The new guide covers the ISV solution lifecycle: learning, building, testing, publishing, previewing, and go-to-market. It explains packaging connectors with security content and lists development workspace permissions and Defender portal onboarding steps.
New guidance covers data lake and graph usage, secure Security Copilot and MCP authentication, notebook jobs, prerequisites, permissions, and post-publication maintenance for ISV platform solutions.
The documentation now states that customers should use the Microsoft 365 auditing solution moving forward after the AIP analytics and audit logs preview retirement.
The article no longer includes connection-agent guidance, preview notices, collection and ingestion details, navigation, or detailed schemas for the documented SAP logs. It adds an ABAP Security Audit Log anchor and updates metadata.
The UEBA reference now lists AWS GuardDuty (Preview) and CommonSecurityLog (Preview), with links to their data connectors, tables, and event details.
The documentation adds a how-to guide for creating and testing an agent that uses Microsoft Sentinel data lake telemetry to correlate identity, access, and endpoint signals before publishing to Security Copilot.
Feature updateAction required The documentation now references output plugin v2.5.0, revises supported Logstash versions, adds version 9.0.8, and flags required security updates for listed versions.
A new article explains how to select and combine Sentinel data lake connectors, Security Copilot agents, the Sentinel MCP server, custom graphs, notebook jobs, and SIEM content based on customer scenarios.
Documentation now explains how ISV partners can build, test, schedule, package, and publish Jupyter notebook analytics solutions for Microsoft Sentinel and the Microsoft Security Store.
A new article explains how to package a Microsoft Security Copilot agent, configure its Partner Center offer, submit listing metadata, and complete review and certification for the Microsoft Security Store.
A new article explains how to use KQL jobs to create tables and ingest scheduled sample IdentityDrift telemetry for querying and agent testing. It also documents production connector options, onboarding prerequisites, and required Security Administrator or Security Operator permissions.
The article now provides more detail on inventorying and comparing QRadar detections, selecting migration paths, and understanding Microsoft Sentinel rule types, including Fusion. It also updates formatting, links, metadata, and examples.
Microsoft added a guide for ISV partners to build, test, package, schedule, and publish Jupyter notebook analytics solutions as SaaS offers in the Microsoft Security Store.
The documentation now describes the solution’s agentless data connector, SAP Integration Suite package, security content, supported SAP data sources, threat detections, monitored configuration, and production-system pricing.
The page now focuses on using the entity analyzer MCP tool in Azure Logic Apps to enrich entities and automate verdicts. It also clarifies supported authentication options and the Security Reader requirement, and updates page metadata.
The article now references Sentinel analytics rules and the SIEM migration experience for finding out-of-the-box matches. It also updates SPL-to-KQL section headings, example links, and wording.
The article was revised with updated metadata and wording, including references to the six-to-12-month rule review window, built-in templates, ArcSight-to-KQL mapping, playbooks, and related resources.
RetirementAction required The documentation states that the containerized SAP data connector agent will be permanently disabled on September 14, 2026. Dependent analytics rules, workbooks, hunting queries, and playbooks will stop returning results for affected SAP systems.
The page updates its title, date, metadata, section headings, navigation anchors, and step numbering for ingestion methods including LightIngest, Azure Blob Storage, Azure Data Factory, and AzCopy.
The page title and metadata were updated, bullet and table formatting was normalized, and the “Use of ingested logs” section was renamed to “Consider how your organization will use ingested logs” with a named anchor added.
The guide now explains that the DeploymentandMigration watchlist stores actions used to track migration progress and that MITRE coverage maps deployed analytics rules to identify detection gaps. Wording, formatting, and SOAR references were also updated.
The Microsoft Sentinel SOC and analyst processes article was updated with a new date and metadata, title capitalization, and minor formatting edits to workflow and incident-assignment guidance.
Updated the page’s capitalization, metadata, step formatting, wording, and navigation heading from “Next steps” to “Related content.”
The guide updates its title and metadata, improves section headings, adds navigation anchors, and clarifies the workflow-stage and component mapping guidance between QRadar SOAR and Microsoft Sentinel.
The guide updates headings and navigation anchors, refines wording and punctuation, and adds definitions for ArcSight SOAR triggers, actions, and playbooks.
