Cloud-Native SIEM SOAR Automation KQL Threat Hunting

Microsoft Sentinel Expert & SIEM Consultant

I have working presales and implementation experience across Microsoft Sentinel: connector design, ingestion cost control, analytics rules, UEBA, Logic Apps playbooks, workbooks, and KQL hunting. Most Sentinel problems I am called into are not detection problems. They are a bill nobody predicted, caused by decisions made in the first two weeks of the deployment.

Microsoft Sentinel logo
Cloud-Native SIEM and SOAR
  • Ingestion cost modelling first
  • Defender portal onboarding
  • Hands-on deployment experience

What is Microsoft Sentinel?

Microsoft Sentinel is Microsoft's cloud-native SIEM and SOAR platform. It collects security telemetry from across the estate, correlates it into incidents, and drives automated response, all without a server to size or an appliance to renew. Data arrives through data connectors, of which there are hundreds covering Microsoft services, the major cloud providers, firewalls and network gear, identity platforms, and third-party SaaS, plus Syslog and CEF for everything else. Detection is driven by analytics rules: scheduled KQL queries, near-real-time rules, Microsoft security rules that promote product alerts into incidents, and anomaly rules. UEBA adds behavioural baselining per user and per entity so a deviation gets flagged even when no signature matches.

Response is handled by SOAR playbooks built on Azure Logic Apps, which is a genuine advantage: you get a full workflow engine with hundreds of connectors rather than a bolt-on scripting box, so a playbook can disable an Entra account, isolate a device in Defender for Endpoint, post to Teams, raise a ticket, and wait for approval in a single flow. Workbooks provide the visual layer for reporting and monitoring, and threat hunting with KQL is where experienced analysts spend their time, using hunts, bookmarks, livestream, and notebooks to chase a hypothesis rather than wait for an alert.

Now the part that decides whether a deployment succeeds: ingestion cost. This is the number one problem in real Sentinel deployments, and it is almost always self-inflicted. Somebody connects everything, sends verbose firewall and proxy logs into the analytics tier at full fidelity, and three months later there is an invoice nobody can defend. The controls exist and they work. A set of data sources is free, including Azure Activity logs, Office 365 audit logs covering SharePoint, Exchange admin activity, and Teams, and security alerts from Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud. Ingestion-time transformations let you drop columns and filter events before they are billed. Data tiering lets each table sit in the analytics, basic, auxiliary, or data lake tier according to how it is actually used. Commitment tier pricing starts at 100 GB per day and is significantly cheaper than pay-as-you-go once volume is predictable. The first 90 days of retention are included at no charge. The Microsoft Sentinel data lake then holds high-volume, low-value data cheaply for long-term retention and large-scale analytics, billed on a uniform 6:1 compression assumption, which is how you keep years of logs for a regulator without paying SIEM rates for them.

On product direction in 2026, the unification is real and largely done. Microsoft Sentinel is generally available in the Microsoft Defender portal, including for customers with no Defender XDR and no E5 licence, and most customers onboarding after 1 July 2025 are onboarded there automatically. Microsoft has confirmed that after 31 March 2027 Sentinel will no longer be supported in the Azure portal and will be available only in the Defender portal, with existing Azure portal users redirected. That date was extended from an earlier target following customer feedback, so treat it as firm but not the last word. Practically, the Defender portal brings a unified incident queue across SIEM and XDR, unified advanced hunting across Sentinel, Defender, and the data lake, case management, SOC optimisation recommendations, native multi-tenant operations for MSSPs, and Security Copilot embedded in investigation. Microsoft has also said plainly that the Defender portal is the primary innovation surface and the Azure experience is in parity and maintenance mode. If you are still working in the Azure portal, the transition is not urgent this quarter but it should be on the plan.

Where I Can Help

From cost modelling and connector selection through to detection engineering and automation. These are the areas I cover across Microsoft Sentinel.

Ingestion Cost Control

Modelling volume per source before anything is connected, then designing to it. Free data sources used properly, ingestion-time transformations to drop noise columns, per-table tiering across analytics, basic, auxiliary, and data lake, and the commitment tier decision once daily volume settles.

Data Connectors & Onboarding

Selecting connectors on the basis of what a detection or an investigation actually needs, not on what is available. Includes Syslog and CEF collection through the Azure Monitor agent, custom connectors via Logic Apps or Functions, and ASIM normalisation so rules work across sources.

Analytics Rules & Detection Engineering

Scheduled and near-real-time rule design, tuning out the false positives that make a queue unusable, MITRE ATT&CK coverage mapping so the gaps are visible, and translating incumbent SIEM correlation rules into KQL rather than reimporting them and hoping.

SOAR Playbooks with Logic Apps

Automation that closes the loop: disable an Entra account, isolate a device in Defender for Endpoint, enrich with threat intelligence, raise the ticket, and hold destructive steps behind an approval. Built as Logic Apps so the workflow is maintainable by people who are not developers.

Threat Hunting & UEBA

Enabling UEBA and using the entity pages properly, then running hypothesis-driven hunts in KQL with hunts, bookmarks, and livestream. Includes the workbook layer so leadership sees coverage and trend rather than a screenshot of the incident count.

SIEM Migration & Defender Portal Onboarding

Moving off an incumbent SIEM without importing its cost model, running both in parallel while detections are validated, then onboarding the workspace into the Defender portal for unified incidents and hunting ahead of the 31 March 2027 Azure portal cutoff.

Why Microsoft Sentinel for UAE Organisations?

