We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. Sentinel SOC optimization
Microsoft Sentinel SOC optimization, UAE

Microsoft will tell you which tables you are paying to ingest and never using in a detection.

SOC optimization produces actionable recommendations in two directions: close coverage gaps against specific threats, and stop ingesting data that provides no security value. Recommendations are recalculated every 24 hours against your own workspace, and the coverage measure is your active analytics rules compared with what the Microsoft research team recommends.

Book a Sentinel optimization reviewSee the recommendation types
Microsoft Sentinel SOC optimization for UAE organisations
  • Every 24 hoursRecommendations recalculated
  • Over 75 percentWhat counts as high coverage
  • Two directionsCoverage gaps and data value
  • 31 March 2027Azure portal support for Sentinel ends
What it produces

Seven things that make this the most useful page in Sentinel that nobody opens.

Microsoft frames SOC optimization around a specific tension: teams want all the data needed to act against risks without paying for more data than needed, and they must adjust controls as threats and business priorities change. The recommendations are tailored to your environment, based on your current coverage and threat landscape.

It names the tables you pay for and never detect on

The published usage flow is direct: use the recommendations to identify tables with low usage, indicating they are not being used for detections, then view the size and cost of that unused data. Two responses follow, and both are legitimate. Add analytics rules so the table earns its place, or change the commitment tier and stop paying for what you will not use.

Threat-based coverage, measured against Microsoft research

Coverage is expressed as the number of analytics rules in your workspace compared with the number recommended by the Microsoft research team for a given threat scenario. That is a materially better benchmark than counting your own rules, because it is the difference between how many detections you have and how many the threat actually requires.

Three coverage bands, and most organisations are not in the top one

High means over 75 percent of recommended rules are activated. Medium means 30 to 74 percent. Low means 0 to 29 percent. Those bands appear per threat scenario, which is what makes them useful: an organisation can be high on one scenario and low on another, and knowing which is which is the whole basis of a sensible tuning plan.

Three kinds of coverage recommendation, not one

Threat-based recommendations add security controls to close gaps for various attack types. AI MITRE ATT&CK recommendations add tagging to close gaps against the framework. Risk-based recommendations add controls to close gaps for types of business risk. The third category is the one that translates most easily into language a board understands.

Recalculated every 24 hours, and completed automatically

Recommendations are calculated every 24 hours, so the picture follows your environment rather than a point-in-time review. Microsoft also states that if a change in your environment makes a recommendation irrelevant, the optimization is automatically completed and moved to the completed tab, with a banner showing how many completed automatically since your last visit.

A status workflow, so it works as a queue

Each recommendation can be marked complete, in progress, active or dismissed, and feedback can be sent to Microsoft. Dismissed and completed items can be reactivated, at which point they are recalculated for the most current value and action, which can take up to an hour. That turns a dashboard into something a team can actually work through week by week.

The Defender portal gives a wider picture, and there is a deadline

Microsoft states that when your workspace is onboarded to the Defender portal, SOC optimizations include coverage from across Microsoft security services rather than Sentinel alone. There is also a hard date attached: after 31 March 2027, Sentinel will no longer be supported in the Azure portal and will be available only in the Defender portal.

A date to put in the plan

After 31 March 2027, Sentinel exists only in the Defender portal.

This is not a recommendation, it is a published retirement date, and it changes how any Sentinel work planned in the next eighteen months should be sequenced.

  • Quoted: after 31 March 2027, Microsoft Sentinel will no longer be supported in the Azure portal and will be available only in the Microsoft Defender portal. All customers using Sentinel in the Azure portal will be redirected and will use Sentinel in the Defender portal only.
  • Microsoft recommends that customers still on the Azure portal start planning the transition now, to ensure a smooth move and take full advantage of the unified security operations experience.
  • For SOC optimization specifically there is an immediate reason to move rather than wait: when the workspace is onboarded to the Defender portal, the optimizations include coverage from across Microsoft security services, not only Sentinel.
  • The practical consequence is that any tuning, runbook, training or documentation work you do in the Azure portal between now and then is work you will do twice. Sequencing the portal move first is cheaper than doing it last.
Ask us to plan your Defender portal transition
How we approach it

Four things that turn recommendations into a smaller bill and better detection.