The page received title, metadata, wording, punctuation, link, and deployment-instruction updates.
Feature updateAction required The SAP connector page no longer displays system role and health as a table. Administrators should use the SAPSystems KQL function for roles and SentinelHealth or the SAP data collection health alert for health signals. Unknown SIDs are treated as production for security and billing.
Feature updateAction required The generator is now documented as available to Microsoft Sentinel customers in the Defender portal without a separate Security Copilot license or Security Compute Units. Dedicated Security Copilot workspace setup was removed; Automation Playbooks Read and Write permissions are now required to generate and deploy playbooks.
Doc updateAction required The article adds an Overview section, guidance to create an inbound rule for required Scuba service IP ranges, and reorganized related links. Wording and metadata were also refreshed.
The article’s formatting and metadata were refreshed, including clearer list and table formatting, an expanded Microsoft Sentinel Incidents REST API link, updated GitHub playbook wording, and revised next-step text.
The article now identifies the YAML as a plugin descriptor template and directs users to find custom plugins under the Custom section of Manage sources. Title, metadata, formatting, and wording were also updated.
The article now explicitly instructs users to export detection rules, confirms that Security Copilot must be enabled, and clarifies analysis status, matched detections, recommendations, and reports. It also states that the tool does not consume SCUs or generate SCU-based charges.
The article title, link wording, image alt text, and phrasing and formatting across its Azure Lighthouse, workspace, alert, and Power BI guidance were updated.
The article now explains that the unified MCP server exposes Sentinel tool collections, links to the getting-started guidance, and more explicitly identifies the endpoint as the MCP server endpoint for Security Copilot agent creation tools. Title and metadata were also refreshed.
Doc updateAction required The article now specifies required Microsoft Entra ID roles before creating or scheduling jobs, and a managed identity permission requirement for jobs that create custom analytics-tier tables. It also clarifies job-management and `save_as` guidance.
Updated notebook guidance includes clearer permissions and Provider class headings, new navigation anchors, revised Visual Studio Code image descriptions, improved scheduling links, and guidance for creating Jupyter notebooks.
The article now links to required roles and permissions, lists Amazon GuardDuty and supported CommonSecurityLog vendor events, and adds guidance for UEBA tables, schemas, and related articles.
The article now more clearly describes exporting legacy SIEM data and ingesting it into Microsoft Sentinel data lake, Azure Data Explorer (ADX), or Azure Blob Storage. ADX steps and links were revised, including explicit Windows requirements for LightIngest.
The article’s title, metadata, introductory guidance, and section heading were updated. The introduction now explicitly states that historical Splunk data should be exported in CSV format before migration to Azure.
Updated the migration page’s metadata, wording, punctuation, and references to required roles and procedures for playbooks used by one or multiple analytics rules.
The article now uses clearer descriptions for querying Entra ID sign-in, group, and device event tables. It also updates guidance for identifying lateral movement and credential-dumping activity, including connection-count thresholds and port filters.
The documentation now states that Windows Event Forwarding events are written to the `WindowsEvent` table, not `SecurityEvent`. It also notes that built-in rules querying `SecurityEvent` won't match data stored only in `WindowsEvent`.
The article updates its metadata and wording, including clearer subscription-status text and guidance to query Defender for Cloud alerts where the product name is Azure Security Center. It also refreshes the introductory links and closing guidance.
The article now specifies that Microsoft Defender XDR incident integration or onboarding Sentinel to the Defender portal causes Defender XDR to correlate incidents, and clarifies the Microsoft security data connector section and Azure account link.
The page date changed to August 4, 2026, and sections covering static SAP security parameter monitoring and SAP audit-log monitoring were removed.
The page metadata was updated, and the migration-process heading and explanatory text were refined. A named anchor was also added for the migration-process section.
Doc updateAction required The article now directs administrators to confirm that SAP_COLLECTOR_FOR_PERFMONITOR runs hourly and links to the agentless SAP connector documentation. The analytics-rule reference was also updated.
The article now links directly to retention and data tiering, XDR data, custom and auxiliary log tables, and direct ingestion sections. The custom log tables heading and anchor were also updated.
