First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Microsoft Sentinel SIEM/SOAR Ongoing Monitoring
Managed services

Microsoft Sentinel SIEM/SOAR Ongoing Monitoring — SOC Threat Detection & Response

IT Partner monitors your production Microsoft Sentinel deployment as a recurring service: we watch and triage Sentinel incidents, a human analyst responds within a 2-hour SLA during the agreed coverage window, and we either remediate within the agreed response authority or escalate to your team with specific recommended actions. Approved responses can also run automatically through Sentinel automation rules and playbooks. A production Microsoft Sentinel implementation is required before onboarding; pricing is quoted per environment.

Timeline 30 daysService owner Roman SotnikMicrosoft Azure

What this engagement is

This service is the operating phase that follows a Microsoft Sentinel production implementation. Once Sentinel is deployed and generating incidents, someone has to watch it — this is that service. IT Partner’s analysts monitor your Sentinel incident and alert queues during the agreed coverage window, triage and investigate what Sentinel raises, and act on it: confirmed issues within the agreed response authority are remediated by IT Partner (for example, locking an account or isolating a workstation through approved playbooks), and everything else is escalated to your team with specific recommended actions. A human analyst responds to in-scope incidents within a 2-hour SLA, and approved responses can also run automatically at machine speed through Sentinel automation rules and Logic Apps playbooks. The service runs on a recurring 30-day cycle and includes ongoing rule tuning and recurring reporting. Pricing is quoted per environment based on data sources, ingestion volume, coverage window, and response scope.

Success criteria

01In-scope Microsoft Sentinel incidents are triaged by a human analyst within the 2-hour response SLA during the agreed coverage window.
02Each actionable incident is either remediated by IT Partner within the agreed response authority or escalated to the client with specific recommended actions.
03Approved automated responses run through Sentinel automation rules and playbooks and are reviewed by an analyst.
04False-positive noise trends down over time through ongoing analytics rule tuning.
05The client receives recurring reports covering incidents, response actions, SLA performance, tuning changes, and recommendations.

What you receive

Onboarding review of the existing production Sentinel deployment: connectors, analytics coverage, automation, contacts, coverage window, and escalation paths.
A documented response-authority matrix defining which actions IT Partner may take without approval and which are escalated to the client.
Monitoring of the Sentinel incident and alert queues during the agreed coverage window.
Human triage and investigation of in-scope incidents within the 2-hour response SLA.
Remediation of confirmed issues within the agreed response authority — for example, predefined account lockouts or workstation isolation through approved playbooks — or escalation to the client with recommended actions.
Approved automated responses configured and maintained through Sentinel automation rules and Azure Logic Apps playbooks.
Ongoing analytics rule tuning and suppression of confirmed false positives.
Recurring security report: incidents, response actions, SLA performance, tuning changes, and security posture recommendations.

How the work unfolds

Onboarding and deployment review

Validate the production Microsoft Sentinel deployment — workspace, connectors, analytics rules, and automation — and document contacts, the coverage window, and escalation paths.

Response authority definition

Agree which response actions IT Partner may take without prior approval and which require client authorization, and set up the notification and escalation channels.

Automation alignment

Review, enable, and test the approved Sentinel automation rules and Logic Apps playbooks that handle immediate machine-speed responses.

Live monitoring start

Begin incident triage under the 2-hour response SLA, with an initial tuning period to align severities and reduce noise for the environment.

Steady state

Continue monitoring, response, and tuning on the recurring 30-day cycle, with recurring reports and periodic service reviews.

Prerequisites

A production Microsoft Sentinel implementation: a deployed workspace with healthy data connectors and analytics rules generating incidents. IT Partner’s Microsoft Sentinel SIEM/SOAR Implementation service (ITPWW150SECOT) can deliver this if you do not have one yet.
An active Azure subscription and continued acceptance of Azure consumption charges (Log Analytics ingestion, retention, automation).
Delegated access for IT Partner’s analysts to Microsoft Sentinel, incidents, and the systems covered by the agreed response actions.
Named client escalation contacts reachable during the coverage window.
An agreed response-authority matrix, approved before live monitoring starts.

Who does what

IT Partner

  • Monitor the Sentinel incident and alert queues during the agreed coverage window.
  • Triage and investigate in-scope incidents with a human analyst response within the 2-hour SLA.
  • Remediate confirmed issues within the agreed response authority, or escalate to the client with specific recommended actions.
  • Configure, maintain, and review the approved Sentinel automation rules and playbooks.
  • Tune analytics rules and suppress confirmed false positives on an ongoing basis.
  • Deliver recurring reports and periodic service reviews, including recommendations on coverage gaps and new data sources.

