Configuring a Windows Endpoint for Cloud SIEM Monitoring in Microsoft Sentinel
After Setting up Microsoft Sentinel, the next step is to create a Windows virtual machine that will act as an endpoint for monitoring and…
Configuring a Windows Endpoint for Cloud SIEM Monitoring in Microsoft Sentinel
After **Setting up Microsoft Sentinel**, the next step is to create a Windows virtual machine that will act as an endpoint for monitoring and attack simulation. This machine generates security events that are collected and analyzed in Microsoft Azure to enable threat detection and SOC operations.

Creating a Windows Virtual Machine
- Search for Virtual Machines in Microsoft Azure search bar and open it.

- The Virtual Machine configuration screen appears. Click Create and select Virtual Machine.

- Under the Basics tab, select your resource group and provide a virtual machine name.

- Scroll down to the Image section and select a Windows operating system such as Windows 10, Windows 11 or Windows Server.
- Choose the VM size based on your requirements and pricing.

Note Compute sizes vary depending on your subscription and region. Select a size that fits your available resources and budget.
- Provide a username and password for the host machine. Under Inbound ports, select RDP (3389) and accept licensing.
- Review all tabs and click Review + Create.

- After validation passes, click Create.

- Wait for deployment to complete.

- Search for Virtual Machines again and confirm that the virtual machine status is Running.

Installing Windows Security Events in Microsoft Sentinel
- Search for Microsoft Sentinel in Microsoft Azure portal and open it.
- Select SIEMworkspace, then go to Content Management and click Content Hub.

Note If you are informed to navigate to the Microsoft Defender portal, click the provided link and continue. The process remains the same.
- Search for Windows Security Events in the Content Hub search bar.
- Select Windows Security Events and click Install.

Note The Windows Security Events solution enables the collection of security logs such as login attempts, account changes and policy modifications from Windows endpoints into Microsoft Sentinel.
- After installation completes, click Manage.

- The Windows Security Events page should appear.
- Select Windows Security Events via AMA and click Open Connector Page.

- Click Create Data Collection Rule.

Note A Data Collection Rule (DCR) defines what data is collected from endpoints and how it is sent to Microsoft Sentinel for monitoring and analysis.
- Provide a rule name and ensure the resource group name matches with the one you created earlier. Click Next: Resources >.

- Click your Azure Subscription with the resource group and the user machine. Proceed to Next: Collect >.

- Under the Collect tab, choose All Security Events and click Next Review + create >.

- After validation passes, click Create.

- Reload the page after deployment. The Windows Security Events via AMA status should now show Connected.

Interface in the Microsoft Defender platform
The Windows endpoint is now connected to Microsoft Sentinel through a Data Collection Rule, enabling centralized collection of security events from the virtual machine.
Next, we will simulate real-world attacks on the Windows machine and analyze the generated logs in Microsoft Sentinel to perform SOC operations and threat detection.
메타데이터
- post_id
- d526eb1a2c46
- slug
- configuring-a-windows-endpoint-for-cloud-siem-monitoring-in-microsoft-sentinel-d526eb1a2c46
- url
- https://medium.com/@jeffreyaaron84/configuring-a-windows-endpoint-for-cloud-siem-monitoring-in-microsoft-sentinel-d526eb1a2c46
- canonical_url
- https://medium.com/@jeffreyaaron84/configuring-a-windows-endpoint-for-cloud-siem-monitoring-in-microsoft-sentinel-d526eb1a2c46
- author_url
- https://medium.com/@jeffreyaaron84
- status
- ok
- fetched_at
- 2026-07-28 15:18:08