I Built an Azure Detection Engineering Lab with Microsoft Sentinel
Brief
From raw Azure and Entra ID telemetry to KQL detections, validation, alerts, and incidents.
A KQL query compiling is not proof that a detection works.
The underlying event, relevant field values, query result, and Sentinel behavior must all be verified.
A reliable detection starts with reliable telemetry. This lab builds an Azure logging foundation for Microsoft Sentinel, validates the native tables, and uses the observed data to develop three Microsoft Entra ID detections.
Azure Resource Hierarchy
Azure resources are organized into management scopes, and Azure RBAC or Azure Policy assignments can inherit from higher scopes to the resources below them.
