{"id":100758,"date":"2019-09-24T18:11:45","date_gmt":"2019-09-24T18:11:45","guid":{"rendered":"https:\/\/news.microsoft.com\/?p=434519"},"modified":"2019-09-24T18:11:45","modified_gmt":"2019-09-24T18:11:45","slug":"now-generally-available-azure-sentinel-cloud-native-security-information-and-event-management-solution","status":"publish","type":"post","link":"https:\/\/sickgaming.net\/blog\/2019\/09\/24\/now-generally-available-azure-sentinel-cloud-native-security-information-and-event-management-solution\/","title":{"rendered":"Now generally available: Azure Sentinel\u2014cloud-native Security Information and Event Management solution"},"content":{"rendered":"<p>Machine learning enhanced with artificial intelligence (AI) holds great promise in addressing many of the global cyber challenges we see today. They give our cyber defenders the ability to identify, detect, and block malware, almost instantaneously. And together they give security admins the ability to deconflict tasks, separating the signal from the noise, allowing them to prioritize the most critical tasks. It is why today, I\u2019m pleased to announce that Azure Sentinel, a cloud-native SIEM that provides intelligent security analytics at cloud scale for enterprises of all sizes and workloads, is now generally available.<\/p>\n<p>Our goal has remained the same since <a href=\"https:\/\/blogs.microsoft.com\/blog\/2019\/02\/28\/announcing-new-cloud-based-technology-to-empower-cyber-defenders\/\" target=\"_blank\" rel=\"noopener noreferrer\">we first launched Microsoft Azure Sentinel in February<\/a>: empower security operations teams to help enhance the security posture of our customers. Traditional Security Information and Event Management (SIEM) solutions have not kept pace with the digital changes. I commonly hear from customers that they\u2019re spending more time with deployment and maintenance of SIEM solutions, which leaves them unable to properly handle the volume of data or the agility of adversaries.<\/p>\n<p>Recent research tells us that 70 percent of organizations continue to anchor their security analytics and operations with SIEM systems,<sup>1<\/sup> and 82 percent are committed to moving large volumes of applications and workloads to the public cloud.<sup>2<\/sup> Security analytics and operations technologies must lean in and help security analysts deal with the complexity, pace, and scale of their responsibilities. To accomplish this, 65 percent of organizations are leveraging new technologies for process automation\/orchestration, while 51 percent are adopting security analytics tools featuring machine learning algorithms.<sup>3<\/sup> This is exactly why we developed Azure Sentinel\u2014an SIEM re-invented in the cloud to address the modern challenges of security analytics.<\/p>\n<h3>Learning together<\/h3>\n<p>When we kicked off the public preview for Azure Sentinel, we were excited to learn and gain insight into the unique ways Azure Sentinel was helping organizations and defenders on a daily basis. We worked with our partners all along the way; listening, learning, and fine-tuning as we went. With feedback from 12,000 customers and more than two petabytes of data analysis, we were able to examine and dive deep into a large, complex, and diverse set of data. All of which had one thing in common: a need to empower their defenders to be more nimble and efficient when it comes to cybersecurity.<\/p>\n<p>Our work with RapidDeploy offers one compelling example of how Azure Sentinel is accomplishing this complex task. RapidDeploy creates cloud-based dispatch systems that help first responders act quickly to protect the public. There\u2019s a lot at stake, and the company\u2019s cloud-native platform must be secure against an array of serious cyberthreats. So when RapidDeploy implemented a SIEM system, it chose Azure Sentinel, one of the world\u2019s first cloud-native SIEMs.<\/p>\n<p>Microsoft recently sat down with Alex Kreilein, Chief Information Security Officer at RapidDeploy. Here\u2019s what he shared: \u201cWe build a platform that helps save lives. It does that by reducing incident response times and improving first responder safety by increasing their situational awareness.\u201d<\/p>\n<p>Now RapidDeploy uses the complete visibility, automated responses, fast deployment, and low total cost of ownership in Azure Sentinel to help it safeguard public safety systems.&nbsp;\u201cWith many SIEMs, deployment can take months,\u201d says Kreilein. \u201cDeploying Azure Sentinel took us minutes\u2014we just clicked the deployment button and we were done.\u201d<\/p>\n<p>Learn even more about our work with RapidDeploy by checking out <a href=\"https:\/\/aka.ms\/AA5ys3p\" target=\"_blank\" rel=\"noopener noreferrer\">the full story<\/a>.<\/p>\n<p>Another great example of a company finding results with Azure Sentinel is ASOS. As one of the world\u2019s largest online fashion retailers, ASOS knows they\u2019re a prime target for cybercrime. The company has a large security function spread across five teams and two sites\u2014but in the past, it was difficult for ASOS to gain a comprehensive view of cyberthreat activity. Now, using Azure Sentinel, ASOS has created a bird\u2019s-eye view of everything it needs to spot threats early, allowing it to proactively safeguard its business and its customers. And as a result, it has cut issue resolution times in half.<\/p>\n<p>\u201cThere are a lot of threats out there,\u201d says Stuart Gregg, Cyber Security Operations Lead at ASOS. \u201cYou\u2019ve got insider threats, account compromise, threats to our website and customer data, even physical security threats. We\u2019re constantly trying to defend ourselves and be more proactive in everything we do.\u201d<\/p>\n<p>Already using a range of Azure services, ASOS identified Azure Sentinel as a platform that could help it quickly and easily unite its data. This includes security data from <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/security-center\/\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Security Center<\/a> and <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/active-directory\/\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Active Directory (Azure AD)<\/a>, along with data from <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/enterprise\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft 365<\/a>. The result is a comprehensive view of its entire threat landscape.<\/p>\n<p>\u201cWe found Azure Sentinel easy to set up, and now we don\u2019t have to move data across separate systems,\u201d says Gregg. \u201cWe can literally click a few buttons and all our security solutions feed data into Azure Sentinel.\u201d<\/p>\n<p>Learn more about how ASOS has <a href=\"https:\/\/aka.ms\/AA5yz8g\" target=\"_blank\" rel=\"noopener noreferrer\">benefitted from Azure Sentinel<\/a>.<\/p>\n<p>RapidDeploy and ASOS are just two examples of how Azure Sentinel is helping businesses process data and telemetry into actionable security alerts for investigation and response. We have an active <a href=\"https:\/\/github.com\/Azure\/Azure-Sentinel\" target=\"_blank\" rel=\"noopener noreferrer\">GitHub community<\/a> of preview participants, partners, and even Microsoft\u2019s own security experts who are sharing new connectors, detections, hunting queries, and automation playbooks.<\/p>\n<p>With these design partners, we\u2019ve continued our innovation in Azure Sentinel. It starts from the ability to connect to any data source, whether in Azure or on-premises or even other clouds. We continue to add new connectors to different sources and more machine learning-based detections. Azure Sentinel will also integrate with Azure Lighthouse service, which will enable service providers and enterprise customers with the ability to view Azure Sentinel instances across different tenants in Azure.<\/p>\n<h3>Secure your organization<\/h3>\n<p>Now that Azure Sentinel has moved out of public preview and is generally available, there\u2019s never been a better time to see how it can help your business. Traditional on-premises SIEMs require a combination of infrastructure costs and software costs, all paired with annual commitments or inflexible contracts. We are removing those pain points, since Azure Sentinel is a cost-effective, cloud-native SIEM with predictable billing and flexible commitments.<\/p>\n<p>Infrastructure costs are reduced since you automatically scale resources as you need, and you only pay for what you use. Or you can save up to 60 percent compared to pay-as-you-go pricing by taking advantage of capacity reservation tiers. You receive predictable monthly bills and the flexibility to change capacity tier commitments every 31 days. On top of that, bringing in data from Office 365 audit logs, Azure activity logs and alerts from Microsoft Threat Protection solutions doesn\u2019t require any additional payments.<\/p>\n<p>Please join me for the <a href=\"https:\/\/info.microsoft.com\/Azure-Security-Expert-Series-Empower-Your-Security-Operations-with-Azure-Sentinel-Registration.html\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Security Expert Series<\/a> where we will focus on Azure Sentinel on Thursday, September 26, 2019, 10\u201311 AM Pacific Time. You\u2019ll learn more about these innovations and see real use cases on how Azure Sentinel helped detect previously undiscovered threats. We\u2019ll also discuss how Accenture and RapidDeploy are using Azure Sentinel to empower their security operations team.<\/p>\n<p><strong>Get started today with <\/strong><a href=\"https:\/\/aka.ms\/AzureSentinel\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Azure Sentinel<\/strong><\/a><strong>!<\/strong><\/p>\n<p><a href=\"https:\/\/aka.ms\/AA6330q\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-89883 size-full\" src=\"https:\/\/www.sickgaming.net\/blog\/wp-content\/uploads\/2019\/09\/now-generally-available-azure-sentinel-cloud-native-security-information-and-event-management-solution.png\" alt width=\"984\" height=\"561\"><\/a><\/p>\n<p><em><sup>1<\/sup> Source: ESG Research Survey, Security Analytics and Operations: Industry Trends in the Era of Cloud Computing, September 2019<br \/><\/em><em><sup>2<\/sup> Source: ESG Research Survey, Security Analytics and Operations: Industry Trends in the Era of Cloud Computing, September 2019<br \/><\/em><em><sup>3<\/sup> Source: ESG Research Survey, Security Analytics and Operations: Industry Trends in the Era of Cloud Computing, September 2019<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Machine learning enhanced with artificial intelligence (AI) holds great promise in addressing many of the global cyber challenges we see today. They give our cyber defenders the ability to identify, detect, and block malware, almost instantaneously. And together they give security admins the ability to deconflict tasks, separating the signal from the noise, allowing them [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":100759,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[54,50],"class_list":["post-100758","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-news","tag-azure","tag-recent-news"],"_links":{"self":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/posts\/100758","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/comments?post=100758"}],"version-history":[{"count":0,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/posts\/100758\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/media\/100759"}],"wp:attachment":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/media?parent=100758"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/categories?post=100758"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/tags?post=100758"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}