core-security with one switch, off by default.
What it does
Sentinel adds security analytics to a workspace: data connectors bring in sources, analytics rules turn queries into incidents, workbooks visualize the data, and playbooks (Logic Apps) automate the response. Onboarding a workspace enables Sentinel on it; from then on the analytics tier of ingested data is billed on top of the Log Analytics ingestion. Sentinel queries what the workspace already holds, so the value of onboarding depends on what flows into that workspace.
How BuiltForProd uses it
The switch is in environments/core/security/security.hcl:
enable_sentinel = false # @optional: Microsoft Sentinel on the security workspace ($2.46/GB analytics tier)
When it is true, the observability-sink unit onboards the security workspace law-acme-eus2-security-security (azurerm_sentinel_log_analytics_workspace_onboarding in modules/observability-sink/main.tf). The Baseline's switch is the onboarding itself.
That workspace already carries the platform's security signal before Sentinel is on:
| Data | Arrives through |
|---|---|
| Defender for Cloud alerts, recommendations, regulatory compliance and secure score of every subscription | The continuous export of each subscription's observability-link unit |
| Defender data from the protected resources | The security workspace setting of every subscription baseline |
The Activity Log and the Microsoft Entra sign-in and audit logs go to the separate audit workspace in acme-core-audit, where the KQL (Kusto Query Language) alerts of the cis-alerts unit run. Alerts from both workspaces already reach people through the ag-acme-security-alerts action group, including the High and Critical Defender for Cloud alerts, the break-glass sign-in alert and the Conditional Access change alert.
Cost: the switch file lists $2.46 per GB for the analytics tier, on top of the workspace's own ingestion. The onboarding sets customer_managed_key_enabled = false.
Terms you will see
| Term | Meaning |
|---|---|
| SIEM | Security information and event management: collect, correlate, alert. |
| SOAR | Security orchestration, automation and response: playbooks on incidents. |
| Onboarding | Enabling Sentinel on one Log Analytics workspace. |
| Analytics rule | A scheduled query that creates incidents from matches. |
| Data connector | The integration that brings a source's events into the workspace. |
Where to read more
- Azure Enterprise Baseline overview for the security subscription and its switches.
- Microsoft Defender for Cloud for the data the workspace holds.
- Observable for the platform's logging and alerting guarantees.