Sentinel already knows which tables you pay to ingest and never once query in a detection. It will tell you if you ask.
The recommendations run in two directions at once. One closes coverage gaps against named threats. The other stops you paying to ingest data that delivers no security value at all. Everything recalculates every twenty four hours against your own workspace, and coverage is scored by comparing your active analytics rules against what the Microsoft research team recommends for that scenario. Our job is turning that page into a weekly rhythm your team actually keeps, for organizations across the United States.

- Every 24 hoursRecommendations recalculated
- Over 75 percentWhat counts as high coverage
- Two directionsCoverage gaps and data value
- Mar 31, 2027Azure portal support for Sentinel ends
Seven reasons this is the most valuable screen in Sentinel and the one least likely to be open.
It names the tables you pay for and never detect on
The documented workflow is refreshingly plain. Find the tables showing low usage, which is the platform telling you nothing is detecting on them, then look at how much that unused data costs and how large it is. From there you have two honest options. Either write analytics rules so the table starts earning its keep, or adjust your commitment tier and stop paying for data you were never going to use.
Threat-based coverage, measured against Microsoft research
Coverage here means your active analytics rule count set against the number the Microsoft research team recommends for that particular threat scenario. That comparison is worth far more than a count of your own rules taken in isolation, because it measures the gap between the detections you happen to have and the detections the threat genuinely calls for.
Three coverage bands, and most organizations are not in the top one
The bands are simple. High is more than seventy five percent of recommended rules activated. Medium runs from thirty to seventy four percent. Low is anything from zero to twenty nine. What makes them useful is that they are reported per threat scenario, so a business can sit at high on one and low on another. Knowing which is which is precisely what a sensible tuning plan is built on.
Three kinds of coverage recommendation, not one
Three categories exist. Threat-based recommendations propose controls that close gaps against particular attack types. AI MITRE ATT&CK recommendations propose tagging that closes gaps against the framework. Risk-based recommendations propose controls addressing categories of business risk. That last group is the one that converts most readily into language a board will engage with.
Recalculated every 24 hours, and completed automatically
Everything recalculates on a twenty four hour cycle, so what you see tracks your environment instead of freezing a review from last quarter. There is a neat detail behind that too: if something changes in your estate that makes a recommendation moot, the optimization completes itself and moves to the completed tab, and a banner tells you how many did so since you last looked.
A status workflow, so it works as a queue
Every recommendation carries a state you set yourself: complete, in progress, active or dismissed, with a route to send feedback back to Microsoft. Anything dismissed or completed can be brought back, and when it is, the platform recalculates it against current values and actions, which takes up to an hour. Those states are what turn a dashboard into a queue a team can genuinely work through week after week.
A broader view lives in the Defender portal, and there is a date on the calendar
Once your workspace is onboarded to the Defender portal, the optimizations widen to take in coverage from across the Microsoft security services rather than looking at Sentinel by itself. Attached to that is a firm deadline. From April 2027, following the end of support on March 31 of that year, Sentinel will exist only in the Defender portal and no longer in the Azure portal.
After March 31, 2027, Sentinel exists only in the Defender portal.
Nothing about this is advisory. It is a published retirement date, and it should change the order in which any Sentinel work over the next eighteen months gets done.
- The wording is unambiguous. Support for Microsoft Sentinel in the Azure portal ends on March 31, 2027, after which it is available only in the Microsoft Defender portal. Everyone still using the Azure portal at that point gets redirected, and the Defender portal becomes the only place Sentinel exists.
- The guidance to anyone still working in the Azure portal is to begin planning the move now, both to keep the transition smooth and to start benefiting from the unified security operations experience sooner.
- For this feature in particular there is a reason not to wait for the deadline. Onboard the workspace to the Defender portal and the optimizations widen immediately, drawing on coverage from across the Microsoft security services rather than Sentinel alone.
- Put plainly, every hour of tuning, runbook writing, training or documentation you invest in the Azure portal between now and the deadline is an hour you will spend again afterwards. Moving portals first costs less than moving portals last.
Four disciplines that convert a page of recommendations into a lower bill and sharper detection.
We decide per table, not by volume
Low usage does not mean waste. Quite often the correct response is to write an analytics rule so the data starts earning its place, which is the first option the documentation puts in front of you. Cutting the biggest tables purely because they are the biggest is how a business ends up without the telemetry it needs most during the next incident, and that is a decision almost impossible to undo once the data is gone.
We prioritize Low band scenarios that match your sector
Because the bands are reported per scenario, holding zero to twenty nine percent of recommended rules is a materially different position from holding thirty to seventy four. Treating every gap as equally urgent spreads a team thin across all of them. Concentrating on the Low band scenarios that plausibly apply to your business, whether that is a regional bank, a freight operator or a hospital group, puts the effort where the risk sits.
We install solutions rather than isolated rule templates
There is a documented catch here. Install an analytics rule template from the Content hub without installing its solution and the solution shows only that one template. Install the whole solution and everything else it carries becomes visible, which typically means workbooks, hunting queries and playbooks nobody would otherwise have found.
