SecOps SignalMicrosoft Security Operations Intelligence

High - Microsoft Defender portal, Microsoft Sentinel, Microsoft Defender for Endpoint, Microsoft Defender XDR - Microsoft primary source

Key Updates on Microsoft Unified Security Operations and Microsoft Sentinel Transition

Microsoft has introduced significant updates to unified security operations, including general availability of new content types for multitenant distribution, integration of Microsoft Sentinel into the Defender portal with a planned retirement from Azure portal by March 2027, enhanced threat intelligence alerts, and new UEBA experiences to aid investigations. Additionally, management features like RBAC viewing, content distribution profiles, and task-based incident workflows are improved to streamline operations.

What changed

- New content types (analytics, automation rules, workbooks) generally available for cross-tenant distribution. - Microsoft Sentinel is now generally available in the Microsoft Defender portal; Azure portal support ends March 2027. - Microsoft Threat Intelligence alerts enhanced for Sentinel customers within the Defender portal. - Introduction of UEBA experiences in Defender portal for behavioral insights. - Incident workflows supported with tasks in Defender portal. - Unified RBAC viewing and multitenant content distribution profiles made generally available. - Ability to create/edit Sentinel workbooks directly in Defender portal. - Automatic onboarding and redirection for new Sentinel customers to the Defender portal starting July 2025.

Why it matters operationally

Security operations teams must plan and execute migration from Microsoft Sentinel in the Azure portal to the Defender portal by March 2027 to maintain support and leverage unified security experiences. They can also benefit from new behavioral analytics and task management features that improve investigation efficiency. Expanded content distribution and RBAC capabilities enhance multitenant security management at scale.

What the SOC should check

Validate affected Microsoft products, confirm whether controls or detections need tuning, and record any change-management or monitoring actions.

Recommended actions

  • Plan migration of Microsoft Sentinel workspaces from Azure portal to Defender portal before March 31, 2027.
  • Enable and integrate UEBA capabilities to leverage behavioral anomaly insights for investigations.
  • Adopt task-based incident workflows in the Defender portal to improve incident management.
  • Use new content distribution profiles for efficient multitenant policy and rule management.
  • Leverage enhanced Microsoft Threat Intelligence alerts under appropriate roles (Security/Global Administrator).
  • Train SOC analysts on new features including workbook editing in Defender portal and UEBA workflows.
  • For new Sentinel customers post-July 2025, prepare for automatic onboarding and default use of Defender portal.

KQL hunting context

New UEBA data sources and behavioral anomaly tables have been introduced that can improve detection and hunting queries.

Source links

https://learn.microsoft.com/en-us/unified-secops/whats-new