SOC optimization is free to look at and sits in a portal most teams open only when investigating. The work is in deciding, table by table and scenario by scenario, and then doing it repeatedly rather than once.

We decide per table, not by volume

A low usage table is not automatically waste. Sometimes the right answer is adding an analytics rule so the data earns its place, which is the first option Microsoft offers. Cutting the largest tables because they are largest is how organisations lose the telemetry they most need during the next incident, and it is a decision that is very hard to reverse after the fact.

We prioritise Low band scenarios that match your sector

Coverage bands are per threat scenario, and 0 to 29 percent of recommended rules is a very different position from 30 to 74 percent. Working every gap equally spreads effort thinly. Working the Low band scenarios that plausibly apply to a UAE bank, a logistics operator or a healthcare group concentrates it where the risk actually is.

We install solutions rather than isolated rule templates

Microsoft notes that installing an analytics rule template from the Content hub without the solution installed means only the installed template appears in the solution. Installing the full solution makes the rest of its content visible, which usually includes workbooks, hunting queries and playbooks that would otherwise never be discovered.

We make it monthly, because it recalculates daily

Recommendations refresh every 24 hours and complete themselves automatically when your environment changes. That rewards a light monthly pass far more than an annual deep review. Using the status workflow as a genuine queue, with a named owner, is what keeps both the coverage bands and the ingestion trend moving.

How we sequence it

Four phases, and the cost saving usually funds the coverage work.

Most Sentinel deployments in the UAE were built once and never revisited. The data value recommendations usually release budget in the first month, and that budget pays for closing the coverage gaps the same review identifies.
  1. 01
    Week 1

    Establish the baseline and the portal position

    Current ingestion, current analytics rules, and the coverage band per threat scenario. Where the workspace is still in the Azure portal, we look at the transition plan first, because optimizations in the Defender portal include coverage from across Microsoft security services and the Azure portal has a published end date.

    • Ingestion baseline over the published 90 day window
    • Coverage band recorded per threat scenario
    • Defender portal onboarding status established
    • Roles and permissions confirmed against Sentinel requirements
  2. 02
    Weeks 2 to 4

    Work the data value recommendations

    Tables with low usage, meaning they are not being used for detections, reviewed one by one with their size and cost visible. Each gets a decision: add an analytics rule so the data earns its place, or change the plan. Neither answer is automatically right, and the wrong move is deciding by volume alone.

    • Every low usage table reviewed with a documented decision
    • Analytics rules added where the data has real detection value
    • Commitment tier reassessed where it does not
    • Savings quantified so they can fund the next phase
  3. 03
    Weeks 5 to 8

    Close the coverage gaps that matter

    Threat scenarios in the Low band first, using the spider charts across tactics and techniques and the prefiltered MITRE ATT&CK view to understand where the gap actually is. Rules come from the Content hub, and we install full solutions rather than individual templates so the rest of the content is visible.

    • Low band scenarios prioritised by relevance to your sector
    • Content hub solutions installed rather than isolated templates
    • New rules tuned before they reach the analyst queue
    • Risk-based recommendations mapped for board reporting
  4. 04
    Ongoing

    Make it a monthly rhythm

    Recommendations recalculate every 24 hours, which means the value comes from looking regularly rather than deeply. A monthly pass through active optimizations, using the status workflow as a queue, keeps coverage and cost both moving in the right direction without a periodic large project.

    • Monthly review with a named owner
    • Status used as a queue: complete, in progress, dismissed
    • Automatic completions reviewed rather than ignored
    • Coverage bands and ingestion trend reported to the business
Where this matters most

Six UAE situations where an optimization review pays for itself quickly.

The common pattern is a Sentinel deployment that was built well, connected generously, and has not been examined since. Both halves of SOC optimization tend to find something in that situation.

A bank whose ingestion bill has grown every quarter

Connectors added over years, each justified at the time, none reviewed since. The data value recommendations name the tables that are not being used for detections and show their size and cost, which converts an uncomfortable finance conversation into a specific list of decisions with an owner against each one.

A group that inherited a Sentinel workspace from a project

The integrator built it, tuned it, handed it over and left. Nobody since has compared the active analytics rules against what Microsoft research recommends for the threats the business actually faces. The coverage bands answer that in an afternoon, per scenario, without a manual gap assessment.

