https://store-images.s-microsoft.com/image/apps.56937.986cc3cf-4de7-4282-80da-7dce62797bbe.fe78e0da-21fd-4fdc-99b0-512eebc3c17d.a71bd2e6-83bd-47d8-94e3-17ba7d797147

Edensoft Microsoft Sentinel 2 Weeks Implementation

伊登软件

Deploy Microsoft Sentinel to unify signals and automate security operations in the cloud.

Microsoft Sentinel provides a cloud‑native SIEM and SOAR platform that unifies signals across your environment, delivers deep visibility into your security posture, and enables real‑time threat detection, investigation, and automated response. This two‑week engagement accelerates your Sentinel implementation through collaborative delivery. We will design the workspace, onboard high‑priority data sources, enable analytics and UEBA/Fusion capabilities, establish incident response automation, and equip your SOC team with hands‑on skills and operating procedures for day‑to‑day defense.

Detailed Agenda: Week 1: • Kick‑off meeting: align expectations, confirm scope and schedule. • Workspace design & setup: plan architecture, roles, and permissions. • Core component deployment: configure priority data connectors, analytics rules, automation rules, and initial playbooks.

Week 2: • Enable UEBA, configure cost management, and retention policies. • Conduct hands‑on security operations training on monitoring, investigation, and response workflows. • Share operational best practices for ongoing optimization.

Supported Connectors: • Azure Activity Logs • Microsoft Entra ID Protection • Office 365 Audit Logs (Sharepoint, Exchange and Teams) • Microsoft Defender XDR • Microsoft Defender for Cloud • Microsoft Defender for Office 365 • Microsoft Defender for Identity • Microsoft Defender for Cloud Apps • Microsoft Defender for Endpoint • Microsoft Defender for IoT • Windows Security Events • Linux Syslog

สรุปย่อ

https://store-images.s-microsoft.com/image/apps.54533.986cc3cf-4de7-4282-80da-7dce62797bbe.fe78e0da-21fd-4fdc-99b0-512eebc3c17d.b4581c57-cff5-4e4d-b75e-f8e18e01d86d