Notifications and device scope
An alert, an incident, a response action, and a threat analytics report are different signals. Configure recipients and filters around each shift’s needs and test delivery. A test email confirms email delivery, not a complete detection. For device groups, check conditions and rank: a device matching several groups belongs to the highest-ranked one. Connect analyst access to Entra groups with the appropriate role. Before deleting a group, inspect dependent notifications. A seemingly administrative change can leave the on-call team without notifications.
Protection, telemetry, and version changes
Advanced features enable capabilities such as network indicators and live response, subject to product prerequisites. Enabling an option does not automatically grant permissions or install missing sensors. ASR rules address risky behaviors; for a legacy process, assess Audit events and test a scoped move to Block. AIR documentation announces that from September 1, 2026, separate investigations and manual triggering are unavailable: capabilities have been integrated into antivirus protection. Do not turn historical AIR instructions into a new runbook. Distinguish this change from automatic response to correlated XDR attacks and verify the capability actually available in the environment.
Additional endpoint event collection
Custom data collection, in preview in the inspected reference, adds telemetry to default collection. Define the table, action, filters, and devices through dynamic tags; confirm the selected Sentinel workspace. To investigate access to an application folder, start with relevant devices and events, measure volume, and inspect received fields. A broad filter can create cost and noise without answering the hypothesis. Record collection stop criteria and who reviews continued need. Distinguish these endpoint rules from Azure Monitor Agent DCRs: their purposes and configuration differ.
Windows, Azure, and application logs
With direct Windows Security Events collection through AMA, many rules use SecurityEvent. With Windows Event Forwarding, WEC receives events and AMA on the collector sends them to WindowsEvent. If a rule reads the first table, events in the second are insufficient: adapt and test the query or choose the appropriate connector. For Azure Activity, define scope and destination through the connector and Azure Policy; for resource-specific logs, inspect diagnostic settings and categories. For an application log file, its custom table, DCR, and transformation must agree on schema and event time. Test with an identifiable record from the source.
Retention tied to data use
Before reducing cost, list detections, workbooks, and investigations using each table. Analytics supports operational analysis and detection; Data Lake supports historical storage and analysis through its own mechanisms. Moving data to a cheaper tier can interrupt queries and rules dependent on Analytics. For example, 90 days of Analytics retention and 180 days of total retention leave the older half in the lake. Increasing retention does not recover already removed data. Distinguish supported XDR tables and their ingestion: do not promise that a new period automatically applies to every table in every product.
Dashboards and demonstrable optimization
A workbook should answer a concrete decision: which sources stopped sending data, which groups concentrate alerts, or where waiting is growing. Confirm workspace, period, and units for each visualization. Zero may mean an incorrect filter or missing data. SOC optimization recommendations help identify gaps and underused data but require contextual assessment. Before removing a source apparently unused by detections, check investigation dependencies and operational needs. After the change, compare coverage, noise, cost, and response capability. Bring the committee a demonstrable observation and an owner for the next review.
Choosing detections and interpreting indicators
A scheduled rule evaluates its query according to timing configuration; NRT runs more frequently and uses ingestion time with its own delay. NRT does not eliminate delays before data arrives. An imported threat-intelligence indicator yields a useful match only when type, validity, normalization, and telemetry fit the rule. Model-based anomalies highlight deviations, including legitimate operational changes. Compare baseline, context, and other evidence before declaring an attack. A release increasing connections may explain a deviation, but that explanation needs confirmation. Record how the rule was tested and how it will be tuned.
In a fictional project, a cost reduction moves logs used by detections. Acceptance depends on demonstrating that critical scenarios remain observable.
Common pitfalls
Email as proof of detection; retention as recovery of deleted data; unscoped groups; the old AIR experience as a current procedure.
Related topics: Investigating across Microsoft services · Hunting with the lake, graphs, and notebooks
Deliver a verifiable chain: source, table, rule, action, owner, and evidence.
Reference: Sentinel data tiers and retention · SC-200 objectives effective 2026-07-28; Microsoft product documentation reviewed 2026-10-01; 2026-10-21 English update compared separately