← Azure projects

Azure · Security Design

Microsoft Sentinel SOC Architecture

Build a Microsoft Sentinel operating model that ingests high-value telemetry, turns detections into incidents, automates repeatable response, and controls retention cost.

PlatformAzure
DomainSecurity
LevelAdvanced
Last reviewed2026-09-19
Use whenDesign a centralized security operations platform that ingests priority telemetry, detects threats, and orchestrates repeatable incident response.
Key decisionIngest intentionally
Primary servicesMicrosoft Sentinel · Log Analytics · Data Connectors
Cost focusGB/day ingestion
On this page

Building blocks

Microsoft SentinelLog AnalyticsData ConnectorsAnalytics RulesAutomation RulesLogic AppsMicrosoft Defender XDR

Design goal

Give the security operations team reliable detection and response coverage without treating every available log source as equally valuable or equally worth retaining.

Architecture

Security data flows into Sentinel through supported connectors, analytics produce alerts and incidents, and automation rules can invoke Logic App playbooks.

Security SourcesMicrosoft SentinelIncidentsAutomation /PlaybooksSOC
Security Sources
Microsoft Sentinel
Incidents
Automation / Playbooks
SOC

Architecture decisions

Decision

Ingest intentionally

Why

Prioritize high-value security telemetry and control noisy sources to manage signal quality and cost.

Trade-off

Selective ingestion improves signal quality and cost control, but overly aggressive filtering can remove telemetry needed for investigation or compliance.

Decision

Separate detection from response

Why

Use analytics for detection and automation/playbooks for repeatable response workflows.

Trade-off

Separating analytics from automation keeps detections understandable, but introduces playbook ownership, permissions, testing, and failure-handling requirements.

Security

Protect the control and data paths deliberately. Use least-privilege Sentinel roles, managed identities for playbooks where possible, and controlled access to automation resources and sensitive incident data.

Availability

Design for the failure domain that must be survived. Operational resilience depends on connector health, workspace governance, alerting, and tested response procedures rather than a single compute component.

Disaster recovery

Treat regional recovery as a separate operating state. Define how security operations continue if a data source, region, or dependent automation service is unavailable; retain critical logs according to compliance requirements.

Cost drivers

  • GB/day ingestion
  • interactive retention
  • archive/search strategy
  • Logic Apps executions
  • data export

Design assumptions

  • Data sources and retention requirements are known
  • SOC ownership and escalation paths exist

Implementation plan

  1. Define workspace topology, daily ingestion assumptions, interactive retention, archive needs, and data ownership before enabling connectors broadly.
  2. Prioritize high-value identity, endpoint, network, cloud, and application sources instead of ingesting every available log by default.
  3. Create and tune analytics rules around actionable detections, including ownership, severity, suppression, and incident grouping.
  4. Use automation rules and Logic Apps only for response steps that are repeatable, permissioned, and safe to automate.
  5. Configure RBAC, connector-health monitoring, and ingestion-cost alerts, then run a controlled incident through detection, triage, automation, and closure.

Validate the design

  • Confirm every critical connector reports healthy ingestion and investigate unexpected drops or volume spikes.
  • Generate a controlled event that should match a representative analytic rule and confirm an incident is created as expected.
  • Run a playbook against a safe test incident and verify permissions, branching, and failure handling.
  • Confirm interactive/archive retention and RBAC match the operating model and that ingestion remains inside the expected cost envelope.

Architecture basis

Continue a learning path