The article’s metadata was updated, and its introductory text was reorganized under a new “Overview” heading.
Updated the article date and authoring metadata, revised wording about Copilot-generated incident summaries and Defender portal guided investigations, and shortened a related link label.
The article description now focuses on ingesting SAP HANA audit logs into Microsoft Sentinel for customer-managed environments and identifies security, infrastructure, and SAP BASIS teams as relevant audiences. The publication metadata was updated, and a “Learn more” line was removed.
The page metadata was updated, and a new section titled “Convert Microsoft Sentinel content to use ASIM normalized data” was added.
The Sentinel Security Copilot article now states that Sentinel data can be used in both the standalone Security Copilot portal and the embedded experience in the Microsoft Defender portal after Sentinel onboarding.
The documentation updates its publication metadata and clarifies that event data retrieved from ESM can be combined with unstructured data alongside CEF data. The listed export formats remain CEF, CSV, and key-value pairs.
The article now states that Windows Security Events via AMA writes to the `SecurityEvent` table, while Windows Forwarded Events writes to `WindowsEvent`. It also adds guidance for forwarded events that do not trigger built-in rules.
The page metadata was updated, and connection pivots, the agent deprecation notice, a deployment image, introductory SAP guidance, and the SAP data connector agent update link were removed.
The AI-assisted SOC row now lists Native Security Copilot references for automated incident summaries, guided response actions, and script analysis.
The article covering prerequisites, package manifests, ZIP creation, and Microsoft Security Store publishing was deleted.
The page now labels the capability as Preview, clarifies storing the client secret in Azure Key Vault, reorganizes connector sections, and adds Azure Databricks prerequisites for hybrid workspaces, external data access, and Delta Parquet tables.
The article received updated wording, formatting, metadata, image markup, and related-content organization. Its preview notice and descriptions of UEBA investigation steps were also edited for consistency.
The article now uses clearer entity-reference link labels, updates wording for launching playbooks from incident views, refreshes metadata, and reorganizes related links.
Feature updateAction required The documentation now requires installing the Amazon Web Services solution from Content Hub so the Amazon Web Services S3 connector appears. It also clarifies connector setup references and updates attack-disruption terminology.
The article title, description, metadata, and formatting were updated. Its description now highlights app registration, authentication, and connecting Sentinel or custom MCP tools to Microsoft Foundry agents.
The page now labels federated data sources as Preview and adds guidance on query optimization, join strategy, and error handling when joining federated and native tables.
The overview now requires external source tables to use Delta Parquet and documents support for hybrid Azure Databricks workspaces, excluding serverless workspaces. The page title also adds “Preview.”
The Microsoft Sentinel comparison table changed custom detection rules from “No” to “Yes (Preview)” for one management capability. The article’s guidance wording and metadata were also updated.
The feature-availability table changes one availability indicator for the Codeless Connectors Platform from “No” to “Yes.” Its Public preview status remains unchanged.
The documentation now describes required ARM template files, folder layouts, metadata fields, validation checks, and incident-versus-alert trigger types for Sentinel playbooks.
The reference now explains that listed UEBA anomalies are stored in the Anomalies table, distinguishes BehaviorInfo insights, and documents Check Point, Fortinet, GuardDuty, and Zscaler anomaly types with data sources, ATT&CK mappings, and activity criteria.
A new guide explains prerequisites and steps to connect SAP to Microsoft Sentinel, including Azure resource deployment, required permissions, DCR authorization, and SAP client setup.
The documentation now explains parser YAML structure, required fields, validation rules, KQL query design, and common submission issues for custom log tables, Syslog, and CEF connectors.
The article describing Microsoft Sentinel for SAP across multiple workspaces was deleted, including guidance on separate SAP and SOC workspaces, access, data residency, and preview limitations.
New guidance explains how anomaly insights enrich UEBA behaviors, where findings are stored, the insight schema, prerequisites, and investigation use in the Microsoft Defender portal.
A new overview explains the differences between SIEM and platform solutions, including their purposes, audiences, content types, foundations, data scopes, tooling, and publishing flows. It also links to guidance for building and publishing SIEM solutions.
