Your analysts approve. Our agents do the rest.

CyberSentinal turns manual, multi-tenant Microsoft Sentinel and Defender XDR operations into an agentic SOC. Agents triage every incident, investigate across tenants with KQL, draft the response and notify the client. Your team keeps the final say.

Built for the Microsoft security stack
Microsoft Sentinel Microsoft Defender XDR Microsoft Entra ID Azure Lighthouse Azure Logic Apps
Every incident
Triaged as it arrives, 24/7, in every tenant
Minutes
From alert to evidence-backed verdict
One queue
All your tenants through Azure Lighthouse
Human-gated
Risky actions wait for analyst approval
The problem

Multi-tenant Sentinel doesn't scale on analyst hours.

Each new tenant adds more alerts, more runbooks and more client emails. Most of that work is the same every time: pull sign-in logs, check the IP, check the device, close it or escalate it, then write it up.

Today Manual SOC

  • Analysts switch between tenants one incident at a time
  • The same enrichment KQL is rewritten for every alert
  • Benign noise buries the incidents that matter
  • Client notifications and SLA reports are written by hand
  • Headcount grows in step with every tenant you sign

With CyberSentinal Agentic SOC

  • One queue across every tenant, already triaged
  • Agents run the investigation and attach their evidence
  • Proven benign patterns close themselves, with a comment
  • Client notifications are drafted, approved and sent through your PSA
  • Analysts spend their time on decisions and threat hunting
Overview

Every tenant's Sentinel overview, in one place.

The views your analysts already know from Microsoft Sentinel, rolled up across every customer workspace, with a clear split between what the agents handled and what needed a person.

CyberSentinal Search incidents, tenants, entities… SO
Home › Operations

Overview

Time range: Last 7 days Tenants: All (14) Severity: All
Incidents
2,184
Last 7 days, all tenants
Closed by agents
1,902
87% of incidents, with evidence
Needed an analyst
282
13%, approved or escalated
Median time to verdict
3m 40s
From alert to decision
Incidents per day
Closed by agentsNeeded an analyst
Show as table
Incidents by tenant
MITRE ATT&CK tactics
FewerMore
Data connectors
  • Microsoft Entra IDHealthy
  • Microsoft Defender XDRHealthy
  • Office 365Healthy
  • Azure ActivityHealthy
  • Syslog · ContosoDelayed 4h
Illustrative data · fictitious tenantsRefreshes every 5 minutes
Platform

A team of agents for every stage of the incident.

Each agent has one job, a narrow set of permissions and a written policy per tenant. Together they cover the incident from the first alert to the client report.

Triage agent

Picks up every new Sentinel and Defender incident, removes duplicates, links related alerts, sets the owner and ranks it by real risk.

DedupCorrelationPrioritisation

Investigation agent

Writes and runs KQL across SigninLogs, AuditLogs, Defender tables and threat intel, then returns a verdict with the evidence attached.

KQLEntity graphThreat intel

Response agent

Prepares containment actions such as isolating a device, revoking sessions, disabling a user or blocking an IOC. Each action runs only if policy allows it or an analyst approves.

DefenderEntra IDApproval gates

Communications agent

Writes the client notification in your house style and opens or updates the ticket in your PSA. It sends only after the incident is approved.

ZohoConnectWiseHaloPSAServiceNow

Multi-tenant control plane

Manages every customer workspace through Azure Lighthouse, with a runbook, autonomy level and SLA set per tenant.

LighthousePer-tenant policySLA tracking

Tuning & reporting agent

Finds analytics rules that keep producing benign alerts and proposes tuning changes. It also writes the monthly report for each client.

Rule tuningCoverageClient reports
How it works

From alert to closed incident, step by step.

Agents do the repetitive work. Analysts step in where judgment is needed, and every step is recorded on the Sentinel incident.

1

Ingest

New incident in any tenant's Sentinel workspace

Agent
2

Enrich

Entities, asset context, threat intel, history

Agent
3

Investigate

KQL across sign-ins, endpoints, mail and cloud

Agent
4

Verdict

Benign, suspicious or true positive, with evidence

Agent
5

Approve & act

Containment within policy, or sent to an analyst

Human gate
6

Notify & learn

Client ticket, report and tuning feedback

Agent
Inside an investigation

Evidence you can audit, not a black box.

Every verdict shows the queries the agent ran, what they returned and how it reached its conclusion. Analysts review the work in seconds instead of redoing it.

  • Queries you can seeThe KQL is attached to the incident, ready to re-run in Sentinel.
  • Your runbooksAgents follow your SOC procedures for each tenant, not a generic playbook.
  • One-click decisionsApprove, edit or reject the proposed action from the incident or from Teams.
Graduated autonomy

Autonomy is earned per tenant, not switched on all at once.

Every tenant starts at level 1. The agent earns more autonomy one alert class at a time, once its accuracy has been measured on your own incidents.

LEVEL 1

Recommend

Agents investigate and suggest a verdict. Analysts make every decision.

LEVEL 2

Approve

Agents prepare the full response. One click from an analyst runs it.

LEVEL 3

Auto-close benign

Proven benign patterns close themselves with a documented comment.

LEVEL 4

Auto-respond

Pre-approved containment runs immediately, within limits you set.

Full audit trailEvery query, decision and action is logged on the incident.
Per-tenant policyEach client sets its own limits, actions and approvers.
Kill switchDrop any tenant back to level 1 instantly.
Least privilegeScoped Lighthouse roles and managed identities.
Who it's for

Built for teams running Sentinel at scale.

MSSPs & MSPs

Multi-tenant Sentinel via Azure Lighthouse

Take on more tenants without hiring a new analyst for each one, and give every client the same quality of response.

  • One agent-triaged queue across every customer workspace
  • Client-branded notifications and monthly reports
  • PSA ticketing and SLA tracking per tenant
  • Better margin on every tenant you manage

Enterprise SOCs

Multiple subsidiaries, regions or workspaces

Give a small team round-the-clock coverage across subsidiaries and regions, without adding night shifts.

  • 24/7 triage with escalation to on-call in Teams
  • Consistent runbooks across business units
  • Fewer benign alerts through continuous rule tuning
  • Audit-ready evidence for every incident
Microsoft SentinelIncidents & KQL
Microsoft Defender XDREndpoint · Identity · O365
Microsoft Entra IDUsers & sessions
Microsoft TeamsApprovals & on-call
PSA / ITSMZoho · ConnectWise · Halo
Threat intelTI feeds & IOCs
Security & data

Your data stays in your tenants.

An agent with access to dozens of tenants has to be locked down more tightly than any analyst. The platform is built on that assumption.

SOC 2 Type IIIndependently audited · report on request
Least-privilege accessScoped Azure Lighthouse delegations and managed identities. No shared credentials.
Logs stay in placeQueries run in each tenant's workspace. Logs are not copied into another data lake.
No training on your dataClient telemetry is never used to train models.
Tamper-evident logsEvery agent action is attributable, timestamped and exportable for audits.
Pricing

Start with a pilot. Scale by tenant.

Choose whether we run it for you or your team runs it. Pricing is per tenant, so cost follows the work.

Pilot

30-day proof

Fixed fee
1-3 tenants · 30 days
  • Agentic onboarding through Azure Lighthouse, no client-side deployment needed
  • Agents run alongside your analysts at level 1
  • Accuracy and time-saved report at day 30
Request a pilot
Most popular
Managed

Agentic MDR

$500per tenant / month
We operate it for you
1-3 tenants$500 per tenant
4-10 tenants$450 per tenant
11+ tenantsTalk to us
  • Agents plus CyberSentinal analysts on approvals
  • 24/7 coverage with defined SLAs
  • Client notifications and monthly reporting
  • Rule tuning and detection engineering
Get started
Platform

Self-operated

Talk to us
Per tenant / month · your SOC runs it
  • Full agent platform for your analysts
  • Custom runbooks and autonomy policies
  • PSA, Teams and white-label reporting
Talk to us
FAQ

Common questions

Is CyberSentinal SOC 2 compliant?

Yes. CyberSentinal has a SOC 2 Type II report from an independent auditor covering the controls behind our platform and managed service. Ask us through the contact form and we will share the report under NDA.

How is this different from Microsoft Security Copilot?

Copilot helps one analyst understand one incident. CyberSentinal runs the whole SOC workflow across many tenants: per-client runbooks, approval gates, PSA ticketing, client notifications and SLA reporting. The two work together.

Do agents take actions without a human?

Only when you allow it. Every tenant starts at level 1 (recommend only). Auto-close and auto-respond are enabled one alert class at a time, after accuracy has been measured on your own incidents. You can drop back to level 1 at any time.

What access do you need?

A scoped Azure Lighthouse delegation to each tenant's Sentinel workspace. A pilot starts with read access plus incident comments. Response permissions are added only when a tenant moves to a higher level.

Does our log data leave our tenants?

Queries run inside each customer's own Log Analytics workspace. Only the investigation summary and the evidence needed for the verdict are attached to the incident. Client data is never used to train models.

Which ticketing systems do you support?

Zoho Desk, ConnectWise, HaloPSA and ServiceNow, plus email and Microsoft Teams. Other systems can be connected through webhooks or Logic Apps.

Get started

See it on your own incidents.

Tell us how many tenants you run and how your SOC works today. We'll reply within one business day with a pilot plan.

  • 30-minute walkthroughA live demo on realistic multi-tenant Sentinel data.
  • Read-only pilotAgents shadow your analysts. Nothing changes until you approve it.
  • Measured resultsAccuracy, time saved and benign-closure rate, reported per tenant.

Or email info@cybersentinal.tech

We'll only use your details to reply to this request.