M365 x Azure · by Andreas Rogge
Microsoft Security,
tested in practice.
Hands-on notes on Microsoft Sentinel, Defender XDR and AI agents. Real investigations, practical examples, and the lessons behind them.

FIELD NOTES
Start with a real problem.
AI & AGENT IDENTITY
One agent. Two identities.
A confusing 403.
A hands-on account of connecting a custom MCP tool to Foundry—and discovering which identity actually makes the call.
Read the investigationMICROSOFT SENTINEL
From events to intent.
Onboarding the UEBA Behaviors layer and using it to add context to investigations.
Read the walkthroughDATA & AUTOMATION
Choose the right way to query.
KQL, async queries, jobs and notebooks: working with Sentinel Data Lake in practice.
Explore the optionsNEXT UP · IN ENGLISH
From field notes
to video walkthroughs.
I’m preparing my first English-language videos: focused demos with companion notes, useful queries and the details that matter when you try it yourself.
The channel is live. The first English-language walkthrough is in preparation.
Visit my YouTube channel ↗Foundry Agent Identity
Two Identities, One Confusing 403
Read the story behind the pilot ↗THE PERSON BEHIND THE NOTES
Hi, I’m Andreas.
I work with Microsoft Sentinel and Defender XDR, with a focus on detection, investigation and improving day-to-day security operations. This is my personal space for sharing what I learn along the way.
Expect practical examples, honest troubleshooting and a closer look at how things behave outside the documentation.
Connect on LinkedIn ↗LET’S TALK SECURITY
Questions, feedback
or an idea for a video?
Connect with me on LinkedIn, or explore my work on GitHub. For a question about a specific article, you can also use its comments.
KEEP EXPLORING
Latest articles.
- Forbidden by the Spec, Documented by Microsoft: Agent Identity for a Custom MCP Tool in Foundry
- From Events to Intent: How to Onboard and Use the UEBA Behaviors Layer in Microsoft Sentinel
- Microsoft Security Weekly: Sentinel Playbook Generator, ConsentFix Alert, and AI Agent Protection
- Sentinel Data Lake is getting “operational”: how to choose KQL vs Async vs Jobs vs Notebooks (and why a small schema change can break big automations)
- When Logs Start Telling Stories: UEBA Behaviors in Microsoft Sentinel
- Maximizing Cybersecurity with SOAR in Microsoft Sentinel: An overview