Microsoft added guidance for ISVs covering data connectors, analytics rules, playbooks, hunting queries, and parsers. New connectors must use the Codeless Connector Framework, and solutions must include at least one analytics rule.
Microsoft added documentation covering the V3 packaging tool, generated artifacts, deployment through Azure portal or CLI, content validation, and local checks before submission.
The Microsoft Sentinel SAP data connector agent update reference was deleted. It documented the update process and options such as `--confirm-all-prompts`, `--no-testrun`, `--force`, `--containername`, `--sdk`, and `--preview`.
The article now includes multiple YAML examples, a complete sample rule, NRT field guidance, title constraints, status values, and ATT&CK v16 tactic requirements, including a five-tactic limit and valid values.
The Microsoft Sentinel publishing article was revised and expanded with clearer prerequisites and a new section explaining Partner Center tabs, required fields, and default values for Sentinel solution offers.
The article now more clearly covers authentication, autoloading providers and components, Python kernels, package installation issues, and MSTICPYCONFIG environment variables, with platform-specific tabs for Windows, Linux, and Azure Machine Learning.
The article now clarifies prerequisites, authentication guidance, trigger examples, output descriptions, and links for creating analytics rules. Metadata and wording were also refreshed.
The article was reorganized into dedicated sections for data connectors, analytics rules, automation rules, and playbooks, with refreshed wording and links to setup guidance.
The Microsoft Sentinel SAP solution reference for configuring the data connector agent’s systemconfig.json file was deleted, including its configuration structure and settings for secrets, authentication, ABAP, Azure, logging, and connector options.
The article description and content were streamlined by removing connection-agent sections, agent installation references, role-creation procedures, and SNC connection guidance. The user section was renamed to focus on creating an SAP user for the Microsoft Sentinel role.
The article now explains gallery template and WorkbooksMetadata.json attributes, including naming, paths, dependencies, versions, and schema requirements. It also warns that JSON syntax errors can cause build failures.
The guide now focuses on the Microsoft Sentinel SIEM solution lifecycle, adds a lifecycle diagram, and documents prerequisites for publishing to Azure Commercial Marketplace, including joining the Microsoft Cloud Partner Program and creating a Partner Center account.
The page was updated with revised wording for data exploration, graph features, setup steps, access requirements, and tool descriptions, along with metadata and formatting changes.
A new concept article introduces onboarding as Part 1 of the Building Microsoft Sentinel Integrations series. It provides series context, prerequisites, related links, and guidance for approaching later integration procedures.
The article now explains LogServ stream routing, DCR-based filtering before ingestion, examples for excluding log types, ASIM content reuse, and verification timing after DCR changes.
The article now uses clearer titles and headings, adds setup and validation guidance, clarifies the AI-assisted Visual Studio Code workflow, and updates screenshots and metadata.
The Microsoft Sentinel SAP overview now describes separate foundation solutions for SAP applications and SAP BTP, along with SAP LogServ, partner add-ons, and community contributions. It also adds a recent SAP attack example and an attack-replay link.
The page now links directly to its prerequisites, clarifies the MCP endpoint’s purpose, and expands KQL as Kusto Query Language in advanced hunting guidance.
The article’s title, publication metadata, and wording were revised to clarify incident navigation, task and activity-log descriptions, the incident details panel, and entity views.
The article updates its title and metadata, standardizes formatting, renames tab headings, and clarifies instructions for adding OR condition groups and entity-property values.
The article was refreshed with clearer wording for trigger selection and improved formatting for trigger and condition tables, along with updated metadata.
The page received wording and punctuation edits, updated metadata, clearer similarity-section headings, and new navigation anchors.
The article updates GitHub Actions and Azure DevOps customization guidance, including triggers, smart deployments, deployment paths, default configurations, and related documentation links.
The documentation now includes a table of common automation rule and playbook errors with recommended resolutions, and refreshes status descriptions and wording.
The article now documents ABAP authorizations for the SAP account used by the Microsoft Sentinel agentless data connector. It points administrators to the MSFTSEN_SENTINEL_READER role file and removes the former per-log authorization tables and responder-role reference.
The page now clarifies S3 and legacy CloudTrail connector instructions, AWS resource descriptions, Azure Government role assignment, credential locations, prerequisites, and troubleshooting links. The title and page metadata were also refreshed.
