Microsoft has rolled out a series of significant enhancements to Azure Sentinel, its cloud-native security information and event management (SIEM) platform, with a strong focus on improving threat detection capabilities across multi-cloud environments. The updates solidify Sentinel as a leading choice for organizations managing security across Azure, AWS, and Google Cloud simultaneously.
Expanded Multi-Cloud Data Connectors
The latest release introduces native data connectors for AWS CloudTrail, Amazon GuardDuty, Google Cloud Platform audit logs, and Google Workspace activity logs. These connectors allow security teams to ingest, correlate, and analyze events from all three major cloud providers within a single unified dashboard, eliminating the blind spots that plague organizations with heterogeneous cloud footprints.
Previously, integrating non-Azure cloud sources required custom ingestion pipelines using Azure Functions or Logic Apps. The new native connectors reduce deployment time from days to minutes while ensuring consistent data formatting and reliable delivery.
Advanced Fusion Detection Engine
Azure Sentinel Fusion detection engine has received a major upgrade that leverages machine learning to identify multi-stage attack campaigns that span multiple cloud providers. The engine correlates low-fidelity signals from different sources, such as a suspicious login in AWS followed by lateral movement in Azure Active Directory, to surface high-confidence incidents that individual detection rules would miss.
MITRE ATT&CK Coverage Improvements
Microsoft has mapped over 200 new detection rules to the MITRE ATT&CK framework, bringing total coverage to more than 500 techniques across cloud and hybrid environments. Security teams can now visualize their detection coverage against the ATT&CK matrix directly within the Sentinel interface, identifying gaps and prioritizing rule development accordingly.
Kusto Query Language Enhancements
The Kusto Query Language (KQL), which powers Sentinel analytics, has been expanded with new operators specifically designed for security investigations. New time-series analysis functions help analysts detect anomalous patterns in authentication logs, while graph-based query capabilities enable relationship mapping between entities such as users, devices, IP addresses, and cloud resources.
These KQL improvements are complemented by a new natural language query interface powered by Microsoft Copilot for Security, allowing less experienced analysts to conduct sophisticated threat hunts using plain English prompts that are automatically translated into optimized KQL queries.
Cost Optimization and Scalability
Recognizing that data volume is the primary cost driver for SIEM platforms, Microsoft has introduced new data tiering options. Organizations can now route high-volume, low-security-value logs to a basic log tier at significantly reduced cost while maintaining full analytics capabilities for critical security data. An auxiliary log tier provides long-term retention for compliance at minimal expense.
These pricing innovations, combined with commitment-based discount tiers, make Sentinel increasingly competitive against legacy on-premises SIEM solutions. Organizations migrating from Splunk or IBM QRadar report cost savings of 30 to 50 percent while gaining the scalability benefits of a fully cloud-native architecture.
As multi-cloud adoption accelerates across enterprises, the ability to detect and respond to threats that traverse cloud boundaries becomes essential. Azure Sentinel enhancements position Microsoft as a formidable contender in the rapidly evolving cloud security analytics market.