Your team

  • Maintain the underlying Microsoft Sentinel deployment costs: Azure consumption and any required Microsoft licensing.
  • Keep escalation contacts current and respond to escalations for actions outside IT Partner’s agreed authority.
  • Approve the response-authority matrix and any changes to automated response behavior.
  • Inform IT Partner of planned changes — migrations, new applications, maintenance windows — that will affect Sentinel signals.
  • Perform remediation that remains under client control, such as business application changes or third-party vendor coordination.

What's not included

Initial Microsoft Sentinel implementation, workspace design, or connector deployment — this service requires an existing production Sentinel deployment (see prerequisites).
Azure consumption charges (ingestion, retention, automation) and Microsoft licensing costs, which are billed by Microsoft.
Coverage beyond the agreed window. Extended and 24/7 coverage are available as extra-cost options delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.
Major-incident and breach response beyond agreed containment actions: full forensic investigation, malware reverse engineering, legal or breach counsel coordination, eDiscovery, and long-running remediation projects.
New detection engineering beyond the agreed tuning scope, custom connectors, custom parsers, and additional threat intelligence feed subscriptions.
Remediation of issues in systems IT Partner has no access or authority over — these are escalated to the client with recommended actions.
Guaranteed prevention or detection of every threat; monitoring effectiveness depends on the telemetry and detections in the underlying Sentinel deployment.

Limitations & technical notes

!The 2-hour SLA applies to the human analyst response to in-scope Sentinel incidents during the coverage window agreed in the service agreement; approved automated playbook responses can act sooner.
!Detection quality depends on the health and coverage of the underlying Sentinel deployment; gaps in connectors, telemetry, or analytics rules limit what monitoring can see.
!Response actions outside the agreed authority are escalated to the client, so time to full remediation then depends on client action.
!Pricing is quoted per environment based on data sources, ingestion volume, coverage window, and response scope; the service runs on a recurring 30-day cycle.

Frequently asked questions

What is IT Partner’s Microsoft Sentinel SIEM/SOAR Ongoing Monitoring service?

It is the recurring monitoring service that follows a Microsoft Sentinel production implementation. IT Partner’s analysts watch your Sentinel incident and alert queues, triage and investigate what Sentinel raises, remediate confirmed issues within the agreed response authority or escalate them to your team with recommended actions, and keep the analytics rules tuned.

What does the 2-hour SLA mean?

A human analyst from IT Partner responds to an in-scope Sentinel incident within 2 hours during the coverage window agreed in your monitoring agreement. Approved automated responses through Sentinel playbooks can act even sooner, and the analyst then reviews what the automation did.

What happens when Microsoft Sentinel raises an incident?

If an approved automation rule or playbook covers the scenario, it runs immediately. A human analyst then triages the incident within the 2-hour SLA: confirmed issues within IT Partner’s agreed response authority are remediated directly, and everything else is escalated to your contacts with specific recommended actions.

Do you fix problems yourselves or tell us about them?

Both, depending on the response-authority matrix agreed during onboarding. Actions you pre-approve — such as locking a compromised account or isolating a workstation through an approved playbook — are executed by IT Partner. Anything outside that authority is escalated to your team with our recommended fix.

Is this a 24/7 monitoring service?

The coverage window is defined in your monitoring agreement. Extended and 24/7 coverage are available as extra-cost options delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.

What do we need before onboarding?

A production Microsoft Sentinel deployment with healthy connectors and analytics rules generating incidents, an active Azure subscription, delegated analyst access, named escalation contacts, and an approved response-authority matrix. If you do not have Sentinel in production yet, IT Partner’s Microsoft Sentinel implementation service can deliver it first.

Can some responses happen automatically?

Yes. Sentinel automation rules and Azure Logic Apps playbooks approved during onboarding run at machine speed — for example, notification, enrichment, account lockout, or workstation isolation. Every automated action is reviewed by an analyst, and automation behavior only changes with your approval.

How is the service priced?

Pricing is quoted per environment on a recurring 30-day cycle, based on the number of data sources, ingestion volume, the coverage window, and the agreed response scope. Contact IT Partner for a quote; the 2-hour human-response SLA is part of the standard service.

Can you monitor a Sentinel deployment that someone else implemented?

Yes, provided it meets the prerequisites. Onboarding starts with a review of the existing deployment — connectors, analytics coverage, and automation — and IT Partner will flag gaps that would limit monitoring before the SLA starts.

What reports do we receive?

A recurring security report covering incidents, response actions taken, SLA performance, tuning changes, and recommendations — including coverage gaps and suggested new data sources. Periodic service reviews walk through the report with your team.

What is not included in this service?

The initial Sentinel implementation, Azure consumption and Microsoft licensing costs, coverage beyond the agreed window, full breach forensics and long-running remediation projects, custom detection engineering and custom connectors, and remediation in systems IT Partner has no access or authority over. See the full exclusions list on this page.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

$15 per user
30 days
Book a meeting