Behind the Build with Gigamon: Enriching Microsoft Sentinel with Network-Derived Telemetry
July 1, 2026Partner Blog | From Microsoft Build to AI implementation: Build the skills to lead Frontier Transformation
July 1, 2026Welcome back to What’s new in Microsoft Sentinel. In June, Sentinel SIEM’s Advanced Security Information Model (ASIM) broadens its normalization, so one analytic rule can reach more sources with less per-source work and, additionally, two new ASIM schemas can now bring asset inventory and AI agent telemetry into common form. In Microsoft Sentinel data lake, the Agent Identities Asset Connector adds the identity context behind your AI agents, helping you see who owns an agent and what permissions it holds. In Sentinel MCP, graph tools help security teams investigate threats and optimize security coverage by visualizing relationships across identities, devices, alerts, and signals in a unified graph experience.
Read on for the details, and explore the resources at the end to go deeper.
Sentinel innovations:
Sentinel SIEM
Advanced Security Information Model (ASIM) parsers and schemas [Generally available]
The Advanced Security Information Model (ASIM) in Sentinel normalizes logs into common schemas, so one analytic rule can cover many sources without managing each native schema. ASIM coverage has expanded across more Azure services, broader AWS CloudTrail activity, and a range of third-party firewall, identity, and proxy products, so your detections reach more of your environment with less per-source work. Two schemas also join ASIM: Asset Entities normalizes asset inventory so you can correlate files and assets across investigations, and AI Agent Events normalizes telemetry from AI-driven workflows and autonomous agents. Browse the ASIM parsers on GitHub to explore, file issues, or contribute. Learn more in our blog.
Sentinel transition to Defender blog series
By March 31, 2027, all Microsoft Sentinel customers transition to Defender. This six-part series guides you through moving your Sentinel experience from the Azure portal to Defender, where SIEM, XDR, threat intelligence, AI, and automation come together in one experience. Your analytics rules, playbooks, workbooks, log analytics workspace, and access assignments all carry forward while the operational layer becomes more connected and intelligent. Starting early matters because you realize the benefits sooner, including a unified incident queue, cross-product correlation, Security Copilot, Sentinel data lake, and SOC optimization. Across the six-part blog series you get 1) the strategic shift, 2) the anatomy of incident and data changes, 3) detection and automation, 4) the governance shift across roles and access, 5) a readiness playbook with the adoption helper and cost guidance, and 6) a look at the AI-first SOC. Each part stands alone, so you can read in order or jump to what matters most to you.
Sentinel data lake
Agent Identities Asset Connector [Public preview]
The Agent Identities Asset Connector brings identity context for AI agents into Sentinel. Activity connectors like Agent 365 and Microsoft 365 Copilot already show you what AI agents do, but activity alone cannot tell you who owns an agent, what permissions it holds, or how it is governed. This connector fills that gap with four asset tables covering agent owners, agent identities, agent blueprints, and the service principals tied to those blueprints. Together they form a connected agent identity graph you can trace from owner to identity to blueprint to permissions to the resources an agent touches. Joining this asset data with activity data in Sentinel data lake lets you detect anomalous behavior relative to permissions, spot over-permissioned or misconfigured agents, and follow full execution chains for end-to-end traceability. To get started, install the Agent 365 and Microsoft 365 Copilot solutions in Content Hub and enable the asset and activity connectors. Learn more.
Sentinel MCP
Sentinel MCP graph tools [Public preview]
Microsoft Security Graph MCP tools, recently introduced in the Microsoft Sentinel MCP Server data exploration collection helps security teams investigate threats by exploring relationships between identities and device assets, and threat and activity signals ingested by data connectors and surfaced by analytic rules. Starting from an alert, analysts can follow the exposure path across connected entities — tracing lateral movement, understanding blast radius, and identifying configuration gaps — all from a single, interactive workspace. The tool provides a clear graph view that highlights dependencies and makes it easier to understand how content interacts across your environment. This helps security teams assess coverage, optimize content deployment, and identify areas that may need tuning or additional data sources. Executing graph queries via the MCP tools will trigger the graph meter. Learn more.
Microsoft Security Store
Partner testimonials from Adaquest and Glueckkanja
For partners like Adaquest and Glueckkanja, the Microsoft Security Store helps not only put their years of knowledge, understanding, and best practices into a scalable, packaged solution, it gives them the ability to democratize that expertise and take it to market globally. Security Store operationalizes their expertise as always-on defenses — discoverable, deployable, and driving real outcomes inside the tools that security teams rely on every day.
See how the Security Store is helping security teams act on threats faster with the right solutions and to be ready when it matters most:
- Watch: Adaquest unlocks faster response times for customers (testimonial)
- Watch: Glueckkanja builds agents with purpose (testimonial)
Additional resources
Blogs and documentation:
- The Advanced Security Information Model (ASIM) Process Event normalization schema reference
- How BlueVoyant’s ASIM-First Strategy Simplifies Threat Detection in Microsoft Sentinel
- Migrate Sentinel to Defender – Why It Is a Security Architecture Decision, Not Just a Portal Change
- Connect Microsoft Sentinel to the Microsoft Defender portal
- Agent 365 connector: Monitor, hunt, and investigate AI agent activity in Microsoft Sentinel
- Get started with Microsoft Sentinel MCP server
Upcoming webinars and events:
- July 15–16: Microsoft Virtual Training Day: Predict and Defend Against Cybersecurity Threats
- July 22: Microsoft Security Immersion Event: Shadow Hunter
- July 23-24: Microsoft Virtual Training Day: Introduction to Microsoft Security
- July 28: Tech Brief: Modernize security operations with a unified platform
- July 29: Security Immersion Event: Into the Breach
Stay connected
Check back each month for the latest innovations, updates, and events to ensure you’re getting the most out of Microsoft Sentinel. We’ll see you in the next edition!