microsoft sentinel — Virtualization Review

microsoft sentinel — Virtualization Review

By By Paul Schnackenburg03/02/2026
Publication Date: 2026-03-02 00:00:00

In-Depth

The Evolution of a SIEM

Popular software products have interesting lifecycles, particularly in today’s cloudy world, where customer driven change requests can bring new features quickly.

The difference between on-premises software’s update cadence measured in years and cloud service changes measured in months or weeks means that just like scientists using fruit flies and their short lifespans for testing changes over generations, we can see the evolutionary changes in services as they mature.

In this article I’ll look at Microsoft Sentinel, originally released as Azure Sentinel back in 2019, follow up article here in 2021. We’ll cover the evolution, briefly look at the competition from other SIEMs, and what’s new, such as a Graph data interface, a built-in MCP server, data lake, unification with Defender XDR, migration tools from other SIEMS, Copilot for Security and AI agents, the Security Store and more.

Introduction
Microsoft Sentinel is a cloud-based Security Information and Event Management (SIEM), now six years in market, used by over 25,000 organizations. Forrester sees it as a leader in “Security Analytics Platforms,” and Gartner sees it as a leader in the Magic QuadrantTM , both in 2025 (and earlier…