Microsoft Sentinel is Microsoft’s cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platform. It ingests, aggregates, and analyzes security telemetry from across an organization’s environment — Microsoft and third-party tools alike — and provides the detection, investigation, and response capabilities that underpin modern security operations.
As a cloud-native platform, Sentinel scales to handle the high-volume telemetry that modern enterprise environments generate, without the infrastructure constraints that limited many legacy, on-premises SIEM deployments.
Where Sentinel becomes particularly relevant to the AI SOC conversation is in how deeply artificial intelligence is embedded into its core functionality — not as an add-on module, but as a capability that runs through detection, investigation, and response alike.
Learn more: What Is an AI-Powered SOC?


