Microsoft Unified SecOps Platform
Architecture and deployment

Microsoft Sentinel Onboard

In brief

The page date and onboarding wording were updated to point readers to feature documentation and service-specific prerequisites for unified security operations.

What Defender admins need to know

Administrators preparing onboarding can use the revised guidance to identify relevant documentation and prerequisites.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Prerequisites

Before you begin, review the following feature documentation to understand the product changes and limitations.

If applicable, complete these prerequisites:service-specific prerequisites for unified security operations:

Service Prerequisite
Search - Search across long time spans in large datasets
- Restore archived logs from search
Threat management - Visualize and monitor your data by using workbooks
- Conduct end-to-end threat hunting with Hunts
- Use hunting bookmarks for data investigations
- Use hunting Livestream in Microsoft Sentinel to detect threat
- Hunt for security threats with Jupyter notebooks
- Add indicators in bulk to Microsoft Sentinel threat intelligence from a CSV or JSON file
- Work with threat indicators in Microsoft Sentinel
- Understand security coverage by the MITRE ATT&CK framework
Content management - Discover and manage Microsoft Sentinel out-of-the-box content
- Microsoft Sentinel content hub catalog
- Deploy custom content from your repository
Configuration - Find your Microsoft Sentinel data connector
- Create custom analytics rules to detect threats
- Work with near-real-time (NRT) detection analytics rules in Microsoft Sentinel
- Create watchlists
- Manage watchlists in Microsoft Sentinel
- Create automation rules
- Create and customize Microsoft Sentinel playbooks from content templates
- Generate playbooks by using AI

Find Microsoft Sentinel settings in the Defender portal under System > Settings > Microsoft Sentinel.