Call to action: update older Microsoft Sentinel content as code
Update
Microsoft Sentinel Updates
2.8KFollower
Software, firmware and hardware updates
Here you will find all software, firmware, and hardware updates from Microsoft Sentinel. Stay up to date and follow this product – you will be automatically notified of updates.
Generate playbooks using AI in Microsoft Sentinel (preview)
UpdateNew Entity Behavior Analytics (UEBA) widget in the Defender portal home page (Preview)
UpdateUEBA behaviors layer aggregates actionable insights from raw logs in near-real time (Preview)
UpdateNew Entity Behavior Analytics (UEBA) experiences in the Defender portal (Preview)
UpdateCall to action: update queries and automation
UpdateExport STIX threat intelligence objects (Preview)
UpdateMicrosoft Sentinel is evolving into a SIEM and platform
UpdateNew data sources for enhanced User and Entity Behavior Analytics (UEBA)
UpdateEdit workbooks directly in the Microsoft Defender portal (Preview)
UpdateMicrosoft Sentinel data lake (preview)
UpdateFor new customers only: Automatic onboarding and redirection to the Microsoft Defender portal
UpdateNo limit on the number of workspaces you can onboard to the Defender portal
UpdateMicrosoft Sentinel in the Defender portal to be retired July 2026
UpdateSummary rule templates now in public preview
UpdateConnector Documentation consolidation
UpdateCodeless Connector Platform (CCP) has been renamed to Codeless Connector Framework (CCF).
UpdateAll Microsoft Sentinel use cases generally available in the Defender portal
UpdateUnified IdentityInfo table
UpdateRisk-based recommendations (Preview)
UpdateSOC optimization support for unused columns (Preview)
UpdateSecurity Copilot generates incident summaries in Microsoft Sentinel in the Azure portal (Preview)
UpdateMulti workspace and multitenant support for Microsoft Sentinel in the Defender portal (preview)
UpdateAgentless connection to SAP now in public preview
UpdateOptimize threat intelligence feeds with ingestion rules
UpdateThreat intelligence upload API now supports more STIX objects
UpdateBicep template support for repositories (Preview)
UpdateMicrosoft Sentinel availability in Microsoft Defender portal*
UpdateNew SOC optimization recommendation based on similar organizations (Preview)
UpdateWas the content helpful to you?
