Microsoft Sentinel Expert & SIEM Consultant
I have working presales and implementation experience across Microsoft Sentinel: connector design, ingestion cost control, analytics rules, UEBA, Logic Apps playbooks, workbooks, and KQL hunting. Most Sentinel problems I am called into are not detection problems. They are a bill nobody predicted, caused by decisions made in the first two weeks of the deployment.
- Ingestion cost modelling first
- Defender portal onboarding
- Hands-on deployment experience
What is Microsoft Sentinel?
Microsoft Sentinel is Microsoft's cloud-native SIEM and SOAR platform. It collects security telemetry from across the estate, correlates it into incidents, and drives automated response, all without a server to size or an appliance to renew. Data arrives through data connectors, of which there are hundreds covering Microsoft services, the major cloud providers, firewalls and network gear, identity platforms, and third-party SaaS, plus Syslog and CEF for everything else. Detection is driven by analytics rules: scheduled KQL queries, near-real-time rules, Microsoft security rules that promote product alerts into incidents, and anomaly rules. UEBA adds behavioural baselining per user and per entity so a deviation gets flagged even when no signature matches.
Response is handled by SOAR playbooks built on Azure Logic Apps, which is a genuine advantage: you get a full workflow engine with hundreds of connectors rather than a bolt-on scripting box, so a playbook can disable an Entra account, isolate a device in Defender for Endpoint, post to Teams, raise a ticket, and wait for approval in a single flow. Workbooks provide the visual layer for reporting and monitoring, and threat hunting with KQL is where experienced analysts spend their time, using hunts, bookmarks, livestream, and notebooks to chase a hypothesis rather than wait for an alert.
Now the part that decides whether a deployment succeeds: ingestion cost. This is the number one problem in real Sentinel deployments, and it is almost always self-inflicted. Somebody connects everything, sends verbose firewall and proxy logs into the analytics tier at full fidelity, and three months later there is an invoice nobody can defend. The controls exist and they work. A set of data sources is free, including Azure Activity logs, Office 365 audit logs covering SharePoint, Exchange admin activity, and Teams, and security alerts from Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud. Ingestion-time transformations let you drop columns and filter events before they are billed. Data tiering lets each table sit in the analytics, basic, auxiliary, or data lake tier according to how it is actually used. Commitment tier pricing starts at 100 GB per day and is significantly cheaper than pay-as-you-go once volume is predictable. The first 90 days of retention are included at no charge. The Microsoft Sentinel data lake then holds high-volume, low-value data cheaply for long-term retention and large-scale analytics, billed on a uniform 6:1 compression assumption, which is how you keep years of logs for a regulator without paying SIEM rates for them.
On product direction in 2026, the unification is real and largely done. Microsoft Sentinel is generally available in the Microsoft Defender portal, including for customers with no Defender XDR and no E5 licence, and most customers onboarding after 1 July 2025 are onboarded there automatically. Microsoft has confirmed that after 31 March 2027 Sentinel will no longer be supported in the Azure portal and will be available only in the Defender portal, with existing Azure portal users redirected. That date was extended from an earlier target following customer feedback, so treat it as firm but not the last word. Practically, the Defender portal brings a unified incident queue across SIEM and XDR, unified advanced hunting across Sentinel, Defender, and the data lake, case management, SOC optimisation recommendations, native multi-tenant operations for MSSPs, and Security Copilot embedded in investigation. Microsoft has also said plainly that the Defender portal is the primary innovation surface and the Azure experience is in parity and maintenance mode. If you are still working in the Azure portal, the transition is not urgent this quarter but it should be on the plan.
Official Product Portfolio
- Microsoft Sentinel Overview
- Sentinel in the Defender Portal
- Transition to Defender Portal
- Data Connectors Reference
- Data Tiers and Log Plans
- Pricing and Billing
- Reduce Sentinel Costs
- Microsoft Sentinel Data Lake
- Analytics Rules
- UEBA Entity Behaviour Analytics
- SOAR Playbooks
- Workbooks
- Threat Hunting
- Kusto Query Language (KQL)
Where I Can Help
From cost modelling and connector selection through to detection engineering and automation. These are the areas I cover across Microsoft Sentinel.
Ingestion Cost Control
Modelling volume per source before anything is connected, then designing to it. Free data sources used properly, ingestion-time transformations to drop noise columns, per-table tiering across analytics, basic, auxiliary, and data lake, and the commitment tier decision once daily volume settles.
