How To Setup Microsoft Sentinel

Step 1: Sign-in to Azure Portal

  1. Visit https://portal.azure.com
  2. Sign in using your Azure Account

Step 2: Create or Select a Workspace for Log Analytics

Microsoft Sentinel will require a Log Analytics workspace.

  1. In the Azure Portal, search for Log Analytics workspaces.
  2. Click on “Create“.
  3. Fill in the required fields:
    • Subscription Select the subscription you want.
    • Group Resource: Add a new group or select one already existing.
    • Specify a unique naming for the workspace.
    • Region Choose the appropriate Azure region.
  4. Click «Review + Creating». Next, click «Create».

Step 3: Install Microsoft Sentinel

  1. Return to Azure portal’s home page after creating workspace.
  2. Find “Microsoft Sentinel” by searching.
  3. Click on “Create“.
  4. In the past, there were many ways to help you. Microsoft Sentinel: Create a Microsoft Sentinel page:
    • Select the subscription.
    • Select the workspace for Log Analytics that you just created.
  5. Click ‘Review + Creating’. Next, click ‘Create.

Step 4: Add Data connectors

To gather information on security:

  1. Navigate from the Microsoft Sentinel workspace to , “Data connectors”.
  2. Select the datasources you want to link (e.g. Azure, Office 365 or Firewall). ).
  3. Follow the instructions provided by each connector in order to configure and authorise data ingestion.

Step 5: Create Analytics Rules Playbooks and Rules (Optional).

  • Analytics Rule: Automate alerting by conditions.
  • Playbooks Automate actions with Logic Apps.

Create these by going to ‘Analysis’, and ‘Automation.

Step 6: Monitor and Respond

  • Use the «Overview» page, HTML1«Incidents» page, and HTML2«Hunting» page to monitor security updates.
  • Investigate an incident and respond with the integrated tools.