Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Technology partner

Microsoft Sentinel and Defender integrator in Switzerland

We design and operate Microsoft detection architectures — Microsoft Sentinel for correlation, the Microsoft Defender family for collection and response on each perimeter.

Why this vendor

Many organisations already hold the Microsoft licences that carry these products without having enabled them. It is the most frequent situation we meet, and it calls for a simple answer: before proposing a purchase, we look at what you already own. It is not unusual for a tenant to contain most of what it needs, dormant for want of configuration.

The technical interest of the whole lies in how close the sensors sit to what they observe. Microsoft Defender for Identity reads Active Directory signals, Microsoft Defender for Office 365 sees messages before delivery, Microsoft Defender for Endpoint is built into the operating system. That closeness produces signals a third-party agent obtains less well, or later.

Microsoft Sentinel — long called Azure Sentinel — handles correlation and archiving. It is also where costs run away if nobody attends to them: the bill follows the volume ingested, and a connector enabled without thought can cost more than the licence it complements. Designing the collection is therefore part of the project, as much as the detection is.

Our value is not in the enablement, which takes a few days. It is in the detection use cases, in noise reduction, and in the triage process — without which a console produces alerts nobody handles. We operate these platforms daily for our managed SOC clients.

Microsoft
What we bring
  • A review of what your licences already cover
  • Collection design and control of the cost
  • Detection use cases and noise reduction
  • Triage and response process
  • Operations by our managed SOC
Vendor website
Diagram

Sensors, one correlation

Microsoft architecture: Sentinel for correlation and four Defender perimeters Endpoints andserversDefender for EndpointEmail andcollaborationDefender for Office 365IdentitiesDefender for IdentitySaaS and cloudapplicationsDefender for Cloud AppsDefender for CloudMicrosoft SentinelSIEM and central correlationMicrosoft Sentinel
Each Defender module covers a perimeter and feeds Microsoft Sentinel, where the signals meet to form one incident.

The products we integrate

The diagram chips use the short form; below are the full names. All belong to the Microsoft Defender XDR family, around Microsoft Sentinel.

Endpoints and servers

Microsoft Defender for Endpoint provides protection and detection on workstations and servers, with the ability to isolate a machine remotely. Being built into the system, it sees behaviours that an agent installed afterwards observes less well. Tuning the exclusions is the sensitive point: too broad, and they open precisely the path an attacker is looking for.

Microsoft Defender for Endpoint

Email and collaboration

Microsoft Defender for Office 365 protects email, SharePoint and Teams — attachments detonated, links checked at click time, and the ability to pull back after delivery a message that turned out to be malicious. That last capability is what counts on the day a campaign gets through: the question is no longer filtering, but catching up.

Microsoft Defender for Office 365

Identities

Microsoft Defender for Identity reads on-premises Active Directory signals and detects the techniques specific to it — privilege reconnaissance, lateral movement, Kerberos ticket manipulation. On an old directory it is often the block that reveals the most, because nobody was looking there.

Microsoft Defender for Identity

SaaS and cloud applications

Microsoft Defender for Cloud Apps brings visibility over SaaS applications and services used without ever having been declared. Microsoft Defender for Cloud addresses the posture of the cloud resources themselves — weak configurations, public exposure, drift after an automated deployment.

Microsoft Defender for Cloud AppsMicrosoft Defender for Cloud
The correlation point

Microsoft Sentinel gathers these signals and adds your non-Microsoft sources. It is where three individually unremarkable events — an unusual sign-in, a mailbox rule created, a file encrypted — become a single incident. It is also where the cost is steered, the bill following the volume ingested.

Microsoft Sentinel
Our approach

How we proceed

We start with what you already have. Many tenants carry licences that cover the essentials without the products ever having been enabled.

Microsoft integration approach, from tenant audit to operations ScopingImplementationDuration01Tenantaudit02Collectiondesign03Detectionuse cases04Rolloutin waves05NoisereductionOperationsor handover
Noise reduction is not a finishing step: a detection that alerts too often stops being read, and the arrangement dies quietly.
Frequently asked questions

Frequently asked questions

Not always, and it is the first thing we check. Depending on your Microsoft agreement, part of these products may already be covered without ever having been enabled. We establish the gap between what you pay for and what you use before proposing anything for purchase.

It costs what you give it to ingest. A connector enabled without thought can weigh more than the licence it complements. Designing the collection — which sources, at what granularity, with what retention, and which ones to move to cheap storage — is part of the project and is steered over time.

Yes. The Defender modules export their signals to a third-party SIEM, and many organisations keep what they have for contractual or skills reasons. You lose part of the native correlation, which is a legitimate trade-off — it just has to be made explicitly rather than suffered.

Yes. We operate these platforms daily as part of our managed SOC: monitoring, alert qualification, response and continuous improvement of the rules. Or through a handover, if your teams take it on.

Licences paid for, but enabled?

Describe your tenant — we start with the gap between what you pay for and what you use.