Microsoft Sentinel is one of the leading SIEM tools on the market today. Over the years, Microsoft has consistently released periodic updates to enhance its capabilities with the goal of helping business enhance their security. In the past few months, Microsoft has rolled out several critical Sentinel updates that will likely prove beneficial for many businesses that rely on this tool as their SIEM solution.
To help you get the best from this SIEM tool, this article will explore all the essential features Sentinel has received in the last three months. We guarantee that by the end, you’ll find at least one crucial feature that will significantly improve your Sentinel experience.
9 New Features in Microsoft Sentinel 2024
These are the 9 key new features Microsoft has added to Sentinel in the last three months. It should be noted that some of these features are still in “preview” and will generally be available soon.
1. Codeless Connector Builder (Preview)
Microsoft introduced this feature to simplify the deployment process of codeless connector platform (CCP) data connectors. Deploying these connectors typically involves working with complex JSON files within ARM templates. However, with the codeless connector builder, users are provided with a workbook that offers a more user-friendly interface.
This interface guides users through the process of navigating and understanding the complex JSON structure. This will ultimately make it easier to deploy CCP data connectors without the need for extensive coding knowledge. By simplifying the development process, organizations can accelerate the integration of data sources into Microsoft Sentinel.
2. SIEM Migration Experience (Preview)
This update will further improve the experience of migrating from other SIEM tools to Sentinel. It addresses the need for seamless migration of security monitoring use cases from non-Microsoft products to Microsoft Sentinel. Previous Splunk users will be the first beneficiaries of this update. However, more SIEM tools will be supported in the future.
By automating the migration of security monitoring use cases, organizations can save time and resources that would otherwise be spent if this process is done manually. This feature is valuable for customers and partners looking to transition from Splunk and other SIEM tools to Microsoft Sentinel.
3. Data Connectors for Syslog and CEF Based on Azure Monitor Agent (GA)
These data connectors enhance the capabilities of Microsoft Sentinel by enabling the collection of Syslog messages. These messages include those formatted in Common Event Format (CEF), from machines with Azure Monitor Agent installed.
Deploying Data Collection Rules (DCRs) to machines equipped with Azure Monitor Agent allows organizations can gather valuable security-related data from diverse sources. This data can then be ingested into Microsoft Sentinel for analysis, enabling comprehensive threat detection and response capabilities.
4. Microsoft Sentinel Solution for Microsoft Power Platform (Preview)
This solution provides organizations with the ability to monitor and detect suspicious or malicious activities within their Microsoft Power Platform environment. With this update, activity logs from various components of the Power Platform, such as Power Apps and Power Automate will be collected and analyzed to identify potential threats.
The solution offers insights into activities like unauthorized Power Apps executions, suspicious data destruction, and phishing attacks facilitated through the Power Platform. This update will be crucial for organizations that use apps in the Power Platform in their workflow.
5. New Google Pub/Sub-based Connector for Ingesting Security Command Center Findings (Preview)
This connector expands the integration capabilities of Microsoft Sentinel by enabling the ingestion of logs from the Google Security Command Center. With this update, organizations that use the Google Cloud Platform (GCP) can seamlessly ingest Security Command Center findings into Microsoft Sentinel for analysis.
Ultimately, this will allow them to centralize their security monitoring efforts and gain comprehensive visibility into security events across both Microsoft and Google environments.
6. Incident Tasks in Microsoft Sentinel (GA)
Incident tasks in Microsoft Sentinel will enable users to standardize incident investigation and response practices. This update will make it easier to streamline incident workflow management, enabling more effective incident handling. Users can utilize incident tasks to manage incidents within Sentinel, track changes, and audit incident-related activities.
The good news is that incident tasks can also be integrated with watchlists, automation rules, and playbooks to create a comprehensive task management solution. This feature enhances efficiency by automating the assignment of tasks to incidents and ensuring they are handled by the appropriate personnel.
7. Microsoft Sentinel Data Connectors for AWS and GCP in Azure Government Clouds
This new update includes connectors for Amazon Web Services (AWS) and Google Cloud Platform (GCP) that enable the ingestion of AWS and GCP service logs into the Sentinel platform. These connectors work by allowing Sentinel to access your AWS and GCP resource logs. So, to set up the connector, a trust relationship needs to be established between AWS/GCP and Sentinel.
There are two versions of this connector available:
- The legacy connector is designed for managing and ingesting CloudTrail logs.
- The new version is capable of ingesting logs from various AWS and GCP services.
This expanded functionality allows for the ingestion of logs from a wider range of AWS and GCP services, ultimately enhancing the visibility and analysis capabilities within Microsoft Sentinel.
8. Windows DNS Events with Azure Monitor Agent (GA)
The Azure Monitor Agent now supports the ingestion of Windows DNS events into Microsoft Sentinel through a generally available data connector. With this connector, organizations can define Data Collection Rules (DCRs) and apply powerful filters to ingest specific DNS records and fields.
By leveraging this feature, organizations can effectively monitor and analyze DNS-related activities within their environment, which enhances their ability to detect and respond to potential threats.
9. Reducing False Positives for SAP Systems with Analytics Rules
The Microsoft Sentinel solution for SAP applications now includes enhancements aimed at reducing false positives triggered by SAP systems. Users can utilize analytics rules in conjunction with the Sentinel solution for SAP applications to lower the number of false positives.
Key enhancements coming with this update include these two major changes:
- Support for excluding users based on their SAP-given roles or profiles using the SAPUsersGetVIP function.
- The ability to use wildcards in the SAPUser field within the SAP_User_Config watchlist for excluding specific users based on syntax.
These changes will help improve the accuracy of threat detection and reduce unnecessary alerts, enhancing overall security monitoring for SAP environments.
Key Takeaways
- Simplified Integrations: The Codeless Connector Builder simplifies the deployment of data connectors, making it easier to integrate external data sources into Microsoft Sentinel. The introduction of connectors for AWS and GCP in Azure Government Clouds also expands the platform’s integration capabilities, allowing for a more comprehensive view of cloud environments.
- Enhanced Threat Detection: Improvements to analytics rules for SAP applications help reduce false positives, ensuring that security teams can focus on genuine threats. The introduction of Incident Tasks standardizes investigation and response practices.
- Improved Migration and Management: Updates to the SIEM Migration Experience facilitate the migration process from other SIEM tools to Microsoft Sentinel. This simplifies the transition for organizations looking to leverage Sentinel’s capabilities for security monitoring and threat detection.
- Broader Visibility: The new Google Pub/Sub-based Connector (Preview) enables the ingestion of findings from the Google Security Command Center, providing organizations with broader visibility into security events across different cloud environments. The Windows DNS Events feature with Azure Monitor Agent offers deeper insights into network activities.
If you’re interested in getting more out of Microsoft Sentinel, our Managed Microsoft Sentinel services are perfect for you. With this service, our team of experts will handle most of the tasks involved in managing this SIEM and ensuring your organization fully utilizes its capabilities, including the new updates discussed in this article.


