Microsoft security architecture
The Microsoft security stack is rarely a single product decision. Sentinel, Defender, Purview and Entra overlap, duplicate each other's telemetry and bill in different ways — the value is in designing them as one system rather than four procurement exercises.
Engagements typically start with the workspace and tenant topology, because those decisions are expensive to reverse, then work outwards through log source onboarding, detection content, access model and data protection policy.
What it covers
- Sentinel workspace topology, retention and commitment tier modelling
- Log source onboarding — Entra ID, Defender, firewall, activity logs, third-party APIs
- Analytics rules, automation rules and SOAR playbooks
- RBAC and PIM access model, including Sentinel unified RBAC
- Defender for Cloud plan selection, Azure Policy deployment and CSPM posture
- Purview data labelling, sensitivity policy mapping and DLP integration
- Deduplication design where Defender XDR and Defender for Cloud both feed Sentinel