Copilot Readiness Is a Data Governance Project
Copilot does not create an oversharing problem. It makes the one you already have searchable. What to fix before you buy the licences.
Sentinel is a capable SIEM and a demanding one. What we learned about connectors, on-premises integration, cost tiers and the move into the Defender portal.

Microsoft Sentinel is a capable SIEM. Getting it running is a good deal harder than the demos suggest.
We wrote this after an implementation project and the lessons have held up. A few details have moved since, and we have flagged those as they come.
Sentinel looks like a single tool from the front end. Behind it sit Azure Monitor, Log Analytics, Logic Apps, Azure Functions and several others.
Each of those is a product in its own right, with its own pricing, its own limits and its own way of falling over. Configuring alerts turns out to be the easy part. The actual job is managing ingestion cost, query performance and automation runbooks across all of them.
Budget for that skill gap. It is the cost most Sentinel projects underestimate.
This is the biggest change since we first published.
Sentinel now sits in the Microsoft Defender portal next to Defender XDR, rather than in the Azure portal. Microsoft has been retiring the old Azure experience, so any runbook, training deck or screenshot written against it needs revisiting.
The unified view is genuinely better. Arriving at it halfway through a project is disruptive, so check where your tenant sits before anyone writes documentation.
Ingestion is where most of the early project time goes, and where a fair chunk of it goes twice.
You will repeatedly choose between a deprecated connector that still works and a preview connector that is not fully supported. Neither is comfortable when you are building something meant to run for years.
Microsoft has been consolidating on the Azure Monitor Agent and codeless connectors, which has improved matters, and the legacy agents are on the way out. Check what a connector is actually built on before you commit to it.
If you have on-premises infrastructure, and nearly everybody does, plan for real effort here.
Older systems need workarounds. The documentation is thin and occasionally wrong. Permissions are fiddly. Getting basic logs out of a legacy application can take days rather than hours.
Protect this line item in your plan. It needs infrastructure, security and application people working together, and it will not go faster because you spent more.
We found spelling mistakes in log event mappings for Microsoft’s own products. Event IDs that did not match the documentation. Fields missing or labelled wrongly.
That matters because your detection rules sit on top of those mappings. A rule built on a field that is quietly empty looks exactly like a rule that works.
So test every detection against real activity before you trust it. Generate the event, confirm the alert fires, then confirm the alert contains what you expected.
Sentinel charges per GB ingested, with commitment tiers that lower the rate when you can predict your volume. Three things are worth knowing before you sign anything.
Not every log needs the same tier. Analytics logs cost the most and support full detection and alerting. Cheaper tiers exist for high volume, low value data you mostly need during an investigation or for a compliance obligation. Sorting your sources across those tiers is the single biggest lever you have on cost.
Some Microsoft sources are free to ingest, including Office 365 audit logs, Azure activity logs and Defender XDR alerts. Entra ID sign-in and audit logs are not. That catches people out, because the free list is narrower than the marketing suggests.
Long-term retention is cheaper outside the analytics tier. Work out what you keep for detection and what you keep to satisfy an obligation, then price the two separately. There is more on this in Simplifying SIEM Pricing.
Once it runs, the value is real. Correlating Defender for Endpoint, Entra ID, Secure Score and vulnerability data in one place cuts investigation time in a way that is hard to argue with.
Just go in with your eyes open. Sentinel rewards a team that invests in it, and it punishes one that expected to switch it on.
Element Digital offers IT consulting services in Hobart. If you are planning a Sentinel deployment, get in touch.
Let us talk about what you are trying to achieve, no obligation, just a conversation.