Microsoft Sentinel SIEM/SOAR Ongoing Monitoring — SOC Threat Detection & Response
IT Partner monitors your production Microsoft Sentinel deployment as a recurring service: we watch and triage Sentinel incidents, a human analyst responds within a 2-hour SLA during the agreed coverage window, and we either remediate within the agreed response authority or escalate to your team with specific recommended actions. Approved responses can also run automatically through Sentinel automation rules and playbooks. A production Microsoft Sentinel implementation is required before onboarding; pricing is quoted per environment.
What this engagement is
This service is the operating phase that follows a Microsoft Sentinel production implementation. Once Sentinel is deployed and generating incidents, someone has to watch it — this is that service. IT Partner’s analysts monitor your Sentinel incident and alert queues during the agreed coverage window, triage and investigate what Sentinel raises, and act on it: confirmed issues within the agreed response authority are remediated by IT Partner (for example, locking an account or isolating a workstation through approved playbooks), and everything else is escalated to your team with specific recommended actions. A human analyst responds to in-scope incidents within a 2-hour SLA, and approved responses can also run automatically at machine speed through Sentinel automation rules and Logic Apps playbooks. The service runs on a recurring 30-day cycle and includes ongoing rule tuning and recurring reporting. Pricing is quoted per environment based on data sources, ingestion volume, coverage window, and response scope.
Success criteria
What you receive
How the work unfolds
Validate the production Microsoft Sentinel deployment — workspace, connectors, analytics rules, and automation — and document contacts, the coverage window, and escalation paths.
Agree which response actions IT Partner may take without prior approval and which require client authorization, and set up the notification and escalation channels.
Review, enable, and test the approved Sentinel automation rules and Logic Apps playbooks that handle immediate machine-speed responses.
Begin incident triage under the 2-hour response SLA, with an initial tuning period to align severities and reduce noise for the environment.
Continue monitoring, response, and tuning on the recurring 30-day cycle, with recurring reports and periodic service reviews.
Prerequisites
Who does what
IT Partner
- Monitor the Sentinel incident and alert queues during the agreed coverage window.
- Triage and investigate in-scope incidents with a human analyst response within the 2-hour SLA.
- Remediate confirmed issues within the agreed response authority, or escalate to the client with specific recommended actions.
- Configure, maintain, and review the approved Sentinel automation rules and playbooks.
- Tune analytics rules and suppress confirmed false positives on an ongoing basis.
- Deliver recurring reports and periodic service reviews, including recommendations on coverage gaps and new data sources.
Your team
- Maintain the underlying Microsoft Sentinel deployment costs: Azure consumption and any required Microsoft licensing.
- Keep escalation contacts current and respond to escalations for actions outside IT Partner’s agreed authority.
- Approve the response-authority matrix and any changes to automated response behavior.
- Inform IT Partner of planned changes — migrations, new applications, maintenance windows — that will affect Sentinel signals.
- Perform remediation that remains under client control, such as business application changes or third-party vendor coordination.
What's not included
Limitations & technical notes
Frequently asked questions
What is IT Partner’s Microsoft Sentinel SIEM/SOAR Ongoing Monitoring service?
It is the recurring monitoring service that follows a Microsoft Sentinel production implementation. IT Partner’s analysts watch your Sentinel incident and alert queues, triage and investigate what Sentinel raises, remediate confirmed issues within the agreed response authority or escalate them to your team with recommended actions, and keep the analytics rules tuned.
What does the 2-hour SLA mean?
A human analyst from IT Partner responds to an in-scope Sentinel incident within 2 hours during the coverage window agreed in your monitoring agreement. Approved automated responses through Sentinel playbooks can act even sooner, and the analyst then reviews what the automation did.
What happens when Microsoft Sentinel raises an incident?
If an approved automation rule or playbook covers the scenario, it runs immediately. A human analyst then triages the incident within the 2-hour SLA: confirmed issues within IT Partner’s agreed response authority are remediated directly, and everything else is escalated to your contacts with specific recommended actions.
Do you fix problems yourselves or tell us about them?
Both, depending on the response-authority matrix agreed during onboarding. Actions you pre-approve — such as locking a compromised account or isolating a workstation through an approved playbook — are executed by IT Partner. Anything outside that authority is escalated to your team with our recommended fix.
Is this a 24/7 monitoring service?
The coverage window is defined in your monitoring agreement. Extended and 24/7 coverage are available as extra-cost options delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.
What do we need before onboarding?
A production Microsoft Sentinel deployment with healthy connectors and analytics rules generating incidents, an active Azure subscription, delegated analyst access, named escalation contacts, and an approved response-authority matrix. If you do not have Sentinel in production yet, IT Partner’s Microsoft Sentinel implementation service can deliver it first.
Can some responses happen automatically?
Yes. Sentinel automation rules and Azure Logic Apps playbooks approved during onboarding run at machine speed — for example, notification, enrichment, account lockout, or workstation isolation. Every automated action is reviewed by an analyst, and automation behavior only changes with your approval.
How is the service priced?
Pricing is quoted per environment on a recurring 30-day cycle, based on the number of data sources, ingestion volume, the coverage window, and the agreed response scope. Contact IT Partner for a quote; the 2-hour human-response SLA is part of the standard service.
Can you monitor a Sentinel deployment that someone else implemented?
Yes, provided it meets the prerequisites. Onboarding starts with a review of the existing deployment — connectors, analytics coverage, and automation — and IT Partner will flag gaps that would limit monitoring before the SLA starts.
What reports do we receive?
A recurring security report covering incidents, response actions taken, SLA performance, tuning changes, and recommendations — including coverage gaps and suggested new data sources. Periodic service reviews walk through the report with your team.
What is not included in this service?
The initial Sentinel implementation, Azure consumption and Microsoft licensing costs, coverage beyond the agreed window, full breach forensics and long-running remediation projects, custom detection engineering and custom connectors, and remediation in systems IT Partner has no access or authority over. See the full exclusions list on this page.