Skip to content

Commit d468b3c

Browse files
authored
Merge pull request #5405 from DeCohen/WI436866-mda-siem-integration-deprecated
Add deprecation notice for siem
2 parents f712f6c + c0a5ec0 commit d468b3c

File tree

1 file changed

+19
-2
lines changed

1 file changed

+19
-2
lines changed

defender-for-cloud-apps/siem-sentinel.md

Lines changed: 19 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,30 @@
11
---
22
title: Microsoft Sentinel integration
33
description: This article provides information integrating Microsoft Sentinel with Defender for Cloud Apps.
4-
ms.date: 01/29/2023
4+
ms.date: 10/29/2025
55
ms.topic: how-to
66
ms.reviewer: Naama-Goldbart
77
---
8-
# Microsoft Sentinel integration (Preview)
98

9+
# Microsoft Sentinel integration (Preview)
1010

11+
> [!IMPORTANT]
12+
> **Deprecation Notice: Microsoft Defender for Cloud Apps SIEM Agents**
13+
>
14+
> As part of our ongoing convergence process across Microsoft Defender workloads, Microsoft Defender for Cloud Apps SIEM agents will be deprecated starting **November 2025**.
15+
>
16+
>
17+
> Existing Microsoft Defender for Cloud Apps SIEM agents will continue to function as is until that time. As of June 19, 2025, **no new SIEM agents can be configured**, but [Microsoft Sentinel](siem-sentinel.md) agent integration (Preview), will remain supported and can still be added.
18+
>
19+
> We recommend transitioning to APIs that support the management of activities and alerts data from multiple workloads.
20+
> These APIs enhance security monitoring and management and offer additional capabilities using data from multiple Microsoft Defender workloads.
21+
>
22+
> To ensure continuity and access to data currently available through Microsoft Defender for Cloud Apps SIEM agents, we recommend transitioning to the following supported APIs:
23+
>
24+
> - For alerts and activities, see: [Microsoft Defender XDR Streaming API](/defender-xdr/streaming-api).
25+
> - For Microsoft Entra ID Protection logon events, see [IdentityLogonEvents](/defender-xdr/advanced-hunting-identitylogonevents-table) table in the advanced hunting schema.
26+
> - For Microsoft Graph Security Alerts API, see: [List alerts_v2](/graph/api/security-list-alerts_v2?view=graph-rest-1.0&tabs=http&preserve-view=true)
27+
> - To view Microsoft Defender for Cloud Apps alerts data in the Microsoft Defender XDR incidents API, see [Microsoft Defender XDR incidents APIs and the incidents resource type](/graph/api/security-list-alerts_v2?view=graph-rest-1.0&tabs=http&preserve-view=true)
1128
1229
You can integrate Microsoft Defender for Cloud Apps with Microsoft Sentinel (a scalable, cloud-native SIEM and SOAR) to enable centralized monitoring of alerts and discovery data. Integrating with Microsoft Sentinel allows you to better protect your cloud applications while maintaining your usual security workflow, automating security procedures, and correlating between cloud-based and on-premises events.
1330

0 commit comments

Comments
 (0)