---
title: "Microsoft Sentinel - Sola Security"
canonical: "https://sola.security/integrations/microsoft-sentinel/"
---

# Microsoft Sentinel + Sola Security

Connect Microsoft Sentinel to your Sola workspace and query your SIEM live for incidents, alerts, and identity threats across your Microsoft environment.

## How the Sola <> Microsoft Sentinel integration helps you meet your security needs

### See what needs your attention first

Surface the open, high-severity incidents that matter and skip the rest, without opening the Azure portal

### Query your whole Microsoft environment

Explore incidents, alerts, and sign-in activity from across your Microsoft tools in plain language

### Add Sola’s context layer on top of Microsoft

Enrich the assets your Microsoft tools cover with identity, endpoint, and business context from across your stack

## Real-time data source

Sola connects directly to real time data sources to give you live answers the exact moment you ask, requiring zero setup or maintenance. Because it reads your data instantly instead of copying it over, these requests won’t count against your daily limits.

## Use cases and capabilities

Data exfiltration risk

Pull Sentinel DLP alerts from the last 7 days and match them to users who also had an unusually large file export or external sharing event in Google Workspace.

Endpoint compromise blast radius

Show Sentinel endpoint malware detections from the last 48 hours, and check whether the affected users have write or admin access to any sensitive GitHub repos.

Compromised credential detection

Find Sentinel impossible-travel alerts from the last 24 hours, then check whether the affected users made any IAM or S3 changes in AWS within the following hour.

Unauthorized Admin Elevation

Show me all Sentinel incidents involving admin role assignment in the last 7 days, and flag any users who weren’t already listed as admins in Okta.

### More Integrations

[Google Sheets](https://sola.security/integrations/google-sheets/)

[Anthropic](https://sola.security/integrations/anthropic/)

[NetSuite](https://sola.security/integrations/netsuite/)

[Webchecker](https://sola.security/integrations/webchecker/)

[WordPress](https://sola.security/integrations/wordpress/)

[AWS](https://sola.security/integrations/aws/)

[Azure](https://sola.security/integrations/azure/)

[GitHub](https://sola.security/integrations/github/)

[Google Cloud Platform](https://sola.security/integrations/gcp/)

[Google Workspace](https://sola.security/integrations/google-workspace/)

[MongoDB Atlas](https://sola.security/integrations/mongodb-atlas/)

[Okta](https://sola.security/integrations/okta/)

[Wiz](https://sola.security/integrations/wiz/)

[Lovable](https://sola.security/integrations/lovable/)

[Cloudflare](https://sola.security/integrations/cloudflare/)

[Zoom](https://sola.security/integrations/zoom/)

[SentinelOne](https://sola.security/integrations/sentinelone/)

[Snowflake](https://sola.security/integrations/snowflake/)

[Google Sheets](https://sola.security/integrations/google-sheets/)

[Anthropic](https://sola.security/integrations/anthropic/)

[NetSuite](https://sola.security/integrations/netsuite/)

[Webchecker](https://sola.security/integrations/webchecker/)

[WordPress](https://sola.security/integrations/wordpress/)

[AWS](https://sola.security/integrations/aws/)

[Azure](https://sola.security/integrations/azure/)

[GitHub](https://sola.security/integrations/github/)

[Google Cloud Platform](https://sola.security/integrations/gcp/)

[Google Workspace](https://sola.security/integrations/google-workspace/)

[MongoDB Atlas](https://sola.security/integrations/mongodb-atlas/)

[Okta](https://sola.security/integrations/okta/)

[Wiz](https://sola.security/integrations/wiz/)

[Lovable](https://sola.security/integrations/lovable/)

[Cloudflare](https://sola.security/integrations/cloudflare/)

[Zoom](https://sola.security/integrations/zoom/)

[SentinelOne](https://sola.security/integrations/sentinelone/)

[Snowflake](https://sola.security/integrations/snowflake/)