A firm that needs to explain security coverage to a board

Risk-based recommendations add controls to close coverage gaps for types of business risk, which is a materially easier conversation than tactics and techniques. Combined with the coverage bands and the recent optimization value metric, that produces a report a non-technical audience can read and act on.

An operator still running Sentinel in the Azure portal

The published deadline is 31 March 2027, after which Sentinel is available only in the Defender portal. Beyond meeting the deadline there is an immediate gain: in the Defender portal, optimizations include coverage from across Microsoft security services rather than Sentinel alone, which is a wider and more useful picture.

An organisation whose analysts are drowning

Adding detections without tuning them makes that worse, which is why coverage work and alert quality belong in the same exercise. Working the Low band scenarios deliberately, tuning each new rule before it reaches the queue, and dismissing recommendations that genuinely do not apply keeps coverage rising without the queue rising with it.

A business preparing for a security audit or certification

Coverage expressed as a percentage of research-recommended rules per threat scenario, with a documented decision on every recommendation, is a considerably stronger evidence position than a list of enabled rules. The status workflow itself provides the record of what was assessed, what was actioned and what was consciously dismissed.

Three positions

How UAE organisations run their Sentinel workspace.

The middle column is the common one. Sentinel was deployed properly during a project, connectors were switched on generously, and nothing has been reviewed since the project closed.
Coverage measured against research recommendations
Optimized monthlyYes
Deployed, never reviewedNo
Logs collected, few detectionsNo
Gaps prioritised by threat scenario
Optimized monthlyYes
Deployed, never reviewedNo
Logs collected, few detectionsNo
Unused tables identified
Optimized monthlyYes
Deployed, never reviewedNo
Logs collected, few detectionsNo
Ingestion cost actively managed
Optimized monthlyYes
Deployed, never reviewedReactively
Logs collected, few detectionsNo
MITRE coverage understood
Optimized monthlyYes
Deployed, never reviewedPartly
Logs collected, few detectionsNo
Risk-based view available to the board
Optimized monthlyYes
Deployed, never reviewedNo
Logs collected, few detectionsNo
Recommendations worked as a queue
Optimized monthlyYes
Deployed, never reviewedNo
Logs collected, few detectionsNo
Defender portal transition planned
Optimized monthlyYes
Deployed, never reviewedNot yet
Logs collected, few detectionsNot yet
New content adopted as it appears
Optimized monthlyYes
Deployed, never reviewedRarely
Logs collected, few detectionsNo
Cost trend visible to the business
Optimized monthlyYes
Deployed, never reviewedAt invoice time
Logs collected, few detectionsAt invoice time
Feature
Optimized monthly
Deployed, never reviewed
Logs collected, few detections
Coverage measured against research recommendations
YesNoNo
Gaps prioritised by threat scenario
YesNoNo
Unused tables identified
YesNoNo
Ingestion cost actively managed
YesReactivelyNo
MITRE coverage understood
YesPartlyNo
Risk-based view available to the board
YesNoNo
Recommendations worked as a queue
YesNoNo
Defender portal transition planned
YesNot yetNot yet
New content adopted as it appears
YesRarelyNo
Cost trend visible to the business
YesAt invoice timeAt invoice time
The recommendation types

What each type tells you, and what to do about it.

Types and definitions as published. The action column is the practical response we take on each, which is ours rather than Microsoft.
TypeWhat Microsoft says it coversWhat we do with it
Threat-based coverageAdding security controls to close coverage gaps for various types of attacksWork the scenarios where coverage is Low first, since those are 0 to 29 percent of recommended rules
AI MITRE ATT&CKTagging recommendations to close coverage gaps based on the MITRE ATT&CK frameworkUse the prefiltered MITRE page to see which tactics and techniques are genuinely uncovered
Risk-based coverageAdding security controls to close coverage gaps for various types of business riskThe category that translates into board language, so it goes in the reporting pack
Data valueImproving data usage to maximise security value from ingested data, or suggesting a better data planDecide per table: add a detection so it earns its place, or change the plan
Recent optimization valueValue gained from recommendations you recently implementedThe number that shows the tuning rhythm is working, worth reporting monthly
Data ingestedTotal data ingested in your workspace over the last 90 days in the Defender portalThe trend line that makes an ingestion conversation factual rather than anecdotal
Optimization statusThe number of recommendations currently active, completed and dismissedTreated as a work queue with a weekly review, not a dashboard
How a review runs

Five steps, and the first two usually pay for the rest.

