<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Microsoft Sentinel on Anything About IT</title><link>https://www.verboon.info/tags/microsoft-sentinel/</link><description>Recent content in Microsoft Sentinel on Anything About IT</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 06 Sep 2025 15:32:18 +0000</lastBuildDate><atom:link href="https://www.verboon.info/tags/microsoft-sentinel/index.xml" rel="self" type="application/rss+xml"/><item><title>Collect Microsoft Entra Connect Sync Audit Events</title><link>https://www.verboon.info/2025/09/collect-microsoft-entra-connect-sync-audit-events/</link><pubDate>Sat, 06 Sep 2025 15:32:18 +0000</pubDate><guid>https://www.verboon.info/2025/09/collect-microsoft-entra-connect-sync-audit-events/</guid><description>&lt;p&gt;Microsoft Entra Connect Sync now includes an admin audit logging capability that is enabled by default. This gives organizations visibility into configuration changes performed by Global Administrators, Hybrid Administrators, and local server administrators.&lt;/p&gt;
&lt;p&gt;In this post, we walk through how to forward those Microsoft Entra Connect Sync audit events into Microsoft Sentinel for centralized monitoring and investigation.&lt;/p&gt;
&lt;h2 id="check-the-microsoft-entra-connect-sync-version"&gt;Check the Microsoft Entra Connect Sync Version&lt;/h2&gt;
&lt;p&gt;In the Entra portal, go to Entra Connect &amp;gt; Connect Sync &amp;gt; Microsoft Entra Connect Health &amp;gt; Sync Services &amp;gt; your service &amp;gt; Microsoft Entra Connect Servers &amp;gt; your server &amp;gt; Properties &amp;gt; Synchronization.&lt;/p&gt;</description></item><item><title>Monitoring Windows built-in local security Groups with Microsoft Defender XDR or Sentinel</title><link>https://www.verboon.info/2024/02/monitoring-windows-built-in-local-security-groups-with-microsoft-defender-xdr-or-sentinel/</link><pubDate>Sun, 04 Feb 2024 21:50:36 +0000</pubDate><guid>https://www.verboon.info/2024/02/monitoring-windows-built-in-local-security-groups-with-microsoft-defender-xdr-or-sentinel/</guid><description>&lt;h1 id="windows-built-in-local-security-groups"&gt;Windows Built-in local security groups&lt;/h1&gt;
&lt;p&gt;Windows has several built-in local security groups that are designed to manage permissions and access rights on a computer. These groups are predefined by Windows, and each group has specific rights and permissions. The exact groups available can vary depending on the version of Windows you&amp;rsquo;re using or the features that are enabled, but here&amp;rsquo;s a general overview of the most commonly found built-in local security groups in Windows systems:&lt;/p&gt;</description></item><item><title>How to analyze Microsoft Sentinel Daily Cap Alerts - AADNonInteractiveUserSignInLogs</title><link>https://www.verboon.info/2022/05/how-to-analyze-microsoft-sentinel-daily-cap-alerts-aadnoninteractiveusersigninlogs/</link><pubDate>Fri, 20 May 2022 20:18:50 +0000</pubDate><guid>https://www.verboon.info/2022/05/how-to-analyze-microsoft-sentinel-daily-cap-alerts-aadnoninteractiveusersigninlogs/</guid><description>&lt;p&gt;To avoid unplanned costs for Microsoft Sentinel, it is recommended to set a daily cap and create an analytics rule that triggers an alert when the daily cap is reached. Microsoft has published general guidance for monitoring costs &lt;a href="https://learn.microsoft.com/azure/sentinel/billing-monitor-costs"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In the past months I have deployed a number of Microsoft Sentinel instances and in many cases the root cause for reaching the daily cap was related to data ingested into the AADNonInteractiveUserSignInLogs table. When analyzing the data we often found an individual user that created an unusually high amount of events. This can happen for various reasons such as:&lt;/p&gt;</description></item></channel></rss>