Microsoft Sentinel
Cloud and workloads

Enable Microsoft Sentinel SIEM and Initial Features and Content

In brief

The article title capitalization, publication metadata, introductory text, and “Next step” section formatting were updated. The link to configure content remains included.

What Defender admins need to know

No administrator action is required; the changes affect documentation presentation and navigation.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Enable Microsoft Sentinel SIEM and initial featuresInitial Features and contentContent description: As the first step of your deployment, you enable Microsoft Sentinel, and then enable the health and audit feature, solutions, and content. ms.author: edbaynash author: EdB-MSFT ms.reviewer: abhiag ms.topic: how-to ms.date: 06/15/07/01/2026 ai-usage: ai-assisted ms.custom: msecd-doc-authoring-10141016

#Customer intent: As a security operations analyst, I want to enable and configure Microsoft Sentinel and its key features so that I can monitor and secure my organization's environment effectively.

Enable Microsoft Sentinel SIEM and initial features and content

As part of the Deployment guide for Microsoft Sentinel, this procedure walks you through enabling Microsoft Sentinel, enabling the health and audit feature, and enabling the solutions and content you've identified according to your organization's needs. This article is intended for security architects and operations teams who have already completed workspace planning and are ready to activate the service. By the end of these steps, you'll have a functioning Microsoft Sentinel instance with health monitoring turned on and the solutions needed for your selected data sources deployed. This procedure covers initial enablement only; configuring data connectors, analytics rules, and other content is handled in subsequent steps of the deployment guide.

Enable features and content

|3. Enable solutions and content |When you planned your deployment, you identified which data sources you need to ingest into Microsoft Sentinel. Now, you want to enable the relevant solutions and content so that the data you need can start flowing into Microsoft Sentinel. |

Next step: Configure contentstep

After you enable Microsoft Sentinel, its health and audit feature, and the required content, proceed to configure the content for your environment.

[!div class="nextstepaction"]

Configure content \ No newline at end of file Configure content \ No newline at end of file