Microsoft Sentinel log sources for DORA and NIS2 evidence

By Yaïr Knijn, Microsoft Certified Trainer — Updated 10 May 2026

Operational resilience evidence depends on logs you can actually search. For Microsoft cloud teams, the first Sentinel question is whether identity, Microsoft 365 audit, Defender, and Azure activity signals are landing where responders can use them.

Primary source checked on 2026-05-10: Stream data from Microsoft Defender XDR to Microsoft Sentinel. Use the Microsoft page as the final source of truth before booking an exam or committing a remediation plan.

Who this is for

  • Security teams preparing incident evidence for DORA, NIS2, or customer reviews.
  • Microsoft 365 admins who need to prove audit coverage beyond screenshots.
  • Azure teams deciding which connectors and retention settings matter first.

What to work on first

  • Verify Entra sign-in and audit logs, Microsoft 365 activity logs, Defender XDR incidents, Azure Activity, and key workload logs.
  • Document retention, workspace ownership, alert rules, and who can query each evidence source.
  • Test one incident walkthrough from alert to investigation notes and post-incident evidence.

Team training angle

A Sentinel readiness workshop should connect data connectors to incident response duties, not only enable every connector in the gallery.

One-week action plan

  • Day 1: inventory required evidence sources.
  • Day 2: connect or validate Entra and Microsoft 365 audit signals.
  • Day 3: stream Defender XDR incidents and alerts where appropriate.
  • Day 4: review retention, access, and alert routing.
  • Day 5: run a mini incident exercise and capture evidence gaps.

Where Cloud Evolvers fits

Cloud Evolvers can review Microsoft Sentinel evidence coverage and produce the first remediation plan for DORA, NIS2, NIST, or CIS discussions.

Need a first Microsoft cloud compliance backlog? Run the free readiness scanner.

Run the readiness scanner

Frequently asked questions

Do we need every Sentinel connector for DORA?

No. Start with the evidence sources that support identity, incident, cloud activity, and critical workload investigations.

Is Microsoft 365 audit data useful in Sentinel?

Yes. Microsoft documents Microsoft 365 activity logs as Sentinel connector data for user and admin activity investigations.