Skip to content
Notifications
Clear all

Has anyone tried using Sentinel as the SIEM for a fully remote company?

2 Posts
2 Users
0 Reactions
3 Views
(@angelaw)
Reputable Member
Joined: 2 months ago
Posts: 285
Topic starter   [#29558]

As an enterprise licensing specialist who has recently been involved in several procurements for distributed organizations, I am analyzing the operational and contractual implications of deploying Microsoft Sentinel in a fully remote, cloud-native environment. The traditional SIEM model often presupposes a corporate network perimeter or on-premises data sources, which are largely irrelevant for a company where endpoints, identities, and applications are entirely cloud-based and geographically dispersed.

My primary inquiry is whether community members have implemented Sentinel under these conditions and can speak to the following specific facets:

* **Data Source Integration & Log Collection:** The feasibility and cost efficiency of ingesting logs exclusively from cloud services (e.g., Entra ID, Microsoft 365 Defender, SaaS applications via REST API connectors, cloud infrastructure logs from AWS/GCP/Azure). A key concern is the absence of traditional firewall or on-premises server logs, shifting the focus entirely to identity, cloud workload, and endpoint detection and response (EDR) signals.
* **Agent Deployment & Management for Remote Endpoints:** The practicalities of deploying the Log Analytics agent (AMA) or other required agents to a fleet of remote, non-domain-joined laptops. This touches on:
* Scalability of deployment via Intune or similar MDM.
* Network bandwidth considerations for agents in home offices transmitting data directly to the cloud workspace.
* Security and compliance of the agent itself on uncontrolled networks.
* **Licensing & Cost Structure Analysis:** The cost model for a fully remote company can differ significantly. Without on-premises data, the commitment to a per-GB pricing tier may be more predictable, but one must rigorously assess:
* The volume of ingested security data from the listed cloud sources.
* The potential need for additional Entra ID P1/P2 licenses for advanced identity protection signals.
* The alignment of Microsoft 365 E5 licensing, if present, with Sentinel costs.
* **Vendor Management & Compliance:** Ensuring that the configuration and data residency of the Sentinel workspace comply with regulatory requirements when all employees are remote, potentially across multiple jurisdictions. This includes a review of the Microsoft Data Protection Addendum and mapping of data processing locations.

I am particularly interested in structured comparisons between this setup and a more traditional hybrid environment, with caveats on where the fully remote model introduces unique complexities or, conversely, simplifications. Any insights into negotiation points with Microsoft regarding commitment tiers based on this usage profile would also be highly valuable.


Check the SLA.


   
Quote
(@chrisp)
Honorable Member
Joined: 3 months ago
Posts: 462
 

Great question on shifting to purely cloud data sources. That's exactly the setup we had to tackle last year.

On your first point about cloud logs, it's very feasible but the cost efficiency totally depends on your ingestion filtering. If you just pipe everything from Entra ID and M365 Defender, the volume (and cost) can explode. We built specific analytic rules first and only ingested the logs those rules needed. For SaaS apps, the API connectors worked but added a maintenance layer we hadn't fully budgeted for.

For remote endpoints, the Microsoft Defender agent deployment was straightforward via Intune. The bigger hiccup was managing the agent health for laptops that might be offline for days - the dashboard alerts can get noisy. You'll likely spend more time tuning those alerts than on the actual deployment.


✌️


   
ReplyQuote