Microsoft will tell you which tables you are paying to ingest and never using in a detection.
SOC optimization produces actionable recommendations in two directions: close coverage gaps against specific threats, and stop ingesting data that provides no security value. Recommendations are recalculated every 24 hours against your own workspace, and the coverage measure is your active analytics rules compared with what the Microsoft research team recommends.

- Every 24 hoursRecommendations recalculated
- Over 75 percentWhat counts as high coverage
- Two directionsCoverage gaps and data value
- 31 March 2027Azure portal support for Sentinel ends
Seven things that make this the most useful page in Sentinel that nobody opens.
It names the tables you pay for and never detect on
The published usage flow is direct: use the recommendations to identify tables with low usage, indicating they are not being used for detections, then view the size and cost of that unused data. Two responses follow, and both are legitimate. Add analytics rules so the table earns its place, or change the commitment tier and stop paying for what you will not use.
Threat-based coverage, measured against Microsoft research
Coverage is expressed as the number of analytics rules in your workspace compared with the number recommended by the Microsoft research team for a given threat scenario. That is a materially better benchmark than counting your own rules, because it is the difference between how many detections you have and how many the threat actually requires.
Three coverage bands, and most organisations are not in the top one
High means over 75 percent of recommended rules are activated. Medium means 30 to 74 percent. Low means 0 to 29 percent. Those bands appear per threat scenario, which is what makes them useful: an organisation can be high on one scenario and low on another, and knowing which is which is the whole basis of a sensible tuning plan.
Three kinds of coverage recommendation, not one
Threat-based recommendations add security controls to close gaps for various attack types. AI MITRE ATT&CK recommendations add tagging to close gaps against the framework. Risk-based recommendations add controls to close gaps for types of business risk. The third category is the one that translates most easily into language a board understands.
Recalculated every 24 hours, and completed automatically
Recommendations are calculated every 24 hours, so the picture follows your environment rather than a point-in-time review. Microsoft also states that if a change in your environment makes a recommendation irrelevant, the optimization is automatically completed and moved to the completed tab, with a banner showing how many completed automatically since your last visit.
A status workflow, so it works as a queue
Each recommendation can be marked complete, in progress, active or dismissed, and feedback can be sent to Microsoft. Dismissed and completed items can be reactivated, at which point they are recalculated for the most current value and action, which can take up to an hour. That turns a dashboard into something a team can actually work through week by week.
The Defender portal gives a wider picture, and there is a deadline
Microsoft states that when your workspace is onboarded to the Defender portal, SOC optimizations include coverage from across Microsoft security services rather than Sentinel alone. There is also a hard date attached: after 31 March 2027, Sentinel will no longer be supported in the Azure portal and will be available only in the Defender portal.
After 31 March 2027, Sentinel exists only in the Defender portal.
This is not a recommendation, it is a published retirement date, and it changes how any Sentinel work planned in the next eighteen months should be sequenced.
- Quoted: after 31 March 2027, Microsoft Sentinel will no longer be supported in the Azure portal and will be available only in the Microsoft Defender portal. All customers using Sentinel in the Azure portal will be redirected and will use Sentinel in the Defender portal only.
- Microsoft recommends that customers still on the Azure portal start planning the transition now, to ensure a smooth move and take full advantage of the unified security operations experience.
- For SOC optimization specifically there is an immediate reason to move rather than wait: when the workspace is onboarded to the Defender portal, the optimizations include coverage from across Microsoft security services, not only Sentinel.
- The practical consequence is that any tuning, runbook, training or documentation work you do in the Azure portal between now and then is work you will do twice. Sequencing the portal move first is cheaper than doing it last.
Four things that turn recommendations into a smaller bill and better detection.
We decide per table, not by volume
A low usage table is not automatically waste. Sometimes the right answer is adding an analytics rule so the data earns its place, which is the first option Microsoft offers. Cutting the largest tables because they are largest is how organisations lose the telemetry they most need during the next incident, and it is a decision that is very hard to reverse after the fact.
We prioritise Low band scenarios that match your sector
Coverage bands are per threat scenario, and 0 to 29 percent of recommended rules is a very different position from 30 to 74 percent. Working every gap equally spreads effort thinly. Working the Low band scenarios that plausibly apply to a UAE bank, a logistics operator or a healthcare group concentrates it where the risk actually is.
We install solutions rather than isolated rule templates
Microsoft notes that installing an analytics rule template from the Content hub without the solution installed means only the installed template appears in the solution. Installing the full solution makes the rest of its content visible, which usually includes workbooks, hunting queries and playbooks that would otherwise never be discovered.
We make it monthly, because it recalculates daily
Recommendations refresh every 24 hours and complete themselves automatically when your environment changes. That rewards a light monthly pass far more than an annual deep review. Using the status workflow as a genuine queue, with a named owner, is what keeps both the coverage bands and the ingestion trend moving.
Four phases, and the cost saving usually funds the coverage work.
- 01Week 1
Establish the baseline and the portal position
Current ingestion, current analytics rules, and the coverage band per threat scenario. Where the workspace is still in the Azure portal, we look at the transition plan first, because optimizations in the Defender portal include coverage from across Microsoft security services and the Azure portal has a published end date.
- Ingestion baseline over the published 90 day window
- Coverage band recorded per threat scenario
- Defender portal onboarding status established
- Roles and permissions confirmed against Sentinel requirements
- 02Weeks 2 to 4
Work the data value recommendations
Tables with low usage, meaning they are not being used for detections, reviewed one by one with their size and cost visible. Each gets a decision: add an analytics rule so the data earns its place, or change the plan. Neither answer is automatically right, and the wrong move is deciding by volume alone.
- Every low usage table reviewed with a documented decision
- Analytics rules added where the data has real detection value
- Commitment tier reassessed where it does not
- Savings quantified so they can fund the next phase
- 03Weeks 5 to 8
Close the coverage gaps that matter
Threat scenarios in the Low band first, using the spider charts across tactics and techniques and the prefiltered MITRE ATT&CK view to understand where the gap actually is. Rules come from the Content hub, and we install full solutions rather than individual templates so the rest of the content is visible.
- Low band scenarios prioritised by relevance to your sector
- Content hub solutions installed rather than isolated templates
- New rules tuned before they reach the analyst queue
- Risk-based recommendations mapped for board reporting
- 04Ongoing
Make it a monthly rhythm
Recommendations recalculate every 24 hours, which means the value comes from looking regularly rather than deeply. A monthly pass through active optimizations, using the status workflow as a queue, keeps coverage and cost both moving in the right direction without a periodic large project.
- Monthly review with a named owner
- Status used as a queue: complete, in progress, dismissed
- Automatic completions reviewed rather than ignored
- Coverage bands and ingestion trend reported to the business
Six UAE situations where an optimization review pays for itself quickly.
A bank whose ingestion bill has grown every quarter
Connectors added over years, each justified at the time, none reviewed since. The data value recommendations name the tables that are not being used for detections and show their size and cost, which converts an uncomfortable finance conversation into a specific list of decisions with an owner against each one.
A group that inherited a Sentinel workspace from a project
The integrator built it, tuned it, handed it over and left. Nobody since has compared the active analytics rules against what Microsoft research recommends for the threats the business actually faces. The coverage bands answer that in an afternoon, per scenario, without a manual gap assessment.
A firm that needs to explain security coverage to a board
Risk-based recommendations add controls to close coverage gaps for types of business risk, which is a materially easier conversation than tactics and techniques. Combined with the coverage bands and the recent optimization value metric, that produces a report a non-technical audience can read and act on.
An operator still running Sentinel in the Azure portal
The published deadline is 31 March 2027, after which Sentinel is available only in the Defender portal. Beyond meeting the deadline there is an immediate gain: in the Defender portal, optimizations include coverage from across Microsoft security services rather than Sentinel alone, which is a wider and more useful picture.
An organisation whose analysts are drowning
Adding detections without tuning them makes that worse, which is why coverage work and alert quality belong in the same exercise. Working the Low band scenarios deliberately, tuning each new rule before it reaches the queue, and dismissing recommendations that genuinely do not apply keeps coverage rising without the queue rising with it.
A business preparing for a security audit or certification
Coverage expressed as a percentage of research-recommended rules per threat scenario, with a documented decision on every recommendation, is a considerably stronger evidence position than a list of enabled rules. The status workflow itself provides the record of what was assessed, what was actioned and what was consciously dismissed.
How UAE organisations run their Sentinel workspace.
| Feature | Optimized monthly | Deployed, never reviewed | Logs collected, few detections |
|---|---|---|---|
Coverage measured against research recommendations | Yes | No | No |
Gaps prioritised by threat scenario | Yes | No | No |
Unused tables identified | Yes | No | No |
Ingestion cost actively managed | Yes | Reactively | No |
MITRE coverage understood | Yes | Partly | No |
Risk-based view available to the board | Yes | No | No |
Recommendations worked as a queue | Yes | No | No |
Defender portal transition planned | Yes | Not yet | Not yet |
New content adopted as it appears | Yes | Rarely | No |
Cost trend visible to the business | Yes | At invoice time | At invoice time |
What each type tells you, and what to do about it.
| Type | What Microsoft says it covers | What we do with it | |
|---|---|---|---|
| Threat-based coverage | Adding security controls to close coverage gaps for various types of attacks | Work the scenarios where coverage is Low first, since those are 0 to 29 percent of recommended rules | |
| AI MITRE ATT&CK | Tagging recommendations to close coverage gaps based on the MITRE ATT&CK framework | Use the prefiltered MITRE page to see which tactics and techniques are genuinely uncovered | |
| Risk-based coverage | Adding security controls to close coverage gaps for various types of business risk | The category that translates into board language, so it goes in the reporting pack | |
| Data value | Improving data usage to maximise security value from ingested data, or suggesting a better data plan | Decide per table: add a detection so it earns its place, or change the plan | |
| Recent optimization value | Value gained from recommendations you recently implemented | The number that shows the tuning rhythm is working, worth reporting monthly | |
| Data ingested | Total data ingested in your workspace over the last 90 days in the Defender portal | The trend line that makes an ingestion conversation factual rather than anecdotal | |
| Optimization status | The number of recommendations currently active, completed and dismissed | Treated as a work queue with a weekly review, not a dashboard |
Five steps, and the first two usually pay for the rest.
- 1
Confirm access, portal position and baseline
SOC optimization uses standard Sentinel roles and permissions. Using it in the Defender portal requires Sentinel to be onboarded there, which is also what makes optimizations include coverage from across Microsoft security services. We record the ingestion baseline and the coverage band per threat scenario before changing anything.
- 2
Work the data value recommendations first
Identifying tables with low usage, meaning they are not being used for detections, and viewing the size and cost of that unused data. Each table gets a decision: add analytics rules from the Content hub so it earns its place, or change the plan. The savings are quantified so they can be set against the coverage work.
- 3
Prioritise coverage gaps by band and by relevance
Low band scenarios, meaning 0 to 29 percent of recommended rules activated, first, filtered by what plausibly applies to your sector. The spider charts across tactics and techniques and the prefiltered MITRE ATT&CK view show where the gap actually sits rather than how many rules are missing.
- 4
Add content properly and tune before going live
Installing full Content hub solutions rather than isolated templates, so the workbooks, hunting queries and playbooks that come with them are visible. Every new rule is tuned before it reaches the analyst queue, because coverage bought with alert fatigue is not a net gain.
- 5
Establish the monthly rhythm and the reporting
Recommendations recalculate every 24 hours and automatically complete when the environment changes. A monthly pass, with the status workflow used as a queue and a named owner, plus reported coverage bands, ingestion trend and recent optimization value, keeps this working after the engagement ends.
What organisations ask about SOC optimization.
Fifteen questions worth answering about your Sentinel workspace.
Position
- Are you in the Defender portal yet?Azure portal support ends 31 March 2027.
- Who has the Sentinel roles required?Standard roles and permissions apply.
- When did anyone last review analytics rules?Usually the answer is at deployment.
- Is Content hub content installed as solutions?Templates alone hide the rest.
- Who owns the workspace day to day?Optimization needs an owner, not a project.
Cost
- What are you ingesting over 90 days?The Defender portal shows it directly.
- Which tables have no detection using them?That is the core data value finding.
- Is your commitment tier still the right one?It is a named recommended action.
- Would basic logs suit any table?Change plan is offered from the recommendation.
- Is anyone tracking ingestion trend?Otherwise cost conversations are anecdotal.
Coverage
- What is your coverage band per scenario?High, medium or low, per threat.
- Which scenarios matter most to your sector?Prioritise those in the Low band.
- Do you look at the MITRE view?It is prefiltered per scenario.
- Are risk-based recommendations reported?They translate best for a board.
- Are new rules tuned before going live?Otherwise coverage costs you analyst hours.
The pages around this one.
Open the page and look at your coverage band. It takes five minutes.
Most organisations we work with find they are in the low band on at least one threat scenario that matters to them, and paying to ingest at least one table that no detection uses. Both are visible in a single session.
Related Services
Explore more solutions that work great with this service
Sentinel to the Defender Portal
Azure portal support for Sentinel ends 31 March 2027
Microsoft Sentinel
Cloud-native SIEM and threat intelligence
SOC-as-a-Service
24/7 SOC on Microsoft Sentinel
Managed Security Services
MSS on Microsoft Defender XDR and Sentinel
Defender XDR
Eleven signal sources, one incident, and containment without a human
Security Exposure Management
Choke points where many attack paths converge
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own
Incident Response
24/7 incident response and forensics in Dubai