You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
graph layer
About this tag
The graph layer is a new capability within Microsoft Sentinel that enriches threat detection by modeling relationships between entities, users, and activities. As discussed in a recent thread, this feature entered public preview alongside the Sentinel data lake and a Model Context Protocol server. The graph layer enables Security Copilot–compatible agents to perform longer-range, context-aware investigations, helping SOC teams automate complex workflows. However, the same thread notes that adopting the graph layer introduces new governance, cost, and attack-surface considerations that organizations must evaluate. The tag covers discussions around the graph layer's role in modernizing security operations within the Microsoft ecosystem.
Microsoft’s security stack just crossed a new practical milestone: Avanade has been named a design partner on the reinvigorated Microsoft Sentinel platform and is shipping the first Security Copilot–compatible agents that run against the newly available Sentinel data lake, while Microsoft has...