Microsoft has rolled out Sentinel Data Lake. It is meant to help security teams deal with the explosion of AI agents in corporate systems. AI agent IDs are growing faster than user IDs. Security data is going up 250 percent every year. Traditional SIEM systems are struggling. Logs are hard to manage. Data is scattered across different tools. Costs are going up. Teams are left exposed in some areas because they cannot monitor everything.
Sentinel Data Lake stores all kinds of data. Not just audit or identity logs. It can hold financial data, マイクロソフト 365 and Entra info, and threat intelligence. All of it in one place. It stops silos and allows integrated analysis. There is also a federation feature. This lets teams search data spread across Azure, AWS, Snowflake, and other places.
こちらもお読みください: 富士通、複雑なワークフローを自動化する「Kozuchi Physical AI 1.0」を発表
The platform has a graph engine. This gives a clear view of the movement of the attackers through the systems to the security teams rather than only viewing alerts in a list. The teams have the option to utilize VS Code and GitHub Copilot for running queries with the assistance of AI even if they lack the knowledge of Python. They can do threat hunting, anomaly detection, and forensic analysis in natural language.
Costs are lower because storage is cheap. Analysis is charged only when used. Companies can keep data for years. Early testers like SOPHiA GENETICS and IBM found it fast to deploy and useful.

