Defender XDR's legacy AAD sign-in tables are being replaced by EntraIdSignInEvents and EntraIdSpnSignInEvents. Portal content migrates automatically - your repos and scripts don't.
Read more →
The final phase of MDTI convergence is GA. Premium threat intelligence is now included with Defender XDR and Sentinel - here's what changed, what's retired, and what to check.
Read more →
Hit the 512 Sentinel analytics rule limit? If you're in the unified Defender portal, custom detections offer a practical workaround without paying for a dedicated cluster.
Read more →
Complete guide to Microsoft Sentinel's data tiers: Analytics, Data Lake, Auxiliary, and Basic. Real-world cost optimization strategies and implementation insights.
Read more →
The Sentinel Data Lake preview isn't showing up in every portal yet. Here's what the announcement means for auxiliary logs and multi-client environments.
Read more →
Learn how to deploy and use the Microsoft Sentinel Attack Range to validate your security detections with real-world attack scenarios.
Read more →
Set up Microsoft Sentinel to minimize costs, meet compliance requirements, and create a manageable environment for security teams.
Read on Medium →
Deploy a Flask application on Azure to interact with Azure AI endpoints using Deployment Center and local git.
Read on Medium →
Honest reviews of free and paid tools, with setup guides and integration tips from real-world usage.
Read on Medium →
How to transition from IT to security by building on your existing skills and knowledge.
Read on Medium →
Common detection rule mistakes and how to build alerts that actually catch bad guys without waking you up at 3am.
Read on Medium →
Step-by-step guide to setting up a home lab for security testing using only free tools.
Read on Medium →