First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Microsoft Sentinel SIEM/SOAR Ongoing Monitoring
Managed services

Microsoft Sentinel SIEM/SOAR Ongoing Monitoring — SOC Threat Detection & Response

IT Partner provides a Security Operations Center (SOC) monitoring service using either Microsoft Sentinel or an in-house developed SIEM solution. The service is for organizations that need threat detection configuration, alerting, agreed incident response actions, compliance monitoring, and security incident reporting integrated with their existing IT environment. 24/7 support, continuous monitoring, and ongoing maintenance are not included by default and are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement. SKU: ITPWW160SECRC. Price: $12 per project. Manager: Roman Sotnik.

Timeline MonthlyService owner Roman SotnikMicrosoft Azure

What this engagement is

This service helps organizations monitor for security threats and respond to detected incidents through a SOC operating model. Customers can choose between Microsoft Sentinel, integrated with their Azure environment, or an in-house developed SIEM solution tailored to their security requirements and infrastructure. IT Partner provides monitoring configuration, alerting setup, agreed-upon response actions, reporting, and security posture advice. 24/7 support, continuous monitoring operations, and ongoing maintenance are not included by default and are available as optional paid add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement. The client is responsible for infrastructure readiness, communication, and cooperation on policy and compliance requirements.

Success criteria

01Demonstrated capability to identify, alert, and respond to security threats in real-time.
02Seamless integration of the chosen solution with existing IT infrastructure and processes.
03Positive feedback from the organization on the SOC service's impact on improving the security posture.
04Selecting between Microsoft Sentinel and an in-house developed SIEM solution allows organizations to tailor their SOC services to best fit their specific security needs, operational environments, and strategic goals.

What you receive

For the Microsoft Sentinel option: Microsoft Sentinel deployed and configured to integrate with the Azure environment for threat detection and response.
For the Microsoft Sentinel option: Sentinel environment configured for rule creation, dashboard monitoring, and alert configuration.
For the in-house developed SIEM option: Bespoke SIEM solution designed and developed based on the client’s specific security requirements and IT infrastructure.
For the in-house developed SIEM option: Custom SIEM solution integrated into the IT environment, with updates within the agreed implementation scope.
Optional paid add-on: round-the-clock surveillance to detect and alert on potential security threats, delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.
Detected threats managed by executing agreed-upon actions to contain and mitigate risks within the agreed scope.
Detailed security incident reports and strategic advice for enhancing security posture.

How the work unfolds

Define goals and select option

Define security goals and select the appropriate SOC service option.

Implement selected solution

Implement Microsoft Sentinel or develop and integrate the custom SIEM solution.

Test and tune

Conduct thorough testing to ensure operational efficacy and fine-tune the system.

Prepare optional active monitoring transition

If purchased as an optional paid add-on, transition to active monitoring, with continuous evaluation and adaptation of strategies.

Prerequisites

For the Microsoft Sentinel option, an active Azure subscription is required.
For the in-house developed SIEM, detailed technical requirements and specifications must be established.

Who does what

IT Partner

  • For Microsoft Sentinel: Deploy Microsoft Sentinel, configuring it to seamlessly integrate with your Azure environment for optimal threat detection and response.
  • For Microsoft Sentinel: Configure the Sentinel environment, including rule creation, dashboard monitoring, and alert configuration to ensure comprehensive coverage.
  • For In-House Developed SIEM Solution: Design and develop a bespoke SIEM solution tailored to your specific security requirements and IT infrastructure.
  • For In-House Developed SIEM Solution: Integrate the custom SIEM solution into your IT environment, ensuring it operates efficiently within the agreed implementation scope.
  • Optional paid add-on: Provide 24/7 support, continuous monitoring, and ongoing maintenance through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.
  • Common Responsibilities: Promptly manage detected threats by executing agreed-upon actions to contain and mitigate risks within the agreed scope.
  • Common Responsibilities: Deliver detailed security incident reports and provide strategic advice for enhancing security posture.

Your team

  • Common across both options: Ensure readiness of IT infrastructure to support SOC operations, including necessary network configurations.
  • Common across both options: Maintain open lines of communication with the IT Partner, facilitating collaboration and swift decision-making.
  • Common across both options: Work alongside the IT Partner to ensure that security policies are adhered to and regulatory compliance is maintained.

What's not included

24/7 support, continuous monitoring, and ongoing maintenance are not included by default. They are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.
Advanced Analytics and Threat Intelligence. For enhanced detection capabilities, subscriptions to additional threat intelligence feeds may be required.
Extended Detection and Response (XDR) Integrations. Integration with XDR solutions for broader threat detection and response capabilities.
Long-term Maintenance and Support. Ongoing support and maintenance contracts for the chosen solution beyond initial deployment are available only as separate optional paid add-ons.

Limitations & technical notes

!The listed price is preserved as $12 per project, but the source does not define the project unit, service term, monitored asset count, data ingestion volume, or included alert volume. For this type of SOC monitoring service, the commercial scope should normally be confirmed per project based on selected SIEM option, number of data sources, Microsoft Sentinel ingestion volume, retention requirements, automation scope, and incident response expectations.
!The source does not specify a fixed duration, billing period, or ongoing monitoring term. A typical engagement may separate initial onboarding, connector/rule configuration, testing and tuning, and an optional paid transition into active monitoring, but the actual timeline, response coverage, renewal terms, and billing period should be confirmed in the statement of work or managed services agreement.
!Maintenance boundaries should be explicitly defined before purchase. 24/7 support, continuous monitoring, and ongoing maintenance are not included by default and are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.
!Security monitoring improves detection and response capability but does not guarantee prevention of all incidents. Effectiveness depends on log source coverage, data quality, identity and endpoint telemetry, agreed response permissions, client approval workflows, and timely remediation of identified risks.

