Microsoft Sentinel
Cloud-native SIEM and SOAR solution that provides intelligent security analytics, threat intelligence, and automated response across enterprise environments, including AI workload telemetry.
Capabilities
- Agent 365 Data ConnectorObserve Agents
Streams AI agent telemetry from Agent 365, Azure AI Foundry, and Microsoft Copilot into the Microsoft Sentinel data lake, where SOC teams investigate agent behavior, tool usage, and execution through KQL hunting, the Sentinel graph, and MCP query workflows. In public preview.
- Agent Identities Asset ConnectorObserve Agents
Ingests agent identities as assets into the Microsoft Sentinel data lake, building an identity graph — owner, agent identity, blueprint, and service principal — for identity-aware investigation and correlation. The inventory counterpart to Defender agent hunting. In public preview.
- Copilot Activity InvestigationObserve Agents Users Data
Brings Microsoft 365 Copilot activity into Microsoft Sentinel through the CopilotActivity table, letting analysts scope interactions by user, host, IP, agent, model, and record type for audit and incident investigation. Detailed prompt and resource context lives in the table's LLMEventData column.
- Power Platform Activity MonitoringObserve Agents
Collects agent and Power Platform activity into Microsoft Sentinel and applies analytics rules to detect, investigate, and respond to suspicious agent behavior alongside other tenant signals. Reduces the risk of undetected malicious agent activity.