SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Fortified digital shield surrounded by interconnected data streams network nodes cyber defense

BlueVoyant joins Microsoft Sentinel to boost global cyber defence

Fri, 3rd Oct 2025

BlueVoyant has announced its selection as a participant in the Microsoft Sentinel partner ecosystem, citing its experience with Microsoft Security technologies and ongoing collaboration with Microsoft.

The inclusion reflects BlueVoyant's involvement in shaping the capabilities and development of Microsoft Sentinel, a platform that is seeing growing relevance in enterprise cyber defence strategies. The company works closely with Microsoft product teams on product development, validation of new usage scenarios, and providing feedback on operations and integration elements like API extensibility.

Micah Heaton, Executive Director of Microsoft Product and Innovation Strategy at BlueVoyant, noted the long-standing partnership and the tangible effects of recent changes in the Sentinel offering.

"We've been in the trenches with Microsoft Sentinel since the beginning. BlueVoyant is privileged to support some of the largest Microsoft XDR investments in the world. The shift to Sentinel data lake is personal. It changes how fast defenders can move, how much they can see, and how confident they feel making decisions.

We helped shape this platform so our shared customers can get more clarity and context in every investigation. Now that it's here, we're building on it with custom analytics, Copilot-ready content, and lessons tested in the field. No fluff. No filler. Just what works, delivered at scale."

As part of the partner ecosystem, BlueVoyant is contributing solutions that make use of Sentinel's open architecture and advanced analytics. Among these are custom connectors, analytics modules, playbooks, hunting queries, Jupyter notebook jobs, and Security Copilot agents, all designed to be accessible to global customers through the Microsoft Security Store.

Microsoft Sentinel itself is undergoing a transition from its origins as a traditional Security Information and Event Management (SIEM) tool to become an AI-ready platform. The new version aims to equip security defenders with unified security data, intelligent reasoning tools, and more sophisticated context driven by graph-powered visibility. The scalability and extended context are expected to support defence teams in large organisations, with the platform now acting as a broader defence backbone.

Vasu Jakkal, Corporate Vice President of Microsoft Security, explained the company's vision for Sentinel and the role of the partner ecosystem in the ongoing development of cyber defence tools.

"We've reimagined Microsoft Sentinel as an AI-ready platform, unifying security data into a single, enriched data lake that delivers graph-powered visibility and intelligent agent capabilities. This transformation positions Microsoft Sentinel as the backbone of modern defense, offering deep context, connected insights, and empowering security teams to act with precision, and stay ahead of evolving threats.

This transformation is amplified by a vibrant partner ecosystem. We are grateful to our partners that use Microsoft Sentinel to create integrated solutions and make them available in the Microsoft Security Store. This collaboration powers a collective defense, because after all- security is a team sport."

The collaboration between Microsoft and BlueVoyant centres on advancing the platform's features and supporting customers with practical, tested content. BlueVoyant's work extends to product validation in emerging cyber threat scenarios and making best-practice tooling available more broadly. The objective is to help organisations address expanding security challenges by leveraging open, extensible architectures and continuously updated analytics.

In practical terms, BlueVoyant's solutions for Sentinel are designed to offer enhanced clarity and context for investigations, improved speed for frontline defenders, and greater confidence in security decision-making. The company notes that its contributions are guided by field experience and customer needs, with a focus on operational efficiency and actionable insights.

Microsoft Sentinel's evolution, together with its partner network, underpins ongoing efforts within the security sector to deliver integrated solutions that help organisations address an increasing volume and variety of cyber threats. Partners like BlueVoyant contribute to continual testing, content development, and extension of the platform's core capabilities for global users.