This demo shows how Microsoft Sentinel data federation enables security teams to investigate across a broader digital estate without moving or duplicating data. It highlights how teams can analyze external data in place, register federated tables alongside native Sentinel data, and query everything through a unified KQL experience. You’ll also see how federated and native data are correlated to uncover complex insider threats while maintaining governance and compliance.
Last updated 2026-07-20
Duration
10 minutes
Recommended Role
Industry
Licensing
Windows E3, Windows E5
Audience
Products
Solution Area
Security
Solution Play
Demo type
Simulated Experience
No available notes
No available assets
No applicable resources