Published: September 4, 2026 9 min read

Managed Sentinel Provider: What to Expect

Patrick Sandu, Founder and COO of Falconer Security
By Patrick Sandu Microsoft-certified security engineer

You can buy Microsoft Sentinel in an afternoon. Running it well, or hiring a managed Sentinel provider to run it well, is the hard part.

That gap is where most SMBs get stuck. The platform is powerful, the connector list is long, and the sales pitch makes it sound like good detections will somehow appear on their own. Then the first month lands: too many alerts, not enough tuning, uncertain ownership during incidents, and a bill nobody modeled properly.

A managed Sentinel provider is supposed to fix that. The problem is that plenty of vendors sell “managed Sentinel” when what they really provide is light onboarding plus a monthly check-in. If you are evaluating providers, the real question is simple: what will they take off your plate, what will stay with your team, and how quickly can they prove it?

At Falconer Security, we look at this from the buyer side. If you want a provider to manage Microsoft Sentinel as a cloud SIEM, you should expect clear ownership for onboarding, detection engineering, tuning, response workflows, and cost control, not just access to a tool.

Key takeaways
  • Demand a clear service model. Providers typically offer platform management only, co-managed, or fully managed monitoring. If a vendor cannot explain which one they sell in a single plain paragraph, keep looking.
  • Check Defender portal readiness now. Microsoft has confirmed Sentinel will no longer be supported in the Azure portal after March 31, 2027, so any provider you hire should already operate in the Defender experience.
  • Tuning matters more than coverage. Out-of-box analytics rules do not know your sign-in patterns or service accounts. A provider that never fixes noisy detections just alerts you faster about the wrong things.
  • Ask about Lighthouse and GDAP. Multi-tenant Sentinel management runs through Azure Lighthouse, and GDAP is required for certain connector scenarios. Providers who plan to figure out the tenant model after kickoff are learning on your time.
  • Outsourcing does not remove accountability. Verizon’s 2025 DBIR found 30% of breaches involved third parties, so insist on monthly reports covering incidents, tuning changes, and remaining gaps.

What a managed Sentinel provider actually does

A managed Sentinel provider is a security partner that deploys, tunes, and operates Microsoft Sentinel for your environment. That usually includes connector onboarding, analytics rules, playbooks, investigations, reporting, and ongoing optimization.

Microsoft describes Sentinel as a cloud-native SIEM that combines analytics, threat intelligence, and automation for detection, investigation, response, and proactive hunting. Microsoft also confirms that Sentinel is generally available in the Defender portal, and after March 31, 2027 it will no longer be supported in the Azure portal. That matters because any provider you hire now should already be comfortable running Sentinel in the Defender experience, not treating the portal move as tomorrow’s problem. Microsoft Learn: Sentinel overview and Microsoft Learn: Sentinel in the Defender portal are explicit on both points.

In practice, buyers usually need one of three service shapes:

  • Platform management only: the provider builds and tunes Sentinel, while your internal team handles alert review and incident response.
  • Co-managed service: your team and the provider split responsibilities for triage, escalation, and response.
  • Fully managed monitoring: the provider delivers round-the-clock coverage with agreed escalation paths and response actions.

If a provider cannot explain which model they offer in one plain paragraph, keep moving.

What you should expect before signing anything

The best providers are boring in the right places. They document scope, name owners, and show how work gets done. The weak ones stay vague until after kickoff.

Area What you should expect Red flag
Onboarding Connector plan, workspace review, use-case mapping, handoff milestones “We turn on the defaults and optimize later”
Detection quality Rule tuning, custom KQL, false-positive review, monthly changes Only Microsoft out-of-box rules
Response Named SLAs, escalation paths, playbook actions, evidence handling No written containment workflow
Multi-tenant operations Azure Lighthouse knowledge, delegated access model, Defender portal readiness Manual tenant switching and ad hoc admin access
Cost control Ingestion review, retention decisions, connector rationalization, query hygiene “The license cost is the main cost”
Reporting Executive summary, incident trends, tuning updates, backlog and next actions Only ticket exports

I’ve seen buyers focus too hard on 24/7 coverage and too little on engineering discipline. Coverage matters, obviously. But if the provider never fixes noisy detections, your team just pays extra to be alerted faster about the wrong things.

Five capabilities a good managed Sentinel provider must have

1. They know how to onboard and manage Sentinel in a service-provider model

Microsoft’s own guidance for managed security service providers is specific here. Providers can manage customer Sentinel resources through Azure Lighthouse, and Microsoft notes that GDAP is also required for certain connector deployment scenarios in managed workspaces. That detail gets missed a lot in sales conversations, then turns into access friction during delivery. The official reference is Manage multiple tenants in Microsoft Sentinel as an MSSP.

A provider that works in Microsoft environments every week should already have a view on delegated access, workspace ownership, tenant boundaries, and how they will operate in the Defender portal. If they need to “figure out the tenant model” after kickoff, they are learning on your time.

2. They treat detection engineering as ongoing work, not a one-time setup

Out-of-box content is a starting point. It is not the finished service.

Microsoft highlights built-in analytics, watchlists, workbooks, and automation in Sentinel. Useful foundation. Still, none of that knows your normal sign-in patterns, your service-account mess, your branch-office traffic, or which high-value identities deserve special monitoring. Good providers build from the platform baseline and then tune around your environment, your business processes, and your actual risk. That is the difference between a dashboard and a security operation.

If you want to see why this matters, compare it with the tuning work behind Sentinel detection engineering and the reality of default Sentinel rules that create noise.

3. They have a cost story that goes deeper than licensing

Sentinel cost problems rarely start with the SKU. They start with poor connector choices, over-collection, lazy retention, and queries nobody revisits.

