Simulated Experience

Microsoft Sentinel Data Federation

This demo shows how Microsoft Sentinel data federation enables security teams to investigate across a broader digital estate without moving or duplicating data. It highlights how teams can analyze external data in place, register federated tables alongside native Sentinel data, and query everything through a unified KQL experience. You’ll also see how federated and native data are correlated to uncover complex insider threats while maintaining governance and compliance.

Last updated 2026-07-20

Duration

10 minutes

Recommended Role

Account Executive

Industry

Licensing

Windows E3, Windows E5

Audience

Business Decision Maker

Products

Azure Security Center, Azure Sentinel, Communication Compliance, Compliance Center, Conditional Acce...

Solution Area

Security

Solution Play

Data Security FY26

Demo type

Simulated Experience

Notes

No available notes

Assets

    No available assets

Resources

    No applicable resources

To top