Data Connectors & Onboarding
Selecting connectors on the basis of what a detection or an investigation actually needs, not on what is available. Includes Syslog and CEF collection through the Azure Monitor agent, custom connectors via Logic Apps or Functions, and ASIM normalisation so rules work across sources.
Analytics Rules & Detection Engineering
Scheduled and near-real-time rule design, tuning out the false positives that make a queue unusable, MITRE ATT&CK coverage mapping so the gaps are visible, and translating incumbent SIEM correlation rules into KQL rather than reimporting them and hoping.
SOAR Playbooks with Logic Apps
Automation that closes the loop: disable an Entra account, isolate a device in Defender for Endpoint, enrich with threat intelligence, raise the ticket, and hold destructive steps behind an approval. Built as Logic Apps so the workflow is maintainable by people who are not developers.
Threat Hunting & UEBA
Enabling UEBA and using the entity pages properly, then running hypothesis-driven hunts in KQL with hunts, bookmarks, and livestream. Includes the workbook layer so leadership sees coverage and trend rather than a screenshot of the incident count.
SIEM Migration & Defender Portal Onboarding
Moving off an incumbent SIEM without importing its cost model, running both in parallel while detections are validated, then onboarding the workspace into the Defender portal for unified incidents and hunting ahead of the 31 March 2027 Azure portal cutoff.
Why Microsoft Sentinel for UAE Organisations?
Building a SOC in the UAE runs into two constraints quickly: qualified analysts are scarce and expensive, and hardware-based SIEM projects tie up capital before they produce a single detection. Sentinel removes the second constraint entirely and softens the first, because the automation layer and the Security Copilot integration mean a smaller team can cover more. For organisations that have been quoted an appliance refresh and a professional services block to go with it, that comparison is usually decisive.
On regulation, logging and retention are not optional here. NESA and the UAE Information Assurance Standards require monitoring and incident response capability with evidence. CBUAE requirements push financial institutions towards continuous monitoring and defined incident reporting timelines. DESC sets expectations for Dubai government entities, and ADGM, DIFC, and the federal PDPL all imply you can reconstruct who touched personal data and when. Sentinel handles the retention problem economically through the data lake tier rather than forcing a choice between compliance and budget.
Data residency is the question that always follows, and it has a real answer: the Sentinel workspace is a Log Analytics workspace in an Azure region that you choose, and Microsoft operates UAE regions. That is not automatic, though. Workspace placement, the location of any Logic Apps used in playbooks, and the storage behind long-term retention all have to be set deliberately at deployment. It is one of the first things I check on a workspace someone else built in a hurry.
Talk to a Sentinel Expert
Whether you are scoping a first SIEM, migrating off an incumbent, or trying to bring a Sentinel bill back under control, I can help you model it before anything is connected.
- Free initial scoping call
- Ingestion cost modelling up front
- UAE & GCC regulatory context
- OSCP-certified security background
Frequently Asked Questions
Part of the Microsoft Security Suite
Sentinel is most valuable when the rest of the estate feeds it. Defender product alerts arrive as free data sources, Entra sign-in logs carry the identity story, Intune supplies device context, and the Defender portal now presents Sentinel and Defender XDR incidents in a single queue. The Microsoft Security hub explains how the pieces connect and links every product page.
Basim Ibrahim, Microsoft Sentinel Consultant in Dubai
If you are searching for a Microsoft Sentinel consultant in Dubai, a Microsoft Sentinel implementation partner in the UAE, or a SIEM expert for GCC deployment, you have found the right person. I am Basim Ibrahim, a Dubai-based cybersecurity presales and technical consultant with hands-on experience deploying and tuning Microsoft Sentinel as a cloud-native SIEM and SOAR platform.
I provide end-to-end Microsoft Sentinel implementation services in Dubai and the UAE, covering data connector design and ingestion cost control, analytics rules and detection engineering, UEBA, SOAR playbook automation with Azure Logic Apps, workbooks and SOC reporting, KQL threat hunting, SIEM migration from incumbent platforms, and onboarding to unified security operations in the Microsoft Defender portal.
Based in Dubai with hands-on experience across UAE and GCC enterprise environments, including NESA, CBUAE, DESC, ADGM, DIFC, and PDPL requirements. An OSCP-certified offensive security background means the detections I build are written against how intrusions actually progress, not just against the rule templates that ship in the content hub.