We make it monthly, because it recalculates daily
Daily refresh, plus recommendations that close themselves out when the environment moves underneath them, favors a light touch every month over a deep dive once a year. What actually keeps the coverage bands and the ingestion trend heading in the right direction is treating the status workflow as a real queue with somebody named against it.
Four phases, in which the savings found early usually pay for the coverage work that follows.
- 01Week 1
Establish the baseline and the portal position
We establish three things: what you are ingesting today, which analytics rules are live, and where each threat scenario falls on the coverage bands. If the workspace still sits in the Azure portal, the transition plan comes before any of that, both because the Defender portal widens optimizations to span the Microsoft security services and because the Azure portal now has a published end date.
- Ingestion baseline over the published 90 day window
- Coverage band recorded per threat scenario
- Defender portal onboarding status established
- Roles and permissions confirmed against Sentinel requirements
- 02Weeks 2 to 4
Work the data value recommendations
Every table flagged as low usage, which means nothing is detecting on it, gets reviewed individually with its size and cost on screen. Each one ends in a decision: write an analytics rule so the data justifies itself, or move the plan. Neither answer is the correct one by default. The genuinely wrong move is deciding on volume alone.
- Every low usage table reviewed with a documented decision
- New analytics rules written wherever the data turns out to be genuinely worth detecting on
- Commitment tier reassessed where it does not
- Savings quantified so they can fund the next phase
- 03Weeks 5 to 8
Close the coverage gaps that matter
We begin with the scenarios sitting in the Low band, reading the spider charts across tactics and techniques together with the prefiltered MITRE ATT&CK view to locate the real gap rather than the apparent one. Rules come out of the Content hub, and we install complete solutions instead of individual templates so everything else those solutions carry becomes visible.
- Low band scenarios prioritized by relevance to your sector
- Content hub solutions installed rather than isolated templates
- New rules tuned before they reach the analyst queue
- Risk-based recommendations mapped for board reporting
- 04Ongoing
Make it a monthly rhythm
Because the recommendations recalculate daily, the return comes from looking often rather than looking hard. A monthly pass through whatever is active, treating the status workflow as a real queue, keeps both coverage and cost drifting the right way without anyone having to run a large project every year.
- Monthly review with a named owner
- Status used as a queue: complete, in progress, dismissed
- Automatic completions reviewed rather than ignored
- Coverage bands and ingestion trend reported to the business
Six US situations where an optimization review pays for itself quickly.
A financial firm whose ingestion bill has grown every quarter
Connectors accumulated across several years, every one of them defensible when it was added, none revisited afterwards. The data value recommendations name each table nothing is detecting on and put its size and cost beside it. That turns an awkward conversation with finance into a concrete list of decisions, each with somebody responsible for making it.
A company that inherited a Sentinel workspace from a project
An integrator built it, tuned it, handed over the documentation and moved on. In the time since, nobody has set the live analytics rules against what the research team recommends for the threats this particular business faces. The coverage bands answer that scenario by scenario in a single afternoon, with no manual gap assessment required.
A firm that needs to explain security coverage to a board
Because risk-based recommendations propose controls against categories of business risk, they are a far easier conversation than tactics and techniques ever are. Put them alongside the coverage bands and the recent optimization value figure and you have a report a non-technical audience can both follow and act on.
An operator still running Sentinel in the Azure portal
March 31, 2027 is the published cut-off, and after it Sentinel exists only in the Defender portal. There is a reason to move well before then rather than simply meeting the date. Inside the Defender portal, optimizations take in coverage from across the Microsoft security services instead of Sentinel by itself, which is both a broader and a more actionable picture.
An organization whose analysts are drowning
Bolting on detections without tuning them makes the problem worse, which is exactly why coverage work and alert quality have to happen in the same exercise. Take the Low band scenarios deliberately, tune every new rule before it is allowed near the analyst queue, and dismiss recommendations that genuinely do not apply to you. Coverage climbs; the queue does not climb with it.
A business preparing for a security audit or insurance renewal
Presenting coverage as a percentage of research-recommended rules for each threat scenario, backed by a written decision against every recommendation, puts you in a far better position at a SOC 2 audit or on an insurance questionnaire than handing over a list of enabled rules. The status workflow doubles as the record, showing what was assessed, what was acted on, and what was dismissed on purpose.
How US organizations run their Sentinel workspace.
| Feature | Optimized monthly | Deployed, never reviewed | Logs collected, few detections |
|---|---|---|---|
Coverage measured against research recommendations | Yes | No | No |
Gaps prioritized by threat scenario | Yes | No | No |
Unused tables identified | Yes | No | No |
Ingestion cost actively managed | Yes | Reactively | No |
MITRE coverage understood | Yes | Partly | No |
Risk-based view available to the board | Yes | No | No |
Recommendations worked as a queue | Yes | No | No |
Defender portal transition planned | Yes | Not yet | Not yet |
New content adopted as it appears | Yes | Rarely | No |
Cost trend visible to the business | Yes | At invoice time | At invoice time |
What each type tells you, and what to do about it.
