Empower Real-Time Security with Microsoft Sentinel’s CCF Push Feature
In our fast-changing world of security threats, organisations require solutions that provide immediate actionable insights – not responses that surface minutes or hours later. Microsoft Sentinel is continually enhancing its features, dedicated to equipping customers and partners with advanced tools for proactive defence. We’re thrilled to share that the public preview of our newest innovation, the Sentinel Codeless Connector Framework (CCF) Push feature, is now available. CCF Push meets a vital requirement by enabling a smooth, automated, and instant delivery of security data to Sentinel, allowing teams to tackle threats as they arise.
What Is CCF Push and Why Is It Important?
Microsoft Sentinel connectors usually operate in two main ways. The first is the polling model, where partners and customers expose their web-based REST API endpoints. Our traditional CCF connectors then poll these endpoints periodically to retrieve data for Sentinel. The second model is the push approach, allowing partners and customers to send data directly to a Sentinel workspace. The new CCF Push feature that we’re introducing is designed to simplify and speed up the adoption of this push method.
For the complete announcement, click here: Empower Real-Time Security with Microsoft Sentinel’s CCF Push Feature
Original Publication: Microsoft Sentinel Blog, February 12th, 2026
Share this content:
Discover more from Qureshi
Subscribe to get the latest posts sent to your email.