Microsoft says Sentinel collects data across users, devices, apps, infrastructure, and multicloud sources at scale. Which is great, until someone decides every log is equally valuable. It isn’t. A serious provider should explain which data sources matter first, which ones can wait, and what tradeoffs come with each decision. They should also review those choices over time instead of locking you into day-one assumptions.

That is why buyers should ask for an ingestion governance model up front. If the provider cannot show how they control spend, read our breakdown of Sentinel cost optimization before you sign anything.

4. They can prove how incidents move from alert to action

A provider does not need to promise magical automation. They do need a clear response model.

Microsoft’s Defender portal guidance emphasizes unified incidents, entity context, advanced hunting, and automation capabilities. Those features are useful only if the provider can show what happens when an alert fires at 02:13, who validates it, what they can contain without calling you, what requires approval, and how evidence gets preserved. You want a written sequence, not a confident paragraph from a sales engineer.

The easiest way to test this is to ask for two walkthroughs: compromised user and suspicious endpoint. If the answer is mostly marketing language, the response process is probably immature too.

5. They report in a way your leadership team can use

Your security lead may care about analytic-rule drift, ingestion spikes, and KQL quality. Your leadership team does not. They care about what happened, how fast it was handled, where exposure remains, and whether the service is improving your position.

Verizon’s 2025 DBIR found that 30% of breaches involved third parties. That stat is useful here for one reason: outsourcing monitoring does not outsource accountability. Provider management is still a governance issue. If you cannot see how your provider is performing, you are taking third-party risk on faith. Source: Verizon DBIR 2025.

A solid monthly report should include incident summaries, meaningful metrics, tuning changes made during the month, outstanding gaps, and the next decisions your team needs to make. Anything less is decoration.

What competitors get right, and where most pages fall short

In the research for this piece, the common vendor pattern was obvious. KEEP leans hard into service tiers, Softcat leans on broad service benefits, and Wizard Cyber pushes round-the-clock SOC coverage, case studies, and add-on features. Those are all valid angles.

What most competitor pages skip is the buyer’s operating model. They tell you they monitor, automate, and optimize. They spend less time explaining where provider access breaks down, how connector deployment really works in delegated environments, how much tuning is included, and what your team still owns when an incident crosses legal, HR, or executive boundaries.

That gap is where buyers get burned. A managed Sentinel provider should not just promise outcomes. They should define the service mechanics behind those outcomes.

Questions to ask before you choose a provider

Use these in the sales process. Ask them live. Then stop talking and let the provider answer.

  • Which Sentinel tasks are included in the base service: onboarding, tuning, custom detections, playbooks, reporting, cost reviews?
  • Do you run Sentinel primarily in the Defender portal today, and what is your migration plan for customers still tied to Azure-portal workflows?
  • How do you handle Azure Lighthouse, GDAP, and delegated access for multi-tenant management?
  • How often do you tune analytics rules, and how do you measure whether alert quality is improving?
  • What response actions can you take without customer approval, and what always requires escalation?
  • How do you review ingestion volume and retention to control cost?
  • What does your first 30, 60, and 90 days look like?

If the provider answers all of this clearly, you’re having a real buying conversation. If they pivot back to “AI-driven visibility” and “peace of mind,” you’re still in brochure territory.

What Falconer thinks good looks like

For most Nordic SMBs, a good managed Sentinel provider does four things well: gets the Microsoft plumbing right, cuts alert noise fast, gives you fast human escalation when something matters, and keeps the service understandable for people outside the SOC.

That sounds obvious. It is also where a lot of services fall apart. Buyers get sold on tooling depth when they should be checking delivery discipline. Sentinel is not hard because the screenshots are hard. It is hard because somebody has to keep it aligned with your identities, your cloud changes, your incident process, and your budget month after month.

If you are comparing providers, start with the service page for managed Microsoft Sentinel, then compare that scope against your wider managed security services needs and any internal coverage you already have. For some teams, the right answer is fully managed. For others, it is co-managed with sharper escalation boundaries. Either can work if the ownership model is honest.

FAQ

What is a managed Sentinel provider?

A managed Sentinel provider is a security partner that deploys, tunes, and operates Microsoft Sentinel for your organization. Depending on the service model, they may handle connector onboarding, custom detections, alert triage, response workflows, reporting, and cost optimization.

What should a managed Sentinel provider include?

At minimum, expect onboarding, detection tuning, incident escalation workflows, reporting, and regular cost reviews. If those are not included, you may be buying platform administration instead of a real managed security service.

Does a managed Sentinel provider also deliver 24/7 SOC coverage?

Sometimes, but not always. Some providers only manage the platform while your team monitors alerts. Others offer co-managed or fully managed 24/7 SOC coverage. You need the service scope in writing before you sign.

Why does Defender portal experience matter for Sentinel buyers?

Microsoft states that Sentinel is generally available in the Defender portal and that support in the Azure portal ends after March 31, 2027. Providers should already know how to operate in the Defender experience so your team is not paying for a transition later.

Is NIS2 relevant when choosing a managed Sentinel provider?

Yes, especially for organizations in Europe. NIS2 raises the bar for incident handling, risk management, and supplier oversight. If a provider cannot explain access control, escalation paths, reporting, and evidence handling clearly, that weakness matters beyond operations. It matters for governance too.

Patrick Sandu, Founder and COO of Falconer Security
Patrick Sandu

Patrick Sandu is a Microsoft-certified security engineer specializing in Microsoft 365 and Azure security for SMBs. He leads security assessments and managed detection services at Falconer Security.

Learn more about our team
The dispatch

New Microsoft security guidance, when it lands.

One email when we publish. Practitioner analysis on detection, response, and hardening. No product pitches, unsubscribe anytime.

We never share your address.