Skip to main content

Microsoft Sentinel

Microsoft Sentinel is Microsoft's cloud security information and event management (SIEM) and security orchestration (SOAR) service, built on top of a Log Analytics workspace. The Azure Enterprise Baseline can onboard it to the security workspace in acme-core-security with one switch, off by default.

What it does​

Sentinel adds security analytics to a workspace: data connectors bring in sources, analytics rules turn queries into incidents, workbooks visualize the data, and playbooks (Logic Apps) automate the response. Onboarding a workspace enables Sentinel on it; from then on the analytics tier of ingested data is billed on top of the Log Analytics ingestion. Sentinel queries what the workspace already holds, so the value of onboarding depends on what flows into that workspace.

How BuiltForProd uses it​

The switch is in environments/core/security/security.hcl:

Azure/acme-azure-platform-baseline/environments/core/security/security.hcl (lines 26-26)
enable_sentinel = false # @optional: Microsoft Sentinel on the security workspace ($2.46/GB analytics tier)

When it is true, the observability-sink unit onboards the security workspace law-acme-eus2-security-security (azurerm_sentinel_log_analytics_workspace_onboarding in modules/observability-sink/main.tf). The Baseline's switch is the onboarding itself.

That workspace already carries the platform's security signal before Sentinel is on:

DataArrives through
Defender for Cloud alerts, recommendations, regulatory compliance and secure score of every subscriptionThe continuous export of each subscription's observability-link unit
Defender data from the protected resourcesThe security workspace setting of every subscription baseline

The Activity Log and the Microsoft Entra sign-in and audit logs go to the separate audit workspace in acme-core-audit, where the KQL (Kusto Query Language) alerts of the cis-alerts unit run. Alerts from both workspaces already reach people through the ag-acme-security-alerts action group, including the High and Critical Defender for Cloud alerts, the break-glass sign-in alert and the Conditional Access change alert.

Cost: the switch file lists $2.46 per GB for the analytics tier, on top of the workspace's own ingestion. The onboarding sets customer_managed_key_enabled = false.

Terms you will see​

TermMeaning
SIEMSecurity information and event management: collect, correlate, alert.
SOARSecurity orchestration, automation and response: playbooks on incidents.
OnboardingEnabling Sentinel on one Log Analytics workspace.
Analytics ruleA scheduled query that creates incidents from matches.
Data connectorThe integration that brings a source's events into the workspace.

Where to read more​