Typically three to six weeks for a first pass, then a light monthly rhythm. The prerequisites are minimal: standard Sentinel roles and permissions, and Defender portal onboarding to get the wider view.
  1. 1

    Confirm access, portal position and baseline

    SOC optimization uses standard Sentinel roles and permissions. Using it in the Defender portal requires Sentinel to be onboarded there, which is also what makes optimizations include coverage from across Microsoft security services. We record the ingestion baseline and the coverage band per threat scenario before changing anything.

  2. 2

    Work the data value recommendations first

    Identifying tables with low usage, meaning they are not being used for detections, and viewing the size and cost of that unused data. Each table gets a decision: add analytics rules from the Content hub so it earns its place, or change the plan. The savings are quantified so they can be set against the coverage work.

  3. 3

    Prioritise coverage gaps by band and by relevance

    Low band scenarios, meaning 0 to 29 percent of recommended rules activated, first, filtered by what plausibly applies to your sector. The spider charts across tactics and techniques and the prefiltered MITRE ATT&CK view show where the gap actually sits rather than how many rules are missing.

  4. 4

    Add content properly and tune before going live

    Installing full Content hub solutions rather than isolated templates, so the workbooks, hunting queries and playbooks that come with them are visible. Every new rule is tuned before it reaches the analyst queue, because coverage bought with alert fatigue is not a net gain.

  5. 5

    Establish the monthly rhythm and the reporting

    Recommendations recalculate every 24 hours and automatically complete when the environment changes. A monthly pass, with the status workflow used as a queue and a named owner, plus reported coverage bands, ingestion trend and recent optimization value, keeps this working after the engagement ends.

Straight answers

What organisations ask about SOC optimization.

Actionable recommendations in two directions. Coverage recommendations for closing gaps against specific threats, against MITRE ATT&CK, and against types of business risk. Data value recommendations for improving how you use ingested data or suggesting a better data plan. Microsoft describes them as tailored to your environment and based on your current coverage and threat landscape.

It is part of Sentinel and uses standard Sentinel roles and permissions. To use it in the Defender portal, Sentinel needs to be onboarded there, which is worth doing anyway. In our experience the first data value pass frequently identifies enough unused ingestion to fund the coverage work the same review recommends.

By comparing the number of analytics rules found in your workspace against the number of rules recommended by the Microsoft research team for a given threat scenario. High means over 75 percent of recommended rules are activated, medium is 30 to 74 percent, and low is 0 to 29 percent. Because the bands are per scenario, an organisation can be high on one threat and low on another.

Recommendations are calculated every 24 hours. Microsoft also states that if a change in your environment makes a recommendation irrelevant, the optimization is automatically completed and moved to the completed tab, with a banner in the overview showing how many completed automatically since your last visit. That daily cadence is why a light monthly review works better than an annual deep one.

The published flow is to identify tables with low usage, indicating they are not being used for detections, then view the size and cost of that unused data. Two actions are offered. Go to the Content hub to add analytics rule templates that use that table, which Microsoft notes takes you directly to the relevant rule. Or change your commitment tier for cost savings.

Not automatically. A table with no detection on it may still be exactly what you need during an investigation, and adding an analytics rule so it earns its place is the first option Microsoft presents. The decision is per table, weighing detection value, investigation value and cost. Cutting by volume alone is the version of this exercise that people regret.

Three. Threat-based recommendations for adding security controls to close coverage gaps for various types of attacks. AI MITRE ATT&CK recommendations for adding tagging to close gaps against the framework. And risk-based recommendations for adding controls to close coverage gaps for various types of business risk. The last of these is the one that translates most naturally into board reporting.

Microsoft states that after 31 March 2027, Sentinel will no longer be supported in the Azure portal and will be available only in the Microsoft Defender portal, with Azure portal customers redirected. It recommends planning the transition now. There is an immediate benefit beyond compliance with the date: in the Defender portal, SOC optimizations include coverage from across Microsoft security services.

The Defender portal overview shows recent optimization value, data ingested over the last 90 days, threat-based coverage optimizations with the band indicator, and optimization status. The Azure portal overview shows ingested data over the last three months and optimization status. The Defender portal also adds the spider charts and the direct link into a prefiltered MITRE ATT&CK view.