The article now separates analyst and workflow-creator scenarios, revises playbook examples, and replaces the “Next steps” section with expanded related-content links.
The article now provides clearer Azure and Defender portal instructions, adds wizard screenshots and steps for automated responses, validation, review, creation, and monitoring, and updates related terminology and links.
The article now has clearer customer-managed key terminology, reorganized headings, updated key-rotation links, and refreshed related-content links and formatting.
The article updates Cost Management labels and links, clarifies data lake billing wording, and reorganizes the closing section as Related content.
The article updates terminology and examples for threat intelligence management and ingestion rules, and adds portal-specific steps for viewing queries against the ThreatIntelIndicators table in the Defender and Azure portals.
The Microsoft Sentinel AWS EKS connector article now includes guidance for verifying audit-log ingestion and troubleshooting common setup issues. Related content links and setup wording were also revised.
The article now distinguishes temporary stops, by pausing the SAP Cloud Integration Data Collector flow, from permanent stops, which involve removing SAP systems, undeploying the flow, and reversing SAP-side configuration. Optional cleanup of related Azure resources is also documented.
The article now highlights requirements to check before switching to simplified pricing, clarifies rollback instructions and dedicated-cluster billing language, and updates cost-management guidance and links.
The article updates wording and metadata, clarifies workbook saving and deletion behavior, recommends ASIM parsers for queries, and specifies that printing and saving as PDF are available only in the Azure portal.
The Microsoft Sentinel TAXII article was revised with clearer wording, reorganized setup steps, updated links, and refreshed metadata. It now explicitly documents importing from TAXII 2.0 or 2.1 and exporting with TAXII 2.1.
The article received clearer navigation links, updated wording and formatting, and refreshed metadata. It now directs readers to connector-specific configuration guidance and identifies the connector details page for support contacts.
The page received wording, formatting, metadata, and link updates. Its related-content links now point to scheduled analytics rules, alert customization, template management, and data connector health guidance.
The article’s title, date, metadata, wording, and limitations-section structure were updated. Guidance now clarifies Logic Apps connector wording, portal-specific alert management, bidirectional synchronization, and the 150-alert incident limit.
The guidance now explicitly names the application ID, tenant ID, client secret, and Microsoft Graph tiIndicators API permission required for TIP integration with Microsoft Sentinel. Section headings and connector-enablement steps were also clarified.
The article’s title, date, metadata, punctuation, grammar, and wording were updated. The guidance now clarifies that workbook parameter values can be referenced elsewhere in the same workbook.
The article now explicitly covers adding or changing entity mappings in existing analytics rules and while creating new scheduled analytics rules. It also updates formatting, metadata, and related-content links.
The article now uses clearer terminology for Azure Logic Apps connections, managed identities, service principals, and application credentials, with updated headings, links, and screenshot descriptions.
The Microsoft Sentinel MITRE ATT&CK coverage article has updated wording, navigation instructions, and references for filtering scenarios and viewing technique details.
The article now uses updated metadata and clearer wording, explicitly names the **Compare to latest version** tab, and reorganizes its related-content links.
Doc updateAction required The article clarifies supported data sources and adds an explicit prerequisite to install a supported data connector and its corresponding Content hub solution before enabling the rule. It also updates terminology, examples, and a related link.
The article adds Azure and Defender portal steps for creating data collection rules, warns not to edit automatically populated transformations for listed applications or devices, and documents ARM-based setup tooling.
The article’s metadata, role link, multitenant portal name, connector-routing wording, and analytics-rule reference were updated.
Feature updateAction required The documentation now requires Microsoft Sentinel data lake onboarding and an Analytics-tier table for split transformations. It also clarifies DCR interactions and warns that deleting a rule immediately stops its data processing.
The article clarifies task-detail fields, adds steps for observing record changes, and updates wording for querying and interpreting incident-task records.
The documentation now clarifies how to create a storage container, upload a watchlist CSV for SAS URL reference, and add the watchlist from Azure Storage. Related Microsoft Sentinel links were also refreshed.
