Microsoft Sentinel Delegate Roundtable Discussion
In this roundtable discussion, the Field Day delegates discussion the current state of the Microsoft Sentinel. Currently, there is work to do with bringing together multiple portals like Defender, Entra, and Purview, as well as clearing up analysts whose roles span multiple security personas. There is also a need to clarify the licensing requirements and how each of the tools in the overall suite are integrated into workflows. The consensus is that the platform feels like a collection of separate products from different teams rather than a truly unified, integrated solution. This challenge is magnified for organizations with hybrid or multi-cloud environments, where the high cost of ingesting data from non-Microsoft sources like AWS presents a significant barrier to adoption.
The delegates expressed hesitation about making a strategic investment in a platform that seems so early in its development, concerned that future changes could force them to retool their processes. They stressed the need for greater maturity, transparency, and traceability, especially in reporting, as they cannot present “black box” data to senior leadership. For Sentinel to succeed in the real world, the delegates believe Microsoft must demonstrate a stronger commitment to interoperability by adopting open standards like OCSF more quickly and offering more flexibility in data engineering and routing before data enters the Sentinel lake. The feeling is that Microsoft needs to transition from its traditional license-based, “all-or-nothing” approach to prove it can truly function as an open ecosystem partner.
Despite these criticisms, the delegates are optimistic about Sentinel’s potential. The underlying data platform, with its integrated layer of tabular, graph, and vector data, is considered powerful, especially for advanced data science teams. The graph visualizations were particularly praised as an effective way to communicate pre- and post-breach scenarios and risk to business leaders. The delegates concluded that the platform’s greatest current strength is its flexibility. By providing low-code/no-code interfaces and natural language query capabilities, Microsoft empowers customers to build the specific reports and tools they need. This ability for organizations to create their own solutions is seen as a powerful way to bridge the current maturity gap and extract immediate, tailored value from the platform.
Moderated by Tom Hollingsworth of Tech Field Day. Recorded live at Tech Field Day Exclusive with Microsoft Security on October 9, 2025. Watch the entire presentation at https://techfieldday.com/event/mssec25/ or visit https://www.microsoft.com/en-us/security for more information.
Transcript
Welcome back everyone. We are continuing this special Microsoft Security Tech Field Day exclusive event with one of my favorite pieces of content, the Field Day delegate round table. This is an opportunity for our delegates, our special guests here to discuss some of the things that they have seen today, uh, to kind of bring up some points that they feel are important for you out there to understand about what you, uh, may have watched so far.
Uh, if you are watching this after the fact, we hope that you've, uh, consumed the other videos from this presentation already. Um, but otherwise, I want to kind of open the floor up to our delegates to kind of help, uh, start some conversation. Uh, for context, we just learned a lot about Microsoft Sentinel, which was a brand, well, it's not a brand new product, but they added some brand new features back on September the 30th, as part of one of their Microsoft Secure events.
And, uh, this thing seems to be the Swiss Army platform now because it has a new data lake feature. Uh, it's included MCP server, which I don't even know if we got to the MCP server part. Um, but it's, it's a platform that is going to be kind of a, a destination for people who are wanting to enhance their security posture.
You know it, when you hear Data Lake, you know that it's probably a seam of some kind, but I also know it has SOAR functionality or has the capability of triggering SOAR functionality. There's XDR. Um, I think we've hit all the security acronyms so far.
Uh, but I wanna, I wanna open this up to some of our great delegates here. Um, what are some things that maybe you've seen today that, that give you promise for the future? Uh, but likewise, you know, what are some of those lingering questions that you might have regarding, uh, Microsoft Sentinel as a platform and how you would be integrating it into your workflows?
Tom, I'll start, and I think, uh, one of the things that sort of resonated with me is that are, and not really resonated, but that Microsoft has maybe a different conception of what a platform is versus what, uh, we, in the security world, think of a security platform in that they have a whole bunch of components that are working together, but they're not presenting it through a single unified or integrated interface. So you do have essentially four or five different portals. You've got the central portal, you've got the defender portal, you've got the Entrepr portal, the purview portal, and there's no single pane of glass, which could be a good thing or a bad thing depending on how you look at it, but it does make, um, accessing functionality.
If you're a person or a security analyst that takes on multiple personas. It makes accessing functionality a little bit challenging depending on what persona you're operating in at the moment. Jack, did you just make a case for single pane of glass?
'cause I know every time I hear that from somebody else, people tend to like, make the retching noises that, oh no, here we go again and say that everything's unified. Is it more that in this particular case, there needs to be an attempt made to make it feel like a unified user experience so that it doesn't feel like you're jumping back and forth between tools? I think it's both that and an understanding of how, from a a, a CISO or a corporate purchasing perspective, how you're actually acquiring what you're and what it is you're acquiring.
Are you buying, do you buy Sentinel? Do you buy perview? Do you buy all of these pieces and as separate components, or are you buying the whole thing and then accessing it separately?
And that's where really the confusion is, is what, how do you consume it? How do you buy it? How do you acquire it?
How do you operate it, how do you manage it? And then how do you interact with it? But then also, um, on that, it's, it's not just from that view.
Yeah. And if my persona doesn't match their version of what my persona should be, it makes it even more challenging because then I need to figure out what persona or what personas I am now using. But also, um, to use this to the best ability, I need the underlining data and to know what licenses I need to get that underlying data can be quite complex.
And then sometimes there's overlap. So some things that defender for identity does on ID protections also do, but in different ways. And I need to figure out where I sit there.
So kind of designing my plan and what I need it is when you've got it all, it's excellent. When you don't, it gets quite tricky. I'd have to agree with you, uh, Jack Enzo really around the personas.
If I am in a soc, where do I live at? Where, where should I be looking? If I do something else from incident response, where should I, where should I be looking at?
And I think that part was a bit confusing. I like all the features and things that are being added, but from a a role perspective, it would be great to show if you are in this specific role, here is where you would live. Here's everything you would need to do this job.
Yeah, I think like a few of the Microsoft products that I've seen in, in this briefing and some others, it feels early. Like I, I like the idea of the single point of success, but at the moment, they have multiple points of success. Um, but they, so that it looks like they want to make them into a platform that can then feed into anything else if you want, but you don't have to.
But it's not really there yet. There, there's a lot of things that are, well, that's coming or there's, there's the potential for that, or you can plug into it and build it yourself. Like, sure.
But if I'm buying a thing from a vendor, I kind of want it to already do most of like, like I have a use case and I would like it to solve for that use case. And if the use case is, well, I'm a large enterprise and I need an integrated platform that plugs into all of my other existing stuff, then I kind of expect it to already do that. So I, I think part of this is just, maybe it's just really early and they haven't had time to build it yet, which does raise questions about, well, why would I buy it now?
Yeah. So I would agree with that. I think we saw a lot of good things in the demo.
We saw some automation, but there was a lack of maturity in some of the, uh, just the feature set. So, uh, I do think it's early. Uh, and for me, I think I would like to see a lot more maturity in the capabilities around, uh, transparency, traceability, uh, and really locking those things down.
Uh, when I saw on the partner slide, I got excited. I thought, oh, great, we're gonna see some compliance stuff. Uh, but it kind of felt bolted on.
So I do think it's early on. So let, let me kind of branch off on that kind of playing devil's advocate here. Um, there's, there's a lot of discussion around the idea that Microsoft is trying to build a platform and they're trying to understand what needs to happen.
And of course, in any large organization, you're going to have different people that are competing against different things, right? There's it. If, if it feels disjointed, it's probably because they are.
But I guess maybe my, my kind of snarky tongue in cheek question is, uh, why don't we hear about this when we talk about Epson printers or view so monitors? Um, and the answer of course is because why the hell would I worry about security on a printer? And for a long time, when Microsoft was just the Windows and office people, we didn't necessarily have to worry as much about security.
But since they kind of transformed their business under Satya Nadela into being a cloud provider and being a more holistic company, now they do have to worry about things like security and identity and seams and soars and data lakes and things like that. So maybe the reason why it feels early now is because it kind of is from the perspective of us trying to provide that. Whereas you go to some other competitors in the industry who have had 5, 6, 7, 8 years to kind of build a more unified tooling set.
It is a little bit more mature, yet they're still scrambling to come up with solutions for some of these newer features that, that honestly, people didn't think we needed to. Like Marian, one of your favorite things is talking about AI governance. If you'd have asked me three years ago if I needed to have an AI governance policy to keep LLMs from scraping my PII, I would've said those are words.
But though don't, don't make sense in that sentence. And now it's something that a lot of people talk about. So maybe one of the questions that I have for the, the panel here is are, are we all a little early on this and are we maybe hoping for too much to say, oh, well, yeah, they completely solved this problem six months ago.
We've just been waiting for them to dr to, to roll it out to people. I would maybe politely push back a little on the day early to this. I think that the problem is slightly different.
Sentinel has been around for a while, right? I think sent, uh, Sentinel's a product, uh, came out, uh, 2019. 2019, right?
That they, they, they showed us that. So, and in, and Microsoft has operated under a playbook that has always been very successful for them, which is a very, uh, um, a very available MVP followed by very rapid, uh, uh, iterations. And then that eventually becomes, uh, it, it keeps getting better, better, better, better, better.
And then it's good enough. And then, and then it's a, it's a, it's a significant product. We were chatting about how some of us have been in industry forever.
I've seen this playbook back with MS dos and pct, P-C-T-C-P, uh, the T-C-P-I-P stacks on PCs, like literally more than 30 years ago. The where I, what struck me here though, is that I think that fentanyl itself has been evolving and, and, and we've seen that evolution where I think that the conversations we had with them now fell a little bit short is because, uh, it's what's called a curse of knowledge, right? The Microsoft team and, and, and, and some of the, the messaging is deeply embedded in the Microsoft ecosystem, right?
So it's obvious that, oh my God, AI governance that's in purview. Of course, that's obvious, right? But that, but for us, uh, like from the outside, sometimes that's not as clear, right?
So I think that that would be the major thing I would take from that confusion about the, the, the, it's, it's, it's referred to as the curse of knowledge on the platform side. I was intrigued. I'm, I'm, I'm optimistic, right?
I am. I, um, in that, I like how they have this concept of this integrated layer of the, a platform that now has Tableau views, graph views and, and, and beddings and so on. We can debate whether the MCP stuff on top like it that may, that sounded a little early for me.
I'll, I'll give you that, but I'm, I'm optimistic about that, that platform view, because to Jack's earlier point on, on platforms, platform is something that you build on top of. And that integrated layer, if it's done well, can be really interesting, particularly for more advanced teams that can look, I can go and build on top of that. Like, yes, we can use the, the different portals that, uh, that's a pain to deal with, but here, data science team, go have fun.
That is interesting. Anyway, enough rambling. Well, I think part of, for me, part of the issue with the, the, the platform is there's a presentation layer and there's also a, uh, how Microsoft views what a platform is.
And I think right now, from an external viewpoint, it appears that you have five product teams building five products. And from, from a marketing and a positioning is they use the word platform, but they are not building a unified solution. They're building a bunch of tools on which you can integrate and do things together.
But I don't feel that the teams are building an integrated product. They're building five separate products that then have API connectors or MCP connectors Agent, agent or whatever you want to call it, that everybody internally has been told about and uses to connect everything together. So it still, to me feels like it's five separate different things.
Now I think it'll evolve rapidly, but today that, that's where I feel we are. I'd also like to point out that how many organizations are only on Microsoft House, right? So it, it's, it's complex in its own setup, and then you add other things in there.
It can get really complex. And if I, if I'm an analyst, I mean not, I'm not now to be fair, but if I was an analyst, knowing where to go, where to get the information, how to get the information in all the different toolings we have is already a challenge. And then now from the Microsoft view, it's almost like, as you said, Jack, it's, it's almost like you have different toolings that they're not the same company, they are the same company, but they're not.
So it, it, I think it is really challenging, but the data that they do have, when you have all of the features, when you have all of the licenses, it's great data. It's really helpful. Don't get me wrong, the visibility's lovely.
Um, the mapping and the visualization is very sexy. Um, I would like to see more of that. I would like to be able to say, here is the, um, as a tech, here's the information I need as a senior person, here's the slightly reduced noise for you to help you properly identify the risk and properly understand where investment should be and where you can accept risk.
Um, and I'd like to be able to easily create, um, that quantitative data, which I think could be a little bit better. But, um, but it does exist. If you know where to look, my thoughts are, my concern is, um, doing it halfway could get it to the point where it's like, well, I, I just need a little bit more.
I just need, and we're just waiting for them to just, just tune it just a bit more to get me what I want. Well, and I'll make a, I'll make a couple points here on, on this. Um, we, we, at, at a previous company, as I I mentioned, we ran, we, we were at all Microsoft shop.
This was, and, and this was established before I got there. I mean, literally 95% in, in Azure. Uh, and with a very small on-prem footprint that was just, you know, office support, right?
Wireless printers, things like that, right? Just to get you, get you where you needed to go. Um, and so when we, we stood up a sock, which again, before I got there, we didn't have, so, uh, that was one of my, my earlier projects.
Um, it was based on Sentinel and in the Microsoft ecosystem, like we were, it worked very well. It was a great, you know, it was a great product for what it was. Um, there's two concerns I have, however, one is, uh, to your point, Zoe, what happens if you are primarily in AWS or you're hybrid, right?
GCP and AWS or AWS and Azure, uh, what happens with the data ingestion and, and more specifically the costs that, you know, come with, okay, we're gonna start extract, we're gonna start pushing a ton of data out of AWS into the sentinel on Azure, and then we're gonna try and get it out of that. And, you know, I mean, et cetera, et cetera, right? The circle of life, it can get, it, it can get just incredibly, incredibly expensive, um, when you start pulling data from, from non-Microsoft, non Azure, uh, sources.
And so I don't know how it compares or I haven't done a, you know, recent price analysis to other, like, for like, tools on the market. Uh, but the pricing's definitely a concern for me. Yeah, I, I feel like the direction that Microsoft is trying to take is similar to a tool that would work with a bunch of different companies.
However, that's not necessarily how they functioned in the past. It is license based. It is, you have to have everything from us and to make that transition.
There is a, a very big jump there, um, in a revamp of how the licensing is positioned, um, how you work with other companies. And I kind of see it going that direction. I'm just not sure if personally, I'm not sure if they're bought in on that yet, in terms of really being able to, to work with all these other different companies without you having to buy all these different licenses from us to make it work.
I'm not sure if they have either figured that out or they're bought into that, that ecosystem right now To that point. Right. I, I, I agree with you.
I think that, that if there's one overarching lesson for them to take from this, if like you've shown us that you can build this now, show us that you can work with the rest of quote unquote, the real world, right? I'm not saying they do, not the real world, of course, but, and, and two things came up, uh, on that, one of them is that I mentioned, I, I would really love to see, I'm not sure where in the roadmap OCSF support is, but I would like to see it sooner, right? Um, particularly as, uh, like Zoe said, we, we have more stuff on this.
And the other point is, one of the things we're tracking on the SOC modernization effort is this whole niche notion of data engineering, data pipelines, uh, data routing, however you wanna call it. I would've liked to have seen a little bit more on it, right? Yes.
The, once the data gets into the Sentinel Data lake, it's awesome. But, uh, uh, how about, let us tell you about how you select what goes there. It seems to be working under the assumption that I'm going to dump everything there, all the data all the time.
And maybe I don't want to do that. Maybe I want to send some data to S3 before I send it somewhere else, maybe. So I think that flexibility around data routing, right?
That we see with the, uh, with some, some startups in the space, I would've liked to have seen a little bit more of that. I, I quite enjoyed the demo of the graph feature, um, and that focus on exposure management. So being able to visualize and, and gain context of pre breach and post breach scenarios, I'd like to have a play with it.
And I certainly know some peers, Mike, maybe Zoe, some analysts on your team. Um, but I'm curious to see how that plays out, but the costs are around and how realistic that is. Uh, and I didn't feel fully confident that it was just a flip a switch on and you know, this will happen and there'll be context of my environment.
Um, yeah, curious to see what others thought about that. And that's part of my hesitation. I think Ru is that what, because it's early and it has potential, and I think we've all acknowledged that things are probably going to need to change a bit because it wants to be so much, and like, it, it actually has value if you dump a lot of data into it and integrate a lot of different systems that that's where the value comes from.
But that implies that there might be a lot of things that would need to change if I, if like, if I adopt this really early, then when those changes happen, I'm gonna have to retool this. And I'm not quite sure how big an effort that will be. So that, I think if we were, if we were looking to adopt this as a, particularly as a new thing or to adopt it more, that's something I'd want to be talking to them a bit more about the roadmap so that I can plan my own roadmap and not have it be a surprise where they change their mind in six months and say, yeah, that thing that we tried to do, we, we think that's a bad idea now, now it's gonna be in defender instead.
Or, so understanding how that's gonna pan out or at least get a little bit more visibility that would, I think help us to plan how to adapt the, um, how to adopt it. Maybe we delay certain aspects of it, maybe we push them harder. Like you, I've really to say this bit is really great and I'd really like that.
Can you please prioritize this over some of the other things that, yeah, it's neat, but I don't care that much. Would you be applying the same level of scrutiny if it wasn't Microsoft though? Because that's really Oh, always.
Yeah, yeah, yeah. Mm-hmm. Really think, uh, any, anything, uh, any kind of strategic investment, I would absolutely be applying this scrutiny because it's important.
And I don't want anything strategic needs to be flexible enough to change based on my business needs. But I'm also, and particularly with the, the companies that I've been working with of late, they have had some very large surprises from infrastructure vendors. Um, I won't name one that was acquired recently, uh, but a few people have had significant price changes that, um, and functionality changes that influence the way that they can actually use technology.
And if they had made a strategic partnership type of investment in, in a particular infrastructure platform, when you build on top of this and it becomes important, if that suddenly changes out from under you, that can, that suddenly cost that I have to, like, I have to absorb that somehow. We have to either change vendor or deal with it in the budget that I didn't plan for. And that's quite disruptive to everything else that I'm doing.
And I don't want those sorts of surprises. So any kind of strategic investment like that, we, people are much more careful now even than they were a couple of years ago. And also, and also, um, not just talking the financial side, although that's very important also considering, um, as we're doing things, how, how that information is gathered, how accurate that information is.
If I look at your reports, where did you get that information? I can't do black box. I need details because if I present to senior leadership, Hey, look at us, we're doing great, and then turns out we're not doing great, I will be looking for a job, um, which I don't wanna do.
Um, so I really need the clarity. Um, and larger vendors tend to have less clarity just by nature, at least from what I've seen. Um, and so it does make me a bit, a bit more nervous.
I like what you brought up Justin, around, um, being invested. Like, I need to make sure that you are invested in this before I change my process and I bring this to a, a company or a team and we change how we do things. And then you double back maybe six to nine months later and say, this specific feature is gonna be deprecated after we built something around this.
So that is definitely something to think about. Yeah, I think that, that you're, you're raising phenomenal points. I think that what I see happening in industry a lot is we are evolving as a, as a, as an industry like cybersecurity, right?
And we are on one hand, we, we want, and we are building that level of strategic thinking that, uh, Justin mentioned that, Zoe mentioned that you mentioned in terms of, Hey, I am, I am making strategic choices around my vendors. I want you to be here for me. That's one use case.
The other use case that the vendor is seeing is that, oh, look, everyone is saying they don't have time for anything, right? So if you don't have time for anything, let me give you an all-in-one or as close to an all, all-in-one as we can. And, and that is part of this, of, of, of this dilemma, right?
On one hand, do they give us more information, uh, for us to dive in, but a lot of people don't have time to do their regular jobs or nevermind the fact of diving into this information. So it's interesting for a vendor to be able to support both of these, uh, uh, personas, if you will. Frankly, there's, if the, there's a very few small set of vendors in our industry that should be able to support those and absolutely Microsoft is one of them.
So, but it was, uh, um, I think you're all raising phenomenal points. Yeah, no, that is a good point. And that's what I was thinking about with the attack.
Um, um, graphs is if you're only firefighting, you'll probably never get to that, but I would hope you would have time to get to that, um, and be able to plan ahead. Um, but possibly making that what they're doing and the direction they're going in does appear that they're going to make it or they plan to make it easier for, uh, a smaller team that has less time to be able to present those statistics that we already know exist, but we can't communicate effectively to the business. That's one area.
I thought that there was some potential there around the communication. Um, like I, I do like the pic, like I like pictures. They're, they're handy and they, they're quite useful to communicate the summary.
Like, yes, we have written documents, but no one reads the appendix. Um, they're executives, they're busy. So having those pictures I think is quite useful.
Um, but I, I made this comment to them last time in a previous briefing. Sometimes I feel like Microsoft doesn't fully understand the capability they've built and what they could have done with this. And I think to your point, Fernando, like going and having those conversations with customers or indeed analysts who speak to customers all the time to find out things like, well, what would actually be quite useful?
And sometimes it's not the really fancy weird technology buzzy things, it's simple layouts of, just show me a picture of it that can, that tells the story I'm trying to tell as a SOC analyst or as the head of IT or the CISO who's trying to get budget outta the c ffo today. I think that there's a lot of potential there that they're possibly missing because they're a bit too focused on the tech side of stuff. And maybe they could simplify it a bit to get that early value in and understand where the strategic potential for their product is and then build the tech stuff underneath it to support the business plan that they've got around.
Well, this is what customers want to use it for. Um, like, I mean, I would love to see this tool being used to actually create less data stuff. Like a lot of these things of like, why is this even happen?
This shouldn't happen at all. Like I shouldn't have this breach pathway. Can we just fix all of that stuff?
And now I don't have to send all of this data into send all because I haven't got so much broken stuff in my environment. I mean, that's kind of the ultimate goal. So Justin, I'd love to see their, their tool do that more.
Part, part of what I saw them show though was both as a platform vision and as we can't do everything at once, we're giving you a taste of what you can do. And we've also built it in such a way that we've given you tools that you can build that for yourself and do it very, very easily, right? There's a low-code, no-code interface that makes it very easy to query the data and generate those reports.
And when my experience has been that every company is believes they're Snowflake, every company's unique and they all have their very different requirements and they want that report formatted their way. And so for Microsoft to go and do that can be very expensive for them to build a tool that gives you the report you want and is also applicable to somebody else. Whereas if we give you the tools to build that report, we can do it.
And, and I think that they've done it in such a way where you get a low code, no code interface, you get a high code interface. You also have the ability to use their own LLM that's already been trained on their data query language, a QL or whatever it was to query the graph database and the, the right that, that you can use a natural language interface. So a non-technical user could go in and use natural language interface to go say, Hey, show me a pretty graph that does this.
I just have an ad hoc query or then, and then turn that into a report and run that every month or every week. All of those types of capabilities are built there. So I think that's actually very powerful and does give them the ability to, it does give you that ability that you would like from this platform early on.
And that is a fair point. They, they did demonstrate some of those capabilities like the, um, generator notebook with some pictures and so on. So I I, I did like that they demoed that aspect, which I, you make a good point, Jack, that they have, unlike some other vendors who create a really closed system, this one does have the, the hooks in and has APIs and so on.
I don't want 'em to rest on that and make customers build everything yourself. Like they should have some standardized parts to it, but yes, it, it is good to see them have that opening more open platform. So yeah, we didn't think of it, um, build it and then we go, actually that's a great idea.
Do you mind telling us more about that? And maybe we should bake it into the product. Well, Not only could they bake it into the product, I think they've given you the ability to, for you to put it in the store and you can either give it away or charge somebody for that if they find it valuable, which I think is really cool.
Alright, folks, uh, we're pretty much outta time for the round table. I wish we, we could've gone on a little bit more with this and I'm sure there's a lot of more discussions that everybody would love to have. Uh, but we're gonna have to wrap it up here for today.
I'm sure that if you want to go to Microsoft Ignite and have these conversations with the folks at Microsoft, they would love to hear your feedback and your conversations. And we know that there are some features that are gonna be coming out around Microsoft Ignite that we couldn't talk about today. 'cause we don't wanna let the horses out of the barn just yet.
Uh, but I want to thank all of our amazing delegates for being a part of this round table discussion and for the Microsoft exclusive event today. I wanna thank all of you for tuning in and watching, uh, whether you're doing it live or you're doing it in the recording, uh, we, we appreciate you being a part of Field Day. com.
If you've, especially if you've been watching this on our LinkedIn page or on Techstrong tv, we'd love for you to see not only, uh, videos from this event, but all of the upcoming stuff that we have coming out. com/tech field day. Uh uh, we are.