Building a SOC in the UAE runs into two constraints quickly: qualified analysts are scarce and expensive, and hardware-based SIEM projects tie up capital before they produce a single detection. Sentinel removes the second constraint entirely and softens the first, because the automation layer and the Security Copilot integration mean a smaller team can cover more. For organisations that have been quoted an appliance refresh and a professional services block to go with it, that comparison is usually decisive.

On regulation, logging and retention are not optional here. NESA and the UAE Information Assurance Standards require monitoring and incident response capability with evidence. CBUAE requirements push financial institutions towards continuous monitoring and defined incident reporting timelines. DESC sets expectations for Dubai government entities, and ADGM, DIFC, and the federal PDPL all imply you can reconstruct who touched personal data and when. Sentinel handles the retention problem economically through the data lake tier rather than forcing a choice between compliance and budget.

Data residency is the question that always follows, and it has a real answer: the Sentinel workspace is a Log Analytics workspace in an Azure region that you choose, and Microsoft operates UAE regions. That is not automatic, though. Workspace placement, the location of any Logic Apps used in playbooks, and the storage behind long-term retention all have to be set deliberately at deployment. It is one of the first things I check on a workspace someone else built in a hurry.

100 GB
Daily volume where commitment tier pricing starts
90
Days of retention included at no charge
2027
Azure portal support ends 31 March
6:1
Compression rate used for data lake billing
Available for engagements

Talk to a Sentinel Expert

Whether you are scoping a first SIEM, migrating off an incumbent, or trying to bring a Sentinel bill back under control, I can help you model it before anything is connected.

  • Free initial scoping call
  • Ingestion cost modelling up front
  • UAE & GCC regulatory context
  • OSCP-certified security background
Get in Touch

Frequently Asked Questions

Yes, and it has largely happened. Microsoft Sentinel is generally available in the Microsoft Defender portal, including for customers who do not have Microsoft Defender XDR or an E5 licence. Most customers onboarding to Sentinel after 1 July 2025 are automatically onboarded to the Defender portal. Microsoft has confirmed that after 31 March 2027 Sentinel will no longer be supported in the Azure portal and will be available only in the Defender portal, with Azure portal users redirected. The service itself is not going anywhere. Full SIEM functionality continues, including ingestion, analytics rules, incidents, workbooks, and hunting. Microsoft has also stated the Defender portal is now the primary innovation surface, so new capabilities land there first.

Ingestion cost is the number one problem in real Sentinel deployments, and it is nearly always a design issue rather than a pricing issue. The levers are: use the free data sources, which include Azure Activity logs, Office 365 audit logs, and security alerts from the Defender products; apply ingestion-time transformations to drop noisy columns and irrelevant events before they are billed; choose the right data tier per table across analytics, basic, auxiliary, and the data lake tier so high-volume low-value logs are not paying analytics rates; and move to a commitment tier once volume is predictable, since commitment pricing starts at 100 GB per day and is materially cheaper than pay-as-you-go. Retention is also worth checking, because the first 90 days are included at no charge.

No. Microsoft Sentinel is generally available in the Defender portal for customers without Microsoft Defender XDR or an E5 licence, and it is billed on Azure consumption rather than per user. E5 helps in two ways: alerts from the Defender products are free data sources in Sentinel, and E5 unlocks the unified incident queue where Sentinel and Defender XDR incidents are correlated together. It is a strong combination, but Sentinel does not depend on it.

The main structural difference is that there is no infrastructure to size, patch, or scale, and cost follows data volume rather than licensed EPS or appliance capacity. That cuts both ways: an on-premises SIEM punishes you for storage, and Sentinel punishes you for undisciplined ingestion. The advantages are native connectors and free alert ingestion for the Microsoft estate, KQL as a genuinely capable hunting language, SOAR built in through Azure Logic Apps rather than as a separate purchase, and the data lake tier for cheap long-term retention. The migration work that matters is detection rule translation and deciding what not to ingest, not the platform build itself.

Part of the Microsoft Security Suite

Sentinel is most valuable when the rest of the estate feeds it. Defender product alerts arrive as free data sources, Entra sign-in logs carry the identity story, Intune supplies device context, and the Defender portal now presents Sentinel and Defender XDR incidents in a single queue. The Microsoft Security hub explains how the pieces connect and links every product page.

Microsoft Security Hub

Basim Ibrahim, Microsoft Sentinel Consultant in Dubai

If you are searching for a Microsoft Sentinel consultant in Dubai, a Microsoft Sentinel implementation partner in the UAE, or a SIEM expert for GCC deployment, you have found the right person. I am Basim Ibrahim, a Dubai-based cybersecurity presales and technical consultant with hands-on experience deploying and tuning Microsoft Sentinel as a cloud-native SIEM and SOAR platform.

I provide end-to-end Microsoft Sentinel implementation services in Dubai and the UAE, covering data connector design and ingestion cost control, analytics rules and detection engineering, UEBA, SOAR playbook automation with Azure Logic Apps, workbooks and SOC reporting, KQL threat hunting, SIEM migration from incumbent platforms, and onboarding to unified security operations in the Microsoft Defender portal.

Based in Dubai with hands-on experience across UAE and GCC enterprise environments, including NESA, CBUAE, DESC, ADGM, DIFC, and PDPL requirements. An OSCP-certified offensive security background means the detections I build are written against how intrusions actually progress, not just against the rule templates that ship in the content hub.

Weekly Cyber Insights

One email per week. UAE/GCC focused. No spam, unsubscribe any time.