The article now more clearly explains using AzureActivity and LAQueryLogs to audit Sentinel activity, including deleted resources, non-successful queries, resource-intensive clients, active users, and access to sensitive tables. Metadata and heading structure were also updated.
Updated the Microsoft Sentinel Azure Functions connector article with clearer links, section headings, deployment guidance, and Key Vault reference information.
The article now provides clearer guidance for users needing access to specific workspace data, revises the architecture description, and expands the Logstash example to explain Beats input, the Microsoft Sentinel output plugin, and the `azure_resource_id` field.
The documentation now identifies optimization metrics in the Overview tab for both the Defender portal and Azure portal, and clarifies the optimization details pane wording. Guidance for acting on recommendations and managing statuses remains documented.
The article now distinguishes CSV and JSON template guidance, adds instructions for choosing CSV template options, and describes CSV schema and JSON STIX 2.1 examples more precisely. Documentation metadata was also updated.
The article now provides streamlined Defender portal steps and clearer guidance on KQL parameters, entity types, strong identifiers, and dynamic activity titles. Publication and authoring metadata were also updated.
The article now describes anomaly insights on behavior records, including first-seen activity, unusual volumes, uncommon values, and threat-intelligence matches. It also clarifies entity-enrichment queries, supported Fortinet data, and the requirement for actively sending logs.
The article now focuses on adding Sentinel MCP tools to AI agents, clarifies how to use the client secret and Azure values in Copilot Studio OAuth settings, and retitles step 3 around configuring the redirect URI.
The documentation describes the SOAR playbook generator as an AI-assisted LLM feature in the Microsoft Defender portal. It clarifies that generated playbooks are code-based Python scripts running in a managed environment and specifies the permissions required to generate and deploy them.
The article updates its metadata and clarifies troubleshooting wording, including how and when to capture a HAR file during issue reproduction.
The page now uses clearer Microsoft Sentinel terminology, improves navigation and headings, clarifies the GuardDuty-to-S3 export step, and refreshes related links and metadata.
The overview removes containerized data connector guidance and now describes the agentless connector as the solution’s deployment model. It also adds links for SAP Cloud Connector sizing, throughput, and isolation.
The article now uses clearer export/import section headings and anchors, clarifies that exported JSON includes all automation-rule parameters, and updates the troubleshooting reference and metadata.
The page now defines service principals, renames the exceptions section to focus on analytics rule queries, adds a section anchor, and clarifies references to Kusto documentation and automation-rule procedures.
The article title, metadata, and related-content heading were refreshed. It also clarifies that default results apply to the selected search job and updates the related-link labels.
Updated metadata and wording clarify bookmark creation, Advanced hunting availability, MITRE ATT&CK mapping, the Bookmarks tab, incident viewing, and deletion behavior.
The guidance now states that interactive-session graphs are temporary, on-demand graph jobs materialize graphs for 30 days before deletion, and custom graph activity is billed under the Microsoft Sentinel graph meter. It also updates terminology, examples, and links.
The page now uses clearer Analytics and Data Lake terminology and adds a warning that resetting analytics and total retention to 30 days disables the connector in the Azure portal. The page date and authoring metadata were also updated.
The page was refreshed with updated metadata, clearer wording about automation rules and the legacy subscription-based connector, and a consolidated link for Defender for Cloud alerts and incidents in Microsoft Defender XDR.
The article now presents prerequisites and steps more clearly, including resource-provider registration, delegated directory and subscription selection, and the GDAP requirement for deploying connectors from Lighthouse-only managed workspaces.
Doc updateAction required The Sentinel Power BI article now explains that scheduled refresh is configured on the report’s backing dataset, which is created when the report is published. It also specifies the required Log Analytics read-access credentials and adds detail about query results and published reports.
The article’s wording, example description, metadata, and related threat-intelligence links were updated for clarity and consistency.
The article now labels the data collection rule reference section, clarifies which DCR procedures require verification, and warns that deleting the legacy table and custom data connector is irreversible and may affect existing queries, workbooks, or integrations.
The page now focuses on retention and data tier settings for Sentinel and Defender XDR tables, adds Table insights for monitoring ingestion health and costs, and revises its permissions section and related-content links.
