What’s new in Microsoft Sentinel: July 2026
Welcome back to another edition of What’s New in Microsoft Sentinel! In July, Sentinel introduced custom detection support within Sentinel repositories. This lets you manage detections as code, alongside your analytics rules, playbooks, parsers, and workbooks. You can now create them in GitHub and deploy through CI/CD pipelines that you’re already using. Additionally, the Sentinel data lake has implemented table insights, bringing table-level observability directly to the Microsoft Defender portal. This feature helps you track ingestion volumes, identify week-on-week variations, and detect connectors that have stopped sending data—without needing to run any KQL queries. Plus, connector coverage has expanded to include GitHub Audit logs, Agari, and Airlock Digital, ensuring that you have all the vital signals gathered in one place.
Keep reading for further insights, and if you plan to attend Black Hat USA 2026, be sure to catch the keynote speech by Agentic Security CVP David Weston along with other Microsoft Security activities at the event. Explore additional resources at the end for more detailed information.
Exciting Innovations in Sentinel:
Now you can manage custom detections as code directly within Sentinel repositories. This integration makes it easy to work alongside analytics rules, playbooks, parsers, and workbooks, effectively completing the detections-as-code workflow within the entire Sentinel ecosystem. Teams can draft detections in GitHub, carry out reviews through pull requests, and deploy them using existing CI/CD pipelines or the Microsoft Security Bicep extension. Discover how to manage custom content with repository connections.
Learn how the integration of Gigamon with Sentinel enhances your security investigations by incorporating network-derived telemetry. It correlates with existing identity, endpoint, and cloud signals in your workspace. By adding this runtime context, you can track suspicious activities across different environments and examine threats that might otherwise be overlooked, delivering faster and more precise investigations. You’ll gain clearer visibility into encrypted and hybrid cloud traffic that logs alone might miss. Read the blog to explore what this integration means for enhancing your security operations.
Table insights now offers a built-in monitoring view on the tables page in the Microsoft Defender portal, enabling you to observe your Sentinel workspace without running KQL queries or opening separate workbooks. It highlights the signals that matter most:
- Ingestion volume by tier – compare analytics against the data lake.
- Week-over-week ingestion fluctuations – easily spot drops or spikes from the prior week.
- Top 5 tables by daily ingestion volume – a quick glance at your biggest cost drivers.
- Last data received – catch connectors that have stopped transmitting data.
- Estimated daily ingestion cost – understand per-table costs for tier and retention decisions.
- Volume anomaly – observe percentage changes from the baseline to identify unusual behaviour early.
Figure 1: Investigate your table behaviour with Sentinel in the Defender portal.
These insights collectively help you detect collection failures sooner, allowing you to address them before they escalate into larger issues. Learn about the GitHub Audit logs connector, which imports GitHub Enterprise audit logs into Sentinel from Azure Blob Storage with nearly real-time latency. This enables you to view this data in workbooks, create custom alerts, and enhance your investigations. Remember, you’ll need to set up audit log streaming on GitHub for your Enterprise. Find out how to stream audit logs.
The Agari Data connector enables you to import logs from Agari APIs into Sentinel. This connector works with Agari Brand Protection (BP) and Phishing Defense (APD), supporting Data Collection Rules for better query execution.
In addition, you can now ingest Airlock Digital application control and execution events to bolster your endpoint detection and response capabilities.
Make sure to check back each month for the latest innovations, updates, and events to ensure you’re getting the most from Microsoft Sentinel. We look forward to seeing you in the next edition!
Share this content:
Discover more from Qureshi
Subscribe to get the latest posts sent to your email.