Microsoft Sentinel and Defender integrator in Switzerland
We design and operate Microsoft detection architectures — Microsoft Sentinel for correlation, the Microsoft Defender family for collection and response on each perimeter.
Why this vendor
Many organisations already hold the Microsoft licences that carry these products without having enabled them. It is the most frequent situation we meet, and it calls for a simple answer: before proposing a purchase, we look at what you already own. It is not unusual for a tenant to contain most of what it needs, dormant for want of configuration.
The technical interest of the whole lies in how close the sensors sit to what they observe. Microsoft Defender for Identity reads Active Directory signals, Microsoft Defender for Office 365 sees messages before delivery, Microsoft Defender for Endpoint is built into the operating system. That closeness produces signals a third-party agent obtains less well, or later.
Microsoft Sentinel — long called Azure Sentinel — handles correlation and archiving. It is also where costs run away if nobody attends to them: the bill follows the volume ingested, and a connector enabled without thought can cost more than the licence it complements. Designing the collection is therefore part of the project, as much as the detection is.
Our value is not in the enablement, which takes a few days. It is in the detection use cases, in noise reduction, and in the triage process — without which a console produces alerts nobody handles. We operate these platforms daily for our managed SOC clients.
- A review of what your licences already cover
- Collection design and control of the cost
- Detection use cases and noise reduction
- Triage and response process
- Operations by our managed SOC
Sensors, one correlation
The products we integrate
The diagram chips use the short form; below are the full names. All belong to the Microsoft Defender XDR family, around Microsoft Sentinel.
Endpoints and servers
Microsoft Defender for Endpoint provides protection and detection on workstations and servers, with the ability to isolate a machine remotely. Being built into the system, it sees behaviours that an agent installed afterwards observes less well. Tuning the exclusions is the sensitive point: too broad, and they open precisely the path an attacker is looking for.
Email and collaboration
Microsoft Defender for Office 365 protects email, SharePoint and Teams — attachments detonated, links checked at click time, and the ability to pull back after delivery a message that turned out to be malicious. That last capability is what counts on the day a campaign gets through: the question is no longer filtering, but catching up.
Identities
Microsoft Defender for Identity reads on-premises Active Directory signals and detects the techniques specific to it — privilege reconnaissance, lateral movement, Kerberos ticket manipulation. On an old directory it is often the block that reveals the most, because nobody was looking there.
SaaS and cloud applications
Microsoft Defender for Cloud Apps brings visibility over SaaS applications and services used without ever having been declared. Microsoft Defender for Cloud addresses the posture of the cloud resources themselves — weak configurations, public exposure, drift after an automated deployment.
Microsoft Sentinel gathers these signals and adds your non-Microsoft sources. It is where three individually unremarkable events — an unusual sign-in, a mailbox rule created, a file encrypted — become a single incident. It is also where the cost is steered, the bill following the volume ingested.
How we proceed
We start with what you already have. Many tenants carry licences that cover the essentials without the products ever having been enabled.
This service in practice
Frequently asked questions
Licences paid for, but enabled?
Describe your tenant — we start with the gap between what you pay for and what you use.