Type
Threat-based coverage
- What Microsoft says it covers
- Proposes security controls that close coverage gaps against particular attack types
- What we do with it
- Start with any scenario sitting at Low, meaning you hold between zero and twenty nine percent of the recommended rules
Type
AI MITRE ATT&CK
- What Microsoft says it covers
- Suggests tagging that closes coverage gaps measured against the MITRE ATT&CK framework
- What we do with it
- The prefiltered MITRE page shows which tactics and techniques you genuinely have nothing against
Type
Risk-based coverage
- What Microsoft says it covers
- Proposes controls that close coverage gaps against categories of business risk
- What we do with it
- This is the category that survives translation into board language, so it belongs in the reporting pack
Type
Data value
- What Microsoft says it covers
- Improves how ingested data is used so it delivers security value, or points you at a data plan that fits better
- What we do with it
- Take each table on its merits: write a detection so it justifies itself, or move the plan
Type
Recent optimization value
- What Microsoft says it covers
- Value gained from recommendations you recently implemented
- What we do with it
- The figure that proves the tuning rhythm is holding, and worth putting in the monthly pack
Type
Data ingested
- What Microsoft says it covers
- Ninety days of total workspace ingestion, shown in the Defender portal
- What we do with it
- The trend line that turns an argument about ingestion cost into a discussion of evidence
Type
Optimization status
- What Microsoft says it covers
- The number of recommendations currently active, completed, and dismissed
- What we do with it
- Handled as a work queue reviewed weekly, rather than a dashboard somebody glances at
Five steps, and the first two usually pay for the rest.
- 1
Confirm access, portal position, and baseline
Nothing exotic is required, just the standard Sentinel roles and permissions. Working in the Defender portal does mean Sentinel has to be onboarded there, and that same onboarding is what widens optimizations to span the Microsoft security services. Before we change anything, we write down the ingestion baseline and the coverage band for every threat scenario.
- 2
Work the data value recommendations first
We locate the tables reporting low usage, which is the platform saying no detection touches them, and put the size and cost of that data on the table. Every one gets a decision: pull analytics rules from the Content hub so it earns its place, or change the plan. The savings are quantified deliberately, so they can be set directly against the cost of the coverage work.
- 3
Prioritize coverage gaps by band and by relevance
Scenarios in the Low band come first, meaning anywhere between zero and twenty nine percent of the recommended rules are live, filtered down to what plausibly applies in your industry. The spider charts across tactics and techniques, together with the prefiltered MITRE ATT&CK view, show where the gap genuinely sits rather than simply counting how many rules are absent.
- 4
Add content properly and tune before going live
Complete Content hub solutions go in rather than isolated templates, which keeps the workbooks, hunting queries and playbooks they carry visible instead of hidden. Each new rule is tuned before an analyst ever sees its output, on the principle that coverage paid for in alert fatigue is not coverage gained.
- 5
Establish the monthly rhythm and the reporting
With daily recalculation and recommendations that close themselves as the environment moves, what sustains this is a monthly pass rather than an annual project. The status workflow becomes a queue with a named owner behind it, and coverage bands, ingestion trend and recent optimization value all get reported. That is what keeps it alive once we are no longer involved.
What organizations ask about SOC optimization.
Fifteen questions worth answering about your Sentinel workspace.
Position
- Are you in the Defender portal yet?Azure portal support ends March 31, 2027.
- Who has the Sentinel roles required?Standard roles and permissions apply.
- When did anyone last review analytics rules?Usually the answer is at deployment.
- Is Content hub content installed as solutions?Templates alone hide the rest.
- Who owns the workspace day to day?Optimization needs an owner, not a project.
Cost
- What are you ingesting over 90 days?The Defender portal shows it directly.
- Which tables have no detection using them?That is the core data value finding.
- Is your commitment tier still the right one?It is a named recommended action.
- Would basic logs suit any table?Change plan is offered from the recommendation.
- Is anyone tracking ingestion trend?Otherwise cost conversations are anecdotal.
Coverage
- What is your coverage band per scenario?High, medium, or low, per threat.
- Which scenarios matter most to your sector?Prioritize those in the Low band.
- Do you look at the MITRE view?It is prefiltered per scenario.
- Are risk-based recommendations reported?They translate best for a board.
- Are new rules tuned before going live?Otherwise coverage costs you analyst hours.
The pages around this one.
Five minutes is all it takes. Open the page and read your coverage band.
Nearly every organization we work with discovers two things in that first sitting: a Low band on at least one threat scenario they genuinely care about, and at least one table they are paying to ingest that no detection has ever read.
Related Services
Explore more solutions that work great with this service
Microsoft Sentinel Analytics Rules
Sentinel detection engineering for US organizations: every enabled
Learn moreMicrosoft Sentinel Transition to the Defender Portal
Sentinel transition planning and delivery for US organizations ahead
Learn moreMicrosoft Sentinel
Cloud-native SIEM and threat intelligence
Learn moreSOC-as-a-Service
24/7 security operations delivered as a service
Learn moreManaged Security Services
Managed security services (MSS) for US businesses, delivered remotely
Learn moreMicrosoft Defender XDR Services
One incident queue across endpoint, email and identity
Learn more