Key implementation platform

Microsoft Sentinel for identity monitoring

Bring identity, application and digital-trust signals into Sentinel with context that supports investigation and response.

Ingestion model

Context connects collection to response.

How identity signals become operational monitoringSignals from identity systems, applications, digital credentials, Delegance and custom systems move through supported collection and normalisation into Microsoft Sentinel or another selected monitoring platform, analytics, alerts and incidents.01SIGNAL SOURCESIdentity · apps · trust02CONNECTORS / INGESTSupported collection03NORMALISEEntity + event context04MONITORING PLATFORMSentinel or selected tool05ANALYTICSDetection hypotheses06ALERTS / INCIDENTSAssessment + ownershipHow identity signals become operational monitoringSignals from identity systems, applications, digital credentials, Delegance and custom systems move through supported collection and normalisation into Microsoft Sentinel or another selected monitoring platform, analytics, alerts and incidents.01SIGNAL SOURCESIdentity · apps · trust02CONNECTORS / INGESTSupported collection03NORMALISEEntity + event context04MONITORING PLATFORMSentinel or selected tool05ANALYTICSDetection hypotheses06ALERTS / INCIDENTSAssessment + ownership
Microsoft Sentinel is a major supported implementation platform, not a mandatory dependency for every Vigilance engagement.
01

A strong identity data plane

MAITS can integrate Entra signals, directory events, access changes, application telemetry, credential lifecycle events and custom systems into Microsoft Sentinel.

02

Normalise for correlation

Source-specific fields become consistent entities and event concepts so analytics can connect the same identity, resource, authority or action across systems.

03

Analytics and incidents

Detection logic should create explainable alerts with enough evidence for triage. Related alerts can be correlated into incidents that have severity, ownership and a response path.

04

Platform and capability are distinct

Sentinel is the SIEM and data platform; Vigilance is the assurance capability MAITS builds using it—the analytics, context, incident ownership and reporting that Sentinel alone does not provide.

05

Sentinel is not mandatory

Vigilance can work with the monitoring platform appropriate to the engagement. Sentinel is a major MAITS capability, not a requirement imposed on every organisation.

Apply the model

Make the signal actionable.

Start with the risk, available telemetry, accountable owner and proportionate response.

Talk to MAITS →