Microsoft Learn
learn.microsoft.com › en-us › azure › sentinel › microsoft-365-defender-sentinel-integration
Microsoft Defender XDR integration with Microsoft Sentinel | Microsoft Learn
October 27, 2025 - Integrate Microsoft Sentinel and Defender XDR directly in the Microsoft Defender portal. In this case, view Microsoft Sentinel data directly with the rest of your Defender incidents, alerts, vulnerabilities, and other security data.
Microsoft Learn
learn.microsoft.com › en-us › azure › sentinel › manage-data-overview
Manage data tiers and retention in Microsoft Sentinel | Microsoft Learn
November 18, 2025 - Manage log data in Microsoft Sentinel and with Microsoft Defender XDR services in the Microsoft Defender portal to optimize security operations and cost efficiency.
Videos
11:23
Microsoft Sentinel 2025 Setup & Defender XDR Integration - YouTube
01:00:17
Microsoft Sentinel and Defender XDR Demo - YouTube
01:33
Enhanced Security: Microsoft Sentinel, Defender XDR & Generative ...
16:09
Integrating Microsoft Sentinel with Defender XDR for Ultimate ...
06:50
Microsoft Sentinel Enable Defender XDR Connector - YouTube
10:12
Microsoft Defender XDR, Copilot for Security & Microsoft Sentinel ...
Microsoft Learn
learn.microsoft.com › en-us › azure › sentinel › microsoft-sentinel-defender-portal
Microsoft Sentinel in the Microsoft Defender portal | Microsoft Learn
Microsoft Sentinel is generally available in the Microsoft Defender portal, either with Microsoft Defender XDR, or on its own, delivering a unified experience across SIEM and XDR for faster and more accurate threat detection and response, simplified ...
Reddit
reddit.com › r/azuresentinel › question: integrating microsoft defender xdr with microsoft sentinel
r/AzureSentinel on Reddit: Question: Integrating Microsoft Defender XDR with Microsoft Sentinel
May 7, 2025 -
Post Integrating Microsoft Defender XDR with Microsoft Sentinel, does advance hunting tables reflects on log analytics tables used by Microsot Sentinel??
Top answer 1 of 2
3
Yeah, it will show the logs that you have enable data connectors on sentinel. So keep that in mind too when making analytics rules. For example if you have a table that is typically only on XDR advance hunting such as DeviceEvents, and you do not have the logs on Sentinel, then while you can query that table on advance hunting, it won't work as an analytic rule until you send the logs to sentinel.
2 of 2
3
Just curious - why won’t you query the XDR tables via XDR hunting? That won’t incur extra ingestion costs.
Reddit
reddit.com › r/defenderatp › is sentinel necessary for defender xdr
r/DefenderATP on Reddit: Is Sentinel necessary for Defender XDR
November 14, 2024 -
We have an audit running at the moment, and the technician is telling me that Sentinel is necessary for Defender XDR.
My opinion is, that XDR is a SIEMless system, hence no need for a SIEM but similar performance. But Sentinel is a SIEM, so that would defeat the idea of XDR.
Does anyone know if Sentinel is actually necessary for the XDR Detections or if it is just to have "better" automation?
Top answer 1 of 5
9
Sentinel is more than just a SIEM aka place to store logs. It is a SOAR as well. Going back to your question, no it's not needed and you can go with just Microsoft XDR but you are missing lots of functionality Threat Intelligence Custom analytic rules Playbooks aka logic apps Etc I would never recommend XDR without Sentinel though, unless you have a very tight budget of course.
2 of 5
5
SIEM in no way ”defeats the idea of XDR”. Most large orgs run both. Do you need to do custom data sources / integrations? Response automation? If so you need Sentinel OR some other SIEM/SOAR.
Microsoft
microsoft.com › en-us › security › business › siem-and-xdr › microsoft-sentinel
Microsoft Sentinel—AI-Ready Platform | Microsoft Security
October 8, 2025 - Microsoft Sentinel is a security platform with built-in SIEM capabilities. ... Microsoft Defender XDR is a suite of tools that unifies prevention, detection, and response across endpoints, identities, email, and applications to deliver a consolidated view of threats, adaptive protection against cyberattacks, and streamlined incident response and remediation.
Microsoft Learn
learn.microsoft.com › en-us › unified-secops › microsoft-sentinel-onboard
Connect Microsoft Sentinel to the Microsoft Defender portal - Unified security operations | Microsoft Learn
September 18, 2025 - Microsoft Sentinel is generally available in the Microsoft Defender portal, with or without Microsoft Defender XDR or an E5 license. Using Microsoft Sentinel in the Defender portal together with Microsoft Defender XDR services, you unify capabilities like incident management and advanced hunting.
Microsoft Learn
learn.microsoft.com › en-us › security › zero-trust › siem-xdr-implement
Zero Trust Security with Microsoft Sentinel and Defender XDR | Microsoft Learn
February 12, 2025 - Using artificial intelligence (AI) and machine learning, the XDR performs automatic analysis, investigation, and real-time response. It also correlates security alerts into larger incidents, giving security teams greater visibility into attacks and prioritizing incidents to help analysts gauge threat risk levels. With Microsoft Sentinel, you can connect to many security sources using built-in connectors and industry standards.
