Community Insights for Microsoft Sentinel
Synthesised from 9 verified reviews.
Overview
Synthesised from 9 reviews
This product assessment is based on a synthesis of 9 recent reviews analyzing Microsoft Sentinel across multiple dimensions of product satisfaction. Microsoft Sentinel is primarily used as a Security Information and Event Management (SIEM) and within Security Operations Centers (SOC) to centralize security alerting and threat detection. A significant portion of reviewers (6 of 9) report a positive business impact, often citing the ability to scale their business and build new service lines around the platform. Reviewers appreciate its ability to integrate with a wide array of data sources, including Microsoft 365 services. However, a notable concern, voiced by 3 of 9 reviewers, revolves around integration and interface issues, specifically difficulties with dashboard usability and integrating various products and network logs. While many appreciate the AI and machine learning capabilities for threat detection, some reviewers express skepticism about the tangible impact and transparency of these features.
Pros
- Strong integration capabilities, particularly with Microsoft products like Microsoft Defender, allowing for seamless data ingestion and correlation.
- Effective automated threat response capabilities, enabling immediate, pre-configured actions against incoming attacks.
- Scalability, allowing businesses to build entire service lines around the platform and expand their security operations.
- Improved threat detection through AI and machine learning, reducing false positives and enhancing overall detection capabilities.
- Faster investigation processes due to intuitive investigation tools like the graph view, which facilitates deeper problem analysis.
Cons
- Complex integration and interface, leading to difficulties with dashboard usability and integrating various products and network logs.
- Complexity in setting up automation and permissions, requiring specialized knowledge and effort.
- Potential lack of transparency regarding the functionality and impact of AI in driving threat detection.
- Pricing model and licensing complexity, which may be a barrier for mid-size and large companies.
- Limited clarity on the tangible benefits of AI/ML features for some users, leading to skepticism about their effectiveness.