The page now describes the KQL query as a 14-day event-volume trend for validating ingestion consistency, notes that TVM tables aren't ingested into Microsoft Sentinel, and improves references to the relevant query documentation.
The article now provides separate steps for viewing existing analytics rule templates in the Defender portal and Azure portal, and updates the procedure wording and metadata.
The article now explicitly describes exporting analytics rules to ARM template JSON files and importing them into other workspaces or tenants. Section headings and anchors were also updated for clarity.
The page now provides clearer links to architecture, deployment instructions, and the ASIM watchlist template. It also clarifies filtering and parameter-less custom parsers, parser union behavior, and watchlist-based exclusion of built-in parsers.
The documentation now provides clearer wording for private-endpoint Azure Machine Learning workspace creation and explains notebook code execution, kernel output, variable persistence, and expression results. Sample output formatting and page metadata were also updated.
The article title and introductory content were revised to emphasize incidents, automation efficiency, data ingestion, and analytics. The automation time-saved formula was rephrased, and links to additional monitoring resources were added.
Updated metadata, added anchors, renamed headings, and clarified when content items are published to member workspaces.
The page metadata was updated, Microsoft Sentinel role names were expanded in links, and screenshot descriptions were made more specific.
The article updates its title and metadata, links the UEBA reference to the deployment guide, and reformats the post-deployment next-step link.
The documentation updates wording and clarifies that the second CloudFormation template creates the remaining AWS resources, including the S3 bucket, SQS queue, and IAM role.
The article updates its metadata, clarifies NRT rule wording, adds a Defender portal viewing section, rephrases creation instructions, and corrects the wizard step numbering.
The article now clarifies required permissions, agents, and log forwarder prerequisites and documents setup through either the Azure or Defender portal or the Logs Ingestion API.
The page clarifies how to assign the Microsoft Sentinel Automation Contributor role through Azure Lighthouse, updates playbook run-history wording, and removes a statement about manually running playbooks on entities in the Defender portal.
The article received updated wording, title capitalization, metadata, code formatting, and revised links to search and restore guidance.
The page received wording refinements for deployment procedures, Content hub filtering, nested playbooks, and connection creation. The publication date and authoring metadata were also updated.
The documentation clarifies that Azure Arc is required for collecting events from non-Azure virtual machines and identifies the JSON filter examples as equivalent definitions for the DCR API payload.
The article title capitalization, publication metadata, introductory text, and “Next step” section formatting were updated. The link to configure content remains included.
The page now describes health and audit logs, SentinelHealth queries, and notifications for analytics rule issues. It also clarifies when SentinelHealth is created, expands NRT terminology, and explains scheduled and Fusion audit rule types.
Doc updateAction required The page now states that users must have the View-Only Audit Logs or Audit Logs role and remote PowerShell access before running the audit-log script. The page metadata and link wording were also updated.
The page’s publication date and authoring metadata were updated, and several Fusion descriptions and scheduled analytics rule guidance were reworded for clarity, including the Customer-Managed Keys link text.
Doc updateAction required The reference now explains that BlobCreated events are sent through an Azure Storage notification queue before connector processing, and adds setup guidance for notification and dead-letter queues.
The article now covers the agentless data connector with SAP Cloud Connector. The connection-agent pivot and its Azure, system, and SAP prerequisite sections were removed.
The article’s date and metadata were updated, introductory wording was revised, and the “Types of insights” heading was renamed to “Types of analytics rule insights” with a named anchor added.
The page adds a link to an open-source Microsoft Sentinel Training Lab with guided exercises and updates terminology and metadata.
The documentation metadata was refreshed, and wording was clarified for query-performance recommendations and the failed-events chart for AWS principal identities.
The page’s update date and custom metadata were revised, and the “Next step” heading was renamed “Next steps” with an anchor added.
The page metadata was updated, and references now explicitly name the Microsoft Entra ID data connector and Microsoft Sentinel in linked guidance.
Updated the page metadata, clarified that dashboards use data collected from Azure Stack Hub virtual machines, identified them as Microsoft Sentinel dashboards, and refined the screenshot description.
The article date and custom metadata were refreshed, and the Dataverse audit-settings reference was reworded and linked directly.
