This award recognizes engineers who have contributed to solving customer challenges and enhancing security using Microsoft solutions. This time, our efforts in "building and operating an integrated security management platform using Microsoft Sentinel" were evaluated.
Award-winning initiatives
We integrated various logs, including Microsoft Defender XDR and Entra ID, into Microsoft Sentinel to create a security foundation that enables Zero Trust.
- Ensuring transparency
The "unclear alert conditions" that was an issue in conventional SIEMs has been improved with Sentinel's query-based analysis rules. Increased effectiveness while reducing false positives. - Operational automation
By utilizing SOAR, etc., it is possible to automatically respond to alerts and add information necessary for investigations when an incident occurs. We have introduced a mechanism to summarize content and provide recommendations in Azure Open AI, significantly reducing response lead times. - Results
- Improve the detection rate of identity-related risks
- Faster incident response
- Improved monitoring accuracy

Future Prospects
Based on this initiative, we will strengthen the following:
- Expand multi-tenant monitoring templates
- Develop a dedicated monitoring package for Microsoft Sentinel
- AI-powered incident response efficiency
This will maximize the value of the Microsoft security stack in more industries and formats, and take your security operations to the next level.
Colorkrew Security's Services Colorkrew Security provides an alert operation optimization support service (SOC) centered on Microsoft Sentinel.
For worries such as "too many alerts to respond" or "I don't know which one to prioritize", please leave everything from initial design to improvement proposals!