Microsoft Sentinel
Cloud and workloads

Soc Optimization Access

In brief

The documentation now identifies optimization metrics in the Overview tab for both the Defender portal and Azure portal, and clarifies the optimization details pane wording. Guidance for acting on recommendations and managing statuses remains documented.

What Defender admins need to know

Administrators can use the portal-specific navigation guidance when reviewing optimization recommendations.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Defender portal

In the Defender portal, the Overview tab shows the following optimization metrics:

Title Description
Recent optimization value Shows value gained based on recommendations you recently implemented

Azure portal

In the Azure portal, the Overview tab includes the following optimization metrics:

Title Description
Ingested data over the last 3 months Shows the total data ingested in your workspace over the last three months.
- Toggle between the spider charts to understand your coverage across different tactics and techniques, based on the user-defined and out-of-the-box detections active in your environment.
- Select **View threat scenario in MITRE ATT&CK** to jump to the [**MITRE ATT&CK** page in Microsoft Sentinel](../mitre-coverage.md?tabs=defender-portal), prefiltered for your threat scenario. For more information, see [Understand security coverage by the MITRE ATT&CK® framework](../mitre-coverage.md).
  1. Scroll down to the bottom of the optimization details pane for a link to where you can take the recommended actions. For example:

  • If an optimization includes recommendations to add analytics rules, select Go to Content Hub.

  • If an optimization includes recommendations to move a table to basic logs, select Change plan.

  • For threat-based coverage optimizations, select View full threat scenario to see the full list of relevant threats, active and recommended detections, and coverage levels. From there you can jump directly to the Content hub to activate any recommended detections, or to the MITRE ATT&CK page to view the full MITRE ATT&CK coverage for the selected scenario. For example:

:::image type="content" source="media/soc-optimization-access/threat-scenario-page.png" alt-text="Screenshot of the SOC optimization threat scenario page." lightbox="media/soc-optimization-access/threat-scenario-page.png":::

Manage optimizations

By default, optimization statuses are Active. Change their statuses as your teams progress through triaging and implementing recommendations.

Either select the options menu or select View details to take one of the following actions:

Action Description
Complete Complete an optimization when you completed each recommended action.

If a change in your environment is detected that makes the recommendation irrelevant, the optimization is automatically completed and moved to the Completed tab.

For example, you might have an optimization related to a previously unused table. If your table is now used in a new analytics rule, the optimization recommendation is now irrelevant.

In such cases,When an environment change makes a recommendation irrelevant, a banner shows in the Overview tab with the number of automatically completed optimizations since your last visit.
Mark as in progress / Mark as active Mark an optimization as in progress or active to notify other team members that you're actively working on it.

Use these two statuses flexibly, but consistently, as needed for your organization.
Dismiss Dismiss an optimization if you're not planning to take the recommended action and no longer want to see it in the list.
Provide feedback We invite you to share your thoughts on the recommended actions with the Microsoft team!

When sharing your feedback, be careful not to share any confidential data. For more information, see Microsoft Privacy Statement.