Microsoft unveils Azure Sentinel, a new cloud service that allows customers to view and respond to security alerts and threats across corporate networks
Tom Krazit / GeekWire :
Context & Ripple Effects
Azure Sentinel is Microsoft's move to turn security monitoring itself into a cloud service — a SIEM that lives in Azure rather than in a customer's data center, letting security teams view and respond to alerts across corporate networks from one place. It extends a security build-out Microsoft has been running for years, from the Cyber Defense Operations Center and Enterprise Cybersecurity Group it stood up in 2015 to Cloud App Security built on the Adallom acquisition going generally available in 2016.
What makes the launch notable is where it points: by September Sentinel had reached general availability priced per gigabyte ingested, and four years later Microsoft folded it into a unified security operations platform alongside Security Copilot and Defender XDR. The 2019 unveiling is the origin point of that consolidation.
First-order effects
- Corporate security teams get a cloud-native alternative to on-premises SIEMs, paying for alert collection and response as an Azure service instead of running their own log-management infrastructure.
- Microsoft's existing security stack — Defender, Cloud App Security, the Cyber Defense Operations Center — gains a central analytics layer, making Sentinel the hub customers buy the rest around.
Second-order effects
- Incumbent SIEM vendors face pressure to match consumption-based cloud pricing; Sentinel's per-gigabyte model ($2.46/GB at general availability) turns pricing into a competitive weapon against license-based rivals.
- Every gigabyte customers ingest deepens their Azure commitment, so Sentinel functions as both a security product and an Azure workload driver — pulling security budgets into the same bill as compute and storage.
Third-order effects
- If the pattern holds, security operations consolidates into vendor-owned platforms: Microsoft's later fusion of Sentinel, Security Copilot, and Defender XDR after the Secure Future Initiative launched following major Azure attacks shows the endpoint — AI-assisted response run largely inside one provider's cloud.
- That consolidation raises the structural question regulators and buyers will eventually weigh: how much of corporate threat detection should sit with the same company whose infrastructure is being defended.
The trend: Security information management is migrating from customer-run appliances to hyperscaler platforms, with Microsoft using Sentinel to make its cloud the default place enterprises detect and respond to threats.