Are you using Microsoft Sentinel? Richard talks to Cloud Security Advocate Sarah Young about Sentinel, Microsoft's Security Information and Event Management (SIEM) solution. Sarah talks about the role of the SIEM in creating a common place for all security-related data to arrive. She mentions some of the many tools in the Microsoft suite to feed into Sentinel - Defender for Endpoints, Identity, and Cloud as examples. Specialized analysis tools send summaries to Sentinel, but Sentinel can also process raw logs as well - make sure you need the data because billing for Sentinel is connected to the number of ingress sources. There's a lot to learn, but also a lot of great documentation and information to work from. Check the show notes for links!
Links:
Recorded April 6, 2023
Team Metrics with Angela Dugan
IPv6 and Azure Active Directory with Pierre Roman
When Does Multi-Cloud Make Sense with Phoummala Schmitt
SMB over QUIC File Servers with Ned Pyle
Incident Management with Hila Fish
FIDO2 and Passwordless with Kyle Kotowick
Reliability Management with Lesley Cordero
Migrating to Windows 11 with Michael Niehaus
Strengthening Security with Jess Dodson
dbatools Update with Rob Sewell
Moving Your Intranet to the Cloud with Susan Hanley
Application Identities in Azure with Martin Ehrnst
DevOps in 2023 with April Edwards
Local Administrator Password Solution with Jeremy Moskowitz
M365 Governance in 2023 with Martina Grom
Being a SysAdmin in 2023
Reflecting on Microsoft with Mary Jo Foley
Securing Apps in the Cloud with Carroll Moon
Getting Rid of Excel with Jennifer Stirrup
What SysAdmins Want for Christmas with Rick Claus and Joey Snow
Create your
podcast in
minutes
It is Free
.NET Rocks!
Hanselminutes with Scott Hanselman
.NET Rocks!