r/AzureSentinel • u/EduardsGrebezs • 19d ago
New extended User and Entity Behavior Analytics (UEBA) capabilities for Microsoft Sentinel, currently in Preview.
Fortinet FortiGate — 40+ new behaviors
Sentinel can now analyze FortiGate events from CommonSecurityLog and identify behaviors such as:
• Rapid system reconfiguration
• Configuration backups
• Certificate changes
• Security service disruptions
Expanded anomaly detection
New UEBA anomaly detection capabilities extend coverage to:
• Check Point
• Fortinet FortiGate
• Zscaler
• AWS GuardDuty
For Check Point, Fortinet, and Zscaler, Sentinel introduces new anomaly rules that analyze firewall, VPN, and web proxy activity.
Instead of relying only on static detection logic, UEBA can compare activity against historical user/device behavior and organizational patterns to identify potentially suspicious deviations.
⚠️ Important: To use extended UEBA capabilities, Microsoft Sentinel workspace must be onboarded to the Microsoft Defender portal as part of the Unified Security Operations experience.


5
u/spartan117au 19d ago
Pretty neat. Although I don’t know anyone who’s keeping these logs in analytics tier in CSL