Azure Sentinel Preview (Feb 2019): Microsoft Enters the Cloud SIEM Market
Retrospective: this article looks back at events from February 2019, written in 2026 with the benefit of hindsight.
On February 28, 2019, Microsoft announced Azure Sentinel in preview — a cloud-native security information and event management (SIEM) service built on Azure Log Analytics. It became generally available in September 2019 and is now called Microsoft Sentinel.
What it offered
- Cloud-native scale: no servers to manage; storage and compute scale automatically.
- Built-in connectors for Microsoft sources (Azure AD, Office 365, Microsoft security products) and many third-party sources, including AWS CloudTrail and firewalls.
- Kusto Query Language (KQL) for analytics and hunting.
- Built-in analytics rules, workbooks and playbooks using Logic Apps for automated response.
- Pay-as-you-go pricing based on data ingested, with some Microsoft data sources free.
Why it mattered
Traditional SIEMs required expensive hardware, licenses and specialist administrators. Many mid-sized organizations had no SIEM at all. Sentinel lowered the barrier: a team could connect Microsoft 365 and Azure logs within an hour and start with built-in detections.
The trade-offs
Cloud SIEM shifted the cost model from fixed infrastructure to data volume. Organizations that ingested everything without planning saw large bills. Cost management — choosing data sources, filtering and using cheaper storage tiers — became a core skill.
In hindsight
Sentinel became one of the most widely adopted cloud SIEMs, especially among Microsoft-centric organizations. It later moved into the unified Microsoft Defender portal alongside XDR, and added a data lake tier for lower-cost long-term storage. The 2019 lesson still applies: start with the data sources that give the most security value per gigabyte, and grow from there.
- How to Plan a Microsoft Sentinel Deployment: Workspaces, Connectors and Costs How-To & Hardening
- Sentinel Data Connector Priority Checklist How-To & Hardening
- CIO Brief: Cloud-Native SIEM vs. Legacy SIEM — The Cost and Coverage Trade-Off CIO Briefings