Microsoft Learn
learn.microsoft.com › en-us › shows › microsoft-sentinel-defender-xdr-virtual-ninja-training › unifying-siem-xdr-a-new-era-in-secops
Unifying SIEM & XDR: a new era in SecOps | Microsoft Learn
March 8, 2024 - In this episode—live from Microsoft Ignite—Principal Product Managers Javier Soriano and Tiander Turpijn lead the conversation on the newest unified security operations platform: Microsoft Sentinel & Defender XDR. Learn how this innovation offers you enhanced analyst efficiency by combining security information and event management (SIEM) and extended detection and response (XDR), reducing interruptions through consolidation of duplicate features, and enabling proactive attack detection and disruption across Microsoft and non-Microsoft products.
Microsoft Learn
learn.microsoft.com › en-us › azure › sentinel › connect-microsoft-365-defender
Connect Microsoft Defender XDR data to Microsoft Sentinel | Microsoft Learn
The Microsoft Defender XDR connector for Microsoft Sentinel allows you to stream all Microsoft Defender XDR incidents, alerts, and advanced hunting events into Microsoft Sentinel.
Microsoft Learn
learn.microsoft.com › en-us › security › zero-trust › siem-xdr-overview
Incident Response with XDR and Integrated SIEM | Microsoft Learn
Microsoft Sentinel is a cloud-native solution that provides security information and event management (SIEM) and security orchestration, automation, and response (SOAR) capabilities.
Ecloudvalley
ecloudvalley.com › en › blog › sa-talks-integration-of-microsoft-defender-xdr-and-microsoft-sentinel
Integration of Microsoft Defender XDR and Microsoft Sentinel
March 27, 2025 - eCloudvalley Digital Technology
Sonne's Cloud
blog.sonnes.cloud › home › general › software › cool tools › microsoft defender xdr – unified security operations platform (sentinel and defender)
Microsoft Defender XDR – Unified Security Operations Platform (Sentinel and Defender) – Blog - Sonne´s Cloud
April 4, 2024 - It seamlessly integrates the full suite of features from a leading cloud-native security information and event management (SIEM) system, a comprehensive extended detection and response (XDR) platform, and AI tailored specifically for cybersecurity. This amalgamation of capabilities truly delivers a unified experience for analysts in the security operations center (SOC). This exiting new public preview of Microsoft Defender is now accessible to users of both Microsoft Sentinel and Microsoft Defender XDR, consolidating these platforms into a single portal!
Microsoft Learn
learn.microsoft.com › en-us › azure › sentinel › whats-new
What's new in Microsoft Sentinel | Microsoft Learn
September 30, 2025 - Microsoft Sentinel's UEBA empowers SOC teams with AI-powered anomaly detection based on behavioral signals in your tenant. It helps prioritize threats using dynamic baselines, peer comparisons, and enriched entity profiles.
Microsoft
microsoft.com › home › unified security operations with microsoft sentinel and microsoft defender xdr
Microsoft Sentinel and Microsoft Defender XDR unify security operations | Microsoft Security Blog
July 23, 2025 - At Microsoft Ignite 2023, we announced that we’re bringing Microsoft Sentinel, which delivers intelligent security analytics and threat intelligence, and Microsoft Defender XDR, our extended detection and response (XDR) solution, into a unified security operations platform—providing more comprehensive features, automation, guided experiences, and curated threat intelligence.
Microsoft Learn
learn.microsoft.com › en-us › azure › sentinel › move-to-defender
Transition Your Microsoft Sentinel Environment to the Defender Portal | Microsoft Learn
July 29, 2025 - The functionalities of analytics rules remain the same, including creation, updating, and management through the wizard, repositories, and the Microsoft Sentinel API. Incident correlation and multi-stage attack detection also continue to work in the Defender portal. The alert correlation functionality managed by the Fusion analytics rule in the Azure portal is handled by the Defender XDR engine in the Defender portal, which consolidates all signals in one place.
Hybridbrothers
hybridbrothers.com › transition-from-microsoft-sentinel-to-defender-xdr-practical-challenges
https://hybridbrothers.com/posts/transition-from-microsoft-sentinel-to-defender-xdr-practical-challenges/
July 4, 2025 - Microsoft Security Blog covering Defender XDR, Sentinel, Entra ID, and more
Microsoft
microsoft.com › en-us › security › business › siem-and-xdr › microsoft-defender-xdr
Microsoft Defender XDR | Microsoft Security
Microsoft Defender XDR is an XDR platform that provides security across your multiplatform endpoints, hybrid identities, email, collaboration tools, and cloud apps. It uses incident-level visibility across the cyberattack chain, automatic cyberattack disruption, and unified security and access ...
SentinelOne
sentinelone.com › cybersecurity-101 › endpoint-security › azure-xdr
Azure XDR: What Is It and How to Set Up
October 2, 2025 - Azure XDR (extended detection and response) is Microsoft’s solution for unifying security across an organization. Traditional tools like antivirus, EDR, and SIEM often work separately, each focusing on only part of a threat. However, Azure XDR integrates data from many sources—like endpoints, networks, emails, and cloud applications—using Azure Sentinel...