Yes, and you should, otherwise the list stops being a queue. Statuses are active, in progress, completed and dismissed, and dismissed or completed items can be reactivated later. Microsoft notes reactivated optimizations are recalculated for the most updated value and action, which can take up to an hour, and may move straight back to completed if they are no longer relevant.

Because of how the Content hub works. Microsoft states that if you install an analytics rule template without the solution installed, only the installed template appears in the solution. Installing the full solution reveals all its available content items, which typically include workbooks, hunting queries and playbooks that most teams never discover if they only ever install individual rules.

It will if you enable them untuned, which is why we do not. Coverage and alert quality belong in the same conversation. Each new rule is tuned before it reaches the queue, scenarios are prioritised by relevance rather than worked exhaustively, and recommendations that genuinely do not apply to your business are dismissed rather than half-implemented.

It gives you most of the value with none of the effort, which is a different thing. The comparison against Microsoft research recommendations per threat scenario, refreshed daily and mapped to MITRE, covers what a manual assessment would produce for Microsoft-detectable threats. A full assessment still adds value where your estate includes significant non-Microsoft telemetry or bespoke systems.

Three numbers work well together. Coverage band per threat scenario, so the picture is per risk rather than a single score. Data ingested over the trailing period, so cost is a trend rather than a surprise at invoice time. And recent optimization value, which shows what implemented recommendations have already returned. Risk-based recommendations supply the narrative around them.

We scope per organisation, driven by workspace size, connector count and whether you want the coverage work implemented or only recommended. The first pass is usually three to six weeks. In most engagements the data value findings identify enough unused ingestion that the coverage work is funded from what the same review saves.
Before the review

Fifteen questions worth answering about your Sentinel workspace.

The first group is position, the second is cost, the third is coverage. Most organisations can answer the first, guess at the second and have never looked at the third.

Position

  • Are you in the Defender portal yet?
    Azure portal support ends 31 March 2027.
  • Who has the Sentinel roles required?
    Standard roles and permissions apply.
  • When did anyone last review analytics rules?
    Usually the answer is at deployment.
  • Is Content hub content installed as solutions?
    Templates alone hide the rest.
  • Who owns the workspace day to day?
    Optimization needs an owner, not a project.

Cost

  • What are you ingesting over 90 days?
    The Defender portal shows it directly.
  • Which tables have no detection using them?
    That is the core data value finding.
  • Is your commitment tier still the right one?
    It is a named recommended action.
  • Would basic logs suit any table?
    Change plan is offered from the recommendation.
  • Is anyone tracking ingestion trend?
    Otherwise cost conversations are anecdotal.

Coverage

  • What is your coverage band per scenario?
    High, medium or low, per threat.
  • Which scenarios matter most to your sector?
    Prioritise those in the Low band.
  • Do you look at the MITRE view?
    It is prefiltered per scenario.
  • Are risk-based recommendations reported?
    They translate best for a board.
  • Are new rules tuned before going live?
    Otherwise coverage costs you analyst hours.
Related reading

The pages around this one.

Sentinel in the Defender portal

The transition itself, and what changes when the workspace is onboarded.

Learn more

Microsoft Sentinel

The product overview, connectors and how a workspace is built.

Learn more

SOC as a service

Where the analyst hours come from once the detections are in place.

Learn more
Next step

Open the page and look at your coverage band. It takes five minutes.

Most organisations we work with find they are in the low band on at least one threat scenario that matters to them, and paying to ingest at least one table that no detection uses. Both are visible in a single session.

Book a Sentinel optimization reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Sentinel to the Defender Portal

Azure portal support for Sentinel ends 31 March 2027

Learn more

Microsoft Sentinel

Cloud-native SIEM and threat intelligence

Learn more

SOC-as-a-Service

24/7 SOC on Microsoft Sentinel

Learn more

Managed Security Services

MSS on Microsoft Defender XDR and Sentinel

Learn more

Defender XDR

Eleven signal sources, one incident, and containment without a human

Learn more

Security Exposure Management

Choke points where many attack paths converge

Learn more

Microsoft Security Dubai

Entra, Defender, Purview, Sentinel, and what you already own

Learn more

Incident Response

24/7 incident response and forensics in Dubai

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy