Home / Insights

Insights & resources

Practical guidance for SOC leads, MSSP operators and security engineers who run Microsoft Sentinel and Defender XDR every day.

Guidance for Microsoft Sentinel
Automation8 min readFeatured

When can an AI agent close an alert on its own?

A practical way to decide which Sentinel alert classes are safe to auto-close: shadow mode, per-class accuracy, sample audits, and what should reset trust.

Read article
Latest guidance

Written by practitioners, for the people who run the SOC.

No articles in this category yet.

Industry news

Latest from the security press

Stay ahead

The monthly Sentinel operations briefing

One short email a month for people who run Sentinel.

  • New detections and tuning ideas worth stealing
  • Changes to Sentinel and Defender XDR that affect operations
  • One KQL query you can run the same day
Get the briefing Mention “briefing” in the message and we'll add you. No spam.