The article’s metadata was updated, and its wording was clarified to state that some diagnostic settings-based connectors are managed through Azure Policy.
The page metadata was refreshed, and the “Sample policy” section was renamed to “Review a sample access restriction policy” with a new anchor. A trailing “For more information” line was removed.
The page now links to the Agent Event schema and documents the Asset Entity schema for normalizing asset inventories and change feeds. The page date was also updated.
The article now links to the procedure for modifying Microsoft Purview analytics rule templates and identifies the referenced Kusto documentation as applying to the sample `PurviewDataSensitivityLogs` query. The page metadata was also updated.
The article now uses the labels “Microsoft Defender portal” and “Microsoft Azure portal,” and its publication date and authoring metadata were updated.
The page now explains that enabling auditing and health monitoring collects resource health and audit data in the SentinelHealth and SentinelAudit tables for monitoring, alerting, and investigation. The page metadata was also updated.
The page date and custom metadata were updated, and the example query text now uses clearer wording for the Log Analytics screenshot and guidance on creating custom analytics rules with watchlists.
The anomaly comparison step now links more clearly to the quality assessment guidance, and the anomaly detection resources heading was revised. Page metadata was also updated.
The article’s date and authoring metadata were updated, and the query guidance now states that queries can run after Azure Virtual Desktop data is connected to Microsoft Sentinel.
The playbook text now says the task targets the user associated with the researched malicious IP address. The document date and authoring metadata were also updated.
The article now states that selecting an incident and choosing **View full details** or **Investigate** switches to the selected incident’s workspace context. Documentation metadata was also updated.
The guide’s publication date and custom metadata were updated, and the description of the MpConfigEdit tabbed configuration tool was reworded.
The Microsoft Sentinel offboarding page now links directly to the “Implications of removing Microsoft Sentinel from your workspace” guidance in its pre-removal review step. The document date and authoring metadata were also updated.
The article now presents the GQL query as a Python example for exploring nested group relationships after graph creation. Documentation metadata was also updated.
The verification step now specifies that administrators should confirm the tools appear under the MCP server they added. The document date and authoring metadata were also updated.
The overview now links to “Build and publish Microsoft Sentinel SIEM solutions” at the updated documentation path.
The documentation now states that deleting a solution does not delete active, cloned, saved, or custom items. The page date and authoring metadata were also updated.
The article date and custom authoring metadata were updated, and its introductory sentence was revised from “This section” to “This article.”
The article metadata was refreshed, and the closing text now directs readers to the next step in the deployment guide.
The documentation now says explicitly that uploading a file after removing items does not delete those items from the existing watchlist. It also updates the page metadata.
The page date was updated, and the guidance now specifies that transformations to Analytics tables in Sentinel-enabled Log Analytics workspaces are exempt from Azure Monitor’s filtering ingestion charge. The Azure Monitor reference link was also updated.
The page date was updated, and the description of the ASIM schemas used by essential solutions was simplified.
The page date was updated, AI-usage metadata was added, and documentation for seven SAP functions—including BAPI_XMI_LOGON and TH_SERVER_LIST—was removed.
Two callouts in the Sentinel ISV solution quality guidance changed from “Caution” to “Important.”
The Microsoft Sentinel best practices page now links partners to “Build and publish Microsoft Sentinel SIEM solutions” instead of the previous partner integration guide.
The Azure Lighthouse guidance sentence now ends correctly with a period instead of an extra “u”.
The threat detection page now links to the updated Microsoft Defender Threat Intelligence page.
The Sentinel threat intelligence integration article now links to the current Defender Threat Intelligence page and updated Microsoft Sentinel GitHub playbook location.
The Microsoft Sentinel for SAP applications kickstart deployment script reference was deleted, including its command-line parameter guidance for secret storage, connection modes, configuration paths, and SAP server settings.
The page no longer includes guidance about the workbook’s hosting workspace or selecting a different SOC workspace when SOC data is stored elsewhere.
The documentation page describing SIEM and platform solution types, prerequisites, and setup requirements was deleted.
The 247-line Microsoft Sentinel SAP reference for the legacy systemconfig.ini file was deleted. It documented configuration sections and settings for data connector agent versions earlier than June 22, 2023.