Building blocks
Design goal
Give the security operations team reliable detection and response coverage without treating every available log source as equally valuable or equally worth retaining.
Architecture
Security data flows into Sentinel through supported connectors, analytics produce alerts and incidents, and automation rules can invoke Logic App playbooks.
Architecture decisions
Ingest intentionally
WhyPrioritize high-value security telemetry and control noisy sources to manage signal quality and cost.
Trade-offSelective ingestion improves signal quality and cost control, but overly aggressive filtering can remove telemetry needed for investigation or compliance.
Separate detection from response
WhyUse analytics for detection and automation/playbooks for repeatable response workflows.
Trade-offSeparating analytics from automation keeps detections understandable, but introduces playbook ownership, permissions, testing, and failure-handling requirements.
Security
Protect the control and data paths deliberately. Use least-privilege Sentinel roles, managed identities for playbooks where possible, and controlled access to automation resources and sensitive incident data.
Availability
Design for the failure domain that must be survived. Operational resilience depends on connector health, workspace governance, alerting, and tested response procedures rather than a single compute component.
Disaster recovery
Treat regional recovery as a separate operating state. Define how security operations continue if a data source, region, or dependent automation service is unavailable; retain critical logs according to compliance requirements.
Cost drivers
- GB/day ingestion
- interactive retention
- archive/search strategy
- Logic Apps executions
- data export
Design assumptions
- Data sources and retention requirements are known
- SOC ownership and escalation paths exist
Implementation plan
- Define workspace topology, daily ingestion assumptions, interactive retention, archive needs, and data ownership before enabling connectors broadly.
- Prioritize high-value identity, endpoint, network, cloud, and application sources instead of ingesting every available log by default.
- Create and tune analytics rules around actionable detections, including ownership, severity, suppression, and incident grouping.
- Use automation rules and Logic Apps only for response steps that are repeatable, permissioned, and safe to automate.
- Configure RBAC, connector-health monitoring, and ingestion-cost alerts, then run a controlled incident through detection, triage, automation, and closure.
Validate the design
- Confirm every critical connector reports healthy ingestion and investigate unexpected drops or volume spikes.
- Generate a controlled event that should match a representative analytic rule and confirm an incident is created as expected.
- Run a playbook against a safe test incident and verify permissions, branching, and failure handling.
- Confirm interactive/archive retention and RBAC match the operating model and that ingestion remains inside the expected cost envelope.