AzureHow-To & HardeningRetrospectives

Sentinel Data Connector Priority Checklist

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from February 2019, written in 2026 with the benefit of hindsight.

Data connectors determine both what Microsoft Sentinel can detect and what it costs. Use this checklist to prioritize them.

Tier 1 — connect first

  • Microsoft Defender XDR (incidents, alerts and optionally advanced hunting data).
  • Microsoft Entra ID sign-in logs (interactive and non-interactive) and audit logs.
  • Microsoft 365 audit logs (Exchange, SharePoint, Teams).
  • Azure Activity logs for all subscriptions.
  • Microsoft Defender for Cloud alerts.

Tier 2 — connect next

  • AWS CloudTrail (via the S3 connector) if you use AWS.
  • Firewall and VPN logs (identify remote access and outbound threats).
  • Entra ID Protection risk events.
  • Key Vault and storage diagnostic logs for sensitive resources.

Tier 3 — connect for specific use cases

  • Windows security events from critical servers (domain controllers first).
  • DNS logs.
  • Web proxy logs.
  • Application and database logs for crown-jewel systems.

For every connector, confirm

  • The use case it supports.
  • Expected daily volume and cost.
  • Whether a cheaper storage tier is suitable.
  • Whether ingestion-time filtering can drop low-value fields or events.
  • Which analytics rules depend on it.

After connecting

  • Verify data arrives (check the table in Log Analytics).
  • Enable the matching analytics rules from Content Hub solutions.
  • Add a health alert if the connector stops sending data.
sentinel data connectors checklistAzure Sentinel preview2019

More on this story