Skip to content

Home

M365 x Azure · by Andreas Rogge

Microsoft Security,
tested in practice.

Hands-on notes on Microsoft Sentinel, Defender XDR and AI agents. Real investigations, practical examples, and the lessons behind them.

Andreas Rogge
Andreas Rogge · Microsoft Security
DETECTIONINVESTIGATIONAUTOMATION

FIELD NOTES

Start with a real problem.

AI & AGENT IDENTITY

One agent. Two identities.
A confusing 403.

A hands-on account of connecting a custom MCP tool to Foundry—and discovering which identity actually makes the call.

Read the investigation

MICROSOFT SENTINEL

From events to intent.

Onboarding the UEBA Behaviors layer and using it to add context to investigations.

Read the walkthrough

DATA & AUTOMATION

Choose the right way to query.

KQL, async queries, jobs and notebooks: working with Sentinel Data Lake in practice.

Explore the options

NEXT UP · IN ENGLISH

From field notes
to video walkthroughs.

I’m preparing my first English-language videos: focused demos with companion notes, useful queries and the details that matter when you try it yourself.

The channel is live. The first English-language walkthrough is in preparation.

Visit my YouTube channel ↗
01 / PLANNED PILOT

Foundry Agent Identity

Two Identities, One Confusing 403

Read the story behind the pilot ↗

THE PERSON BEHIND THE NOTES

Hi, I’m Andreas.

I work with Microsoft Sentinel and Defender XDR, with a focus on detection, investigation and improving day-to-day security operations. This is my personal space for sharing what I learn along the way.

Expect practical examples, honest troubleshooting and a closer look at how things behave outside the documentation.

Connect on LinkedIn ↗

LET’S TALK SECURITY

Questions, feedback
or an idea for a video?

Connect with me on LinkedIn, or explore my work on GitHub. For a question about a specific article, you can also use its comments.

KEEP EXPLORING

Latest articles.