Skip to content

2024

Microsoft Sentinel and Zero Trust

Microsoft Sentinel and Zero Trust

In the last few years, the term "Zero Trust" has been used both to describe a real security strategy and as a buzzword for selling more products. Depending on how you first encountered it, your understanding of the term can vary wildly.

This article is focused on two simple goals:

  1. Define what zero trust means and why it matters.
  2. Show how Microsoft Sentinel can support a zero trust strategy.

Introduction to Microsoft Sentinel's User and Entity Behavior Analytics

As SOC analysts work to defend their environments, one of the hardest problems is understanding what normal actually looks like. Baselines are difficult in distributed organizations with remote work, varied privilege, and a wide mix of systems and workflows.

Microsoft Sentinel's User and Entity Behavior Analytics, or UEBA, is designed to help with that problem by correlating logs and alerts from multiple sources and building behavioral baselines around entities in the environment.