Frequently asked questions

What is included in IT Partner’s Microsoft Sentinel SIEM/SOAR ongoing monitoring service?

IT Partner provides a SOC monitoring service that includes threat detection configuration, alerting setup, agreed-upon incident response actions, compliance monitoring, security incident reporting, and security posture advice. The service can use Microsoft Sentinel or an in-house developed SIEM solution, depending on the organization’s security requirements and IT environment. 24/7 support, continuous monitoring, and ongoing maintenance are available only as optional extra-cost add-ons.

Does this service use Microsoft Sentinel, or can IT Partner provide another SIEM option?

IT Partner can deliver the service using either Microsoft Sentinel or an in-house developed SIEM solution. Microsoft Sentinel is used when the organization wants integration with its Azure environment, while the in-house SIEM option is tailored to specific security requirements and infrastructure.

What does IT Partner deliver for the Microsoft Sentinel option?

For the Microsoft Sentinel option, IT Partner deploys and configures Microsoft Sentinel to integrate with the customer’s Azure environment for threat detection and response. IT Partner also configures the Sentinel environment, including rule creation, dashboard monitoring, and alert configuration. Ongoing maintenance is not included by default and is available as an optional paid add-on.

What does IT Partner deliver for the in-house SIEM option?

For the in-house SIEM option, IT Partner designs and develops a bespoke SIEM solution based on the client’s security requirements and IT infrastructure. IT Partner then integrates the custom SIEM into the IT environment. Ongoing maintenance and updates are not included by default and are available as optional paid add-ons.

Is round-the-clock security monitoring included?

No. Round-the-clock security monitoring is not included by default. 24/7 support, continuous monitoring, and ongoing maintenance are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.

What incident response actions are included in the service?

The service includes agreed-upon response actions to contain and mitigate detected risks within the agreed scope. The exact actions should be defined during the engagement, because the service description commits to executing agreed actions but does not list a universal response playbook for every customer.

Does the service include security incident reports?

Yes, IT Partner provides detailed security incident reports as part of the SOC monitoring service. The reports are intended to document detected incidents and support strategic advice for improving the organization’s security posture.

What are the prerequisites for using Microsoft Sentinel in this service?

For the Microsoft Sentinel option, the customer must have an active Azure subscription. The customer should also ensure its IT infrastructure is ready to support SOC operations, including any necessary network configurations.

What are the prerequisites for the in-house developed SIEM option?

For the in-house developed SIEM option, detailed technical requirements and specifications must be established before design and development. This is necessary because the solution is tailored to the customer’s specific security requirements and IT infrastructure.

What is the implementation process for this SOC monitoring service?

The implementation starts by defining security goals and selecting either Microsoft Sentinel or the in-house SIEM option. IT Partner then implements the selected solution, tests and tunes it for operational effectiveness, and, if purchased as an optional paid add-on, transitions the customer into active monitoring with continuous evaluation and adaptation.

How long does the Microsoft Sentinel SIEM/SOAR ongoing monitoring engagement take?

The service description does not specify a fixed duration or billing period. Prospective buyers should confirm the expected timeline with IT Partner because implementation effort depends on the selected option, infrastructure readiness, integrations, and agreed monitoring scope.

Will implementing this SOC monitoring service cause downtime or business disruption?

The service description does not state that downtime is required. Any business impact should be confirmed during planning, because integration with the customer’s IT environment, network configurations, and testing requirements may vary by environment.

What is the customer responsible for during the service?

The customer is responsible for ensuring IT infrastructure readiness for SOC operations, including necessary network configurations. The customer must also maintain open communication with IT Partner and collaborate on security policy adherence and regulatory compliance requirements.

What is IT Partner responsible for during the service?

IT Partner is responsible for deploying and configuring Microsoft Sentinel or designing and integrating the in-house SIEM solution, depending on the selected option. IT Partner also provides alerting setup, agreed threat response actions, incident reporting, and strategic security posture advice within the agreed scope. 24/7 support, continuous monitoring, and ongoing maintenance are available only as optional paid add-ons.

What is not included in this service?

The service does not include 24/7 support, continuous monitoring, or ongoing maintenance by default; these are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement. The service also does not include Advanced Analytics and Threat Intelligence subscriptions, which may require additional threat intelligence feeds for enhanced detection, and it excludes XDR integrations and long-term maintenance and support beyond initial deployment unless separately purchased.

Are XDR integrations included with the SIEM/SOAR monitoring service?

No, Extended Detection and Response integrations are listed as not included in this service. If the organization needs broader XDR-based detection and response capabilities, that scope should be discussed separately with IT Partner.

Are advanced threat intelligence feeds included?

No, advanced analytics and threat intelligence are not included by default. Additional threat intelligence feed subscriptions may be required if the customer wants enhanced detection capabilities beyond the base service scope.

How does pricing work for this service?

The listed price for the service is $12 per project, with SKU ITPWW160SECRC. The source does not define what counts as a project or the billing period, so buyers should confirm the pricing unit, duration, and any additional costs with IT Partner before purchase.

What happens after the solution is implemented and tested?

After implementation, testing, and tuning, the service can transition to active monitoring if the optional paid monitoring add-on is purchased. Under that add-on, IT Partner provides 24/7 support, continuous monitoring, and ongoing maintenance through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement within the agreed scope.

Who should a buyer contact or reference for this service?

The service is identified as Microsoft Sentinel SIEM/SOAR ongoing monitoring, SKU ITPWW160SECRC. The listed manager is Roman Sotnik, and buyers should reference the SKU when confirming scope, pricing, duration, optional add-ons, and whether Microsoft Sentinel or the in-house SIEM option is the better fit.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Custom quote — scales with data ingestion and alert scope
Monthly
Book a meeting