Microsoft Sentinel Adds Detections-As-Code, Table Insights, and New Data Connectors

New integrations and monitoring tools help security teams investigate threats, and track data health more efficiently.

Microsoft Security image

Key Takeaways:

  • Security teams can now manage custom detections as code using GitHub and CI/CD workflows.
  • Table Insights provides visibility into data ingestion, connector health, and usage trends.
  • New connectors expand Sentinel coverage across GitHub Enterprise, Agari, Airlock Digital, and Gigamon.

Microsoft’s July 2026 update for Sentinel introduces new capabilities to streamline detections-as-code workflows for commercial customers. The release also improves data lake visibility and expands data connector coverage, giving security teams broader access to security signals through a unified platform.

Microsoft introduced a new feature that allows security teams to manage custom detections as code alongside analytics rules, playbooks, parsers, and workbooks. Detections can be authored in GitHub, reviewed through pull requests, and deployed using existing CI/CD pipelines, which makes security content management more consistent and automated.

In the Microsoft Defender portal, a new Table Insights feature provides an at-a-glance view of Sentinel data tables without requiring KQL queries. It helps security teams monitor ingestion volume, identify unusual spikes or drops in data collection, and estimate ingestion costs. This feature also makes it easier to track top data-consuming tables and detect connectors that have stopped sending data. The goal is to simplify operational monitoring and help security teams detect data collection issues before they affect investigations.

Microsoft Sentinel Adds Detections-As-Code, Table Insights, and New Data Connectors
View all table insights (Image Credit: Microsoft)

New and expanded Data Connectors

Microsoft Sentinel has expanded its connector ecosystem with several new data integrations in public preview. Organizations can now ingest GitHub Enterprise audit logs through Azure Blob Storage, which provides near real-time visibility into GitHub activities and enables deeper monitoring and investigation capabilities.

Additionally, Sentinel introduces an Agari connector, which brings phishing defense and brand protection telemetry into the platform. This capability helps security teams better detect and respond to email-based threats. Moreover, the new Airlock Digital connector ingests application control and execution event data, which enhances endpoint security monitoring and improves overall threat detection and response capabilities.

Last but not least, Microsoft highlighted how Gigamon’s integration enhances Sentinel investigations with network-derived telemetry. This additional context helps security analysts correlate network activity with identity, endpoint, and cloud signals to improve threat detection and investigation accuracy.