Detect and stop threats with Sentinel and Defender
CloudServus architects run Sentinel inside the unified Microsoft Defender portal, so your team works from one incident queue instead of switching tools.
Talk to an Expert →Sentinel now runs inside the Defender portal
Microsoft folded Sentinel's SIEM capabilities into the Microsoft Defender portal, so your SOC works from one incident queue instead of switching between Azure and Microsoft 365 tools. Alerts from endpoints, identities, email, and cloud workloads correlate automatically. Microsoft plans to retire the Azure portal experience for Sentinel after March 31, 2027.
If your team is still running Sentinel in the Azure portal, that date is the reason to plan the move now. CloudServus architects handle the transition: workspace onboarding, connector remapping, and analytics rule validation, so detection coverage doesn't drop during the switch.
What the unified platform covers
Unified incident response
- One queue. Sentinel and Defender XDR alerts land in a single incident queue instead of two separate ones.
- Attack story view. Investigation pages combine identity, device, and cloud signals into one timeline.
AI-assisted investigation
- Security Copilot. Generates incident summaries and guided response steps inside the portal.
- Hunting support. Copilot helps build hunting queries instead of your team hand-writing every one.
SOC optimization
- Guided recommendations. The portal flags coverage gaps and cost-saving changes to your analytics rules.
- API access. Pull optimization data programmatically for your own reporting.
Cost and data controls
- Data lake tiering. Move older logs to lower-cost storage without losing search access.
- Shared schema. Sentinel and Defender data use one normalized schema, so queries don't need translation.
Built for mid-market IT teams, not enterprise SOCs
You don't need a round-the-clock security operations center to run Sentinel well. CloudServus configures analytics rules, data connectors, and automation playbooks around the alerts your team can act on, not a stock template sized for a much bigger security staff.
We tune ingestion first, so you're not paying to store logs nobody queries. Then we layer in automation for the incidents that repeat. The goal is a monitoring setup your IT director can run without a dedicated security analyst on staff.
Ongoing tuning, not a one-time deployment
Threat patterns change, and so does your environment. We review analytics rules and automation on a set cadence, so detections keep pace with new connectors, new users, and new attack techniques instead of drifting stale.
Your team gets a direct line to the CloudServus architects who built the environment, not a ticket queue.
Ready to move to the unified Defender portal?
Talk to a CloudServus architect about your Sentinel setup, whether you're starting fresh or transitioning off the Azure portal before support ends.
Talk to an Expert →