Microsoft has announced significant enhancements to its Sentinel Security Information and Event Management (SIEM) platform, introducing advanced agentic capabilities and a unified data lake to address the evolving landscape of AI-driven cybersecurity threats. The latest upgrades enable Sentinel to operate more autonomously, allowing it to respond to cyber threats with minimal human intervention. Central to these improvements is the adoption of graph-based context, which allows the platform to map and analyze the interconnections within a network, providing a holistic view of potential attack paths and relationships between digital assets. This graph-based approach is designed to empower Security Copilot agents, which leverage AI to assist security teams in threat detection and response. The general availability of the Sentinel data lake provides a cloud-native, purpose-built repository for ingesting, managing, and analyzing vast amounts of security data from diverse sources. By integrating structured and semi-structured signals, Sentinel builds a rich, contextual understanding of an organization’s digital estate, enhancing the ability to detect subtle attack patterns and correlate signals across domains. The platform’s semantic access and agentic orchestration features allow defenders to utilize AI agents not only within Security Copilot but also in developer environments such as VS Code with GitHub Copilot. With these capabilities, security teams can retroactively hunt for attacker behaviors over historical data, automatically trigger detections based on the latest adversary tradecraft, and surface high-fidelity alerts. Integration with other Microsoft security tools, such as Defender and Purview, ensures that graph-powered context is available within familiar workflows, streamlining the process of tracing attack paths, understanding the impact of incidents, and prioritizing response actions. The enhancements are part of Microsoft’s broader strategy to capitalize on the industry’s transition to AI-powered cybersecurity, positioning Sentinel as a central platform for modern security operations. These developments aim to provide organizations with greater operational resilience by leveraging AI-driven automation and advanced analytics. The unified data lake and agentic features are expected to improve visibility, accelerate incident response, and reduce the burden on human analysts. Microsoft’s focus on agentic security platforms reflects the growing need for autonomous, context-aware solutions in the face of increasingly sophisticated cyber threats. The public preview of Sentinel Graph and the Model Context Protocol (MCP) server further extends the platform’s capabilities, offering new tools for defenders to correlate data and orchestrate AI-driven responses. Overall, the upgraded Sentinel platform represents a significant step forward in the integration of AI and automation within enterprise cybersecurity operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft announced an expansion of Microsoft Sentinel into an agentic security platform with a unified data lake, positioning the product to address AI-era cybersecurity operations.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.