Skip to main content
Cloud / Azure / Products / Microsoft Sentinel data lake - Security Data Lake

Microsoft Sentinel data lake - Security Data Lake

Microsoft Sentinel data lake: cloud-native security data lake with up to 12 years of retention, KQL queries, Jupyter notebooks, and open Parquet format.

security
Pricing Model Billed through Microsoft Sentinel (ingestion and storage per tier), see official pricing page
Availability Regions per the 'Regions supported for Microsoft Sentinel data lake' list in the official documentation
Data Sovereignty Region and data residency per the Microsoft Sentinel geographical availability documentation
Reliability per provider / see official documentation SLA

What is Microsoft Sentinel data lake?

Microsoft Sentinel data lake is a purpose-built, cloud-native security data lake. It ingests, stores, and analyzes large volumes of diverse security data in an open, extensible format. By centralizing security data on a single platform, Microsoft states it provides deep visibility, long-term retention, and advanced analytics.

The service addresses a common problem with traditional SIEM approaches: the cost and complexity of storing and querying long-term security data force organizations to choose between coverage and cost. Microsoft Sentinel data lake is fully managed, so you don’t deploy or maintain data infrastructure yourself. It stores a single copy of security data across assets, activity logs, and threat intelligence and makes it available to multiple analytics engines.

Technically, the data lake uses open Parquet files for interoperability and extensibility, separates storage from compute, and integrates natively with Microsoft Sentinel SIEM and its security operations workflows.

Core Features

  • Two storage tiers: analytics tier for hunting, alerting, and incident management; data lake tier for cost-effective long-term retention of up to 12 years
  • Unified data across Microsoft Defender XDR, third-party sources, assets, activity logs, and threat intelligence
  • KQL query editor with IntelliSense, autocomplete, and the full range of KQL capabilities including machine learning functions
  • Jupyter notebooks with Python libraries for machine learning, advanced analytics, and visualization
  • Jobs for one-time or scheduled promotion of data from the lake tier to the analytics tier
  • Activity auditing for data access, query events, and job management, enabled by default
  • Compatibility with all existing Microsoft Sentinel data connectors

Typical Use Cases

Long-term retention of security telemetry
Regulated organizations must retain security data verifiably for years. The data lake tier is designed for retention periods of up to 12 years without putting that data out of reach for analysis.

Forensics and incident response
Historical context is decisive when working through a security incident. KQL queries and notebooks let you analyze past time ranges and promote relevant data into the analytics tier on demand.

Anomaly detection with your own models
Security data science teams use Jupyter notebooks with Python libraries to run their own machine learning models against raw data and refresh results on a schedule.

Consolidating heterogeneous security sources
Beyond Microsoft sources, firewall, proxy, DNS, EDR, and identity logs can be brought together through the existing Sentinel connectors and analyzed jointly.

Benefits

  • Cost control through tiered storage, on-demand data promotion, and a single copy of the data
  • Fully managed: no data infrastructure of your own to run
  • Open Parquet format and separation of storage and compute for interoperability and flexibility
  • Multiple analytics engines on the same data: KQL for queries, Python notebooks for deeper analysis
  • Native integration with Microsoft Sentinel SIEM and existing security operations workflows
  • Traceability through auditing enabled by default

Integration with innFactory

As a Microsoft Solutions Partner, innFactory supports your adoption of Microsoft Sentinel data lake: assessing your existing data sources and retention requirements, splitting data across the analytics and data lake tiers, building KQL queries and notebook-based analyses, and embedding all of it into your security operations processes.

We also advise on the architecture of your Azure security and data stack, for example in combination with Microsoft Defender, Microsoft Entra ID, and Azure Monitor. Contact us for a no-obligation consultation.

Typical Use Cases

Long-term retention of security telemetry across multiple years
Forensics and incident response with historical context
Anomaly detection with Python and machine learning libraries
Cost optimization by separating analytics tier and data lake tier
Consolidating Microsoft and third-party security data

Technical Specifications

0th Two storage tiers: analytics tier for hunting, alerting, and incident management; data lake tier for cost-effective long-term storage
1st Retention of security data and telemetry for up to 12 years
2nd Open Parquet file format, separation of storage and compute
3rd Single copy of the data; analytics tier data is mirrored to the lake tier
4th KQL query editor with IntelliSense and autocomplete, full KQL capability set
5th Jupyter notebooks with Python libraries for machine learning and visualization
6th One-time or scheduled jobs to promote data from the lake tier to the analytics tier
7th Audit log for data access, job management, and query events, enabled by default
8th Works with all existing Microsoft Sentinel data connectors

Frequently Asked Questions

How long can data be retained in Microsoft Sentinel data lake?

According to Microsoft, the data lake tier is designed for cost-effective retention of large volumes of security data for up to 12 years. Microsoft documents tier and retention details under 'Manage data tiers and retention in Microsoft Defender portal'.

What is the difference between the analytics tier and the data lake tier?

The analytics tier is the existing Microsoft Sentinel data tier supporting advanced hunting, alerting, and incident management, and is designed for high-performance analytics and real-time processing. The data lake tier provides centralized long-term storage for querying and Python-based analytics. Analytics tier data is mirrored to the lake tier, preserving a single copy of the data.

Which data sources can be connected?

The data lake works with all existing Sentinel data connectors. Microsoft lists all Microsoft Defender and Microsoft Sentinel data sources, Microsoft 365, Microsoft Entra ID, Microsoft Resource Graph, EDR platforms, firewall and network logs, cloud infrastructure and workload telemetry, identity and access logs, and DNS, proxy, and email telemetry.

Which tools are available for analysis?

A KQL query editor with IntelliSense and autocomplete, plus Jupyter notebooks with Python libraries for machine learning, advanced analytics, and visualization. Both can create jobs that promote data from the lake tier to the analytics tier.

Is access to the data lake audited?

Yes. Microsoft Sentinel data lake tracks activities in the lake, including data access through KQL queries, running notebooks, and creating, editing, running, and deleting jobs. Auditing is enabled by default.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Ready to start with Microsoft Sentinel data lake - Security Data Lake?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation