↳ GitHub sourceWorkbook

Microsoft Security Feature & Telemetry Utilization

Description

Surfaces whether telemetry from Microsoft security product families is actually flowing into this Microsoft Sentinel workspace. Each tab checks signal presence for Entra ID, Defender for Endpoint, Defender for Office 365, Purview, Defender for Cloud, and core Sentinel data sources. Empty results indicate no rows in the selected period and require connector configuration, table availability, and freshness validation.
Version
1.0.3
Declared author / publisher
Microsoft Sentinel community

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Connectors

Data types

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
MicrosoftSecurityLicenseUtilization
Additional source files 2Workbooks/MicrosoftSecurityLicenseUtilization.jsonsource ↗Workbooks/WorkbooksMetadata.jsonworkbook-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.