Securing 2M+ accounts & $15B+ in assets, protected & secure·B5 Secure™ — per data-element authorization for .NET platforms

Sentinel and Defender

← Microsoft
Microsoft

Detection needs something worth detecting on.

A SIEM is only as good as the events it receives. B5’s decisions are unusually high-signal events — each one names a caller, a record, a purpose and a reason code — which makes them worth getting into Sentinel in a usable shape.

ConnectorsAnalytics rulesWorkbooksHuntingPlaybooks
Q4 2026 Roadmap ExtensionThird-Party Integration

This capability is a Q4 2026 roadmap extension. The sections below describe the planned shape and evidence; production availability has not yet been declared. The status above is rendered from the Product Truth Registry.

Detection is half of it. Response is the other half.

Exporting decisions to a SIEM makes a pattern visible. Acting on that pattern still requires something to act through. B5 exposes revoke, suspend and tighten-limit as authorised, recorded operations a response playbook can call — so “this delegate was denied the same record eleven times in four minutes” can end with the authority withdrawn rather than with a ticket.

We are able to offer that safely for one reason: revocation here is already fail-closed, and an instruction that has been accepted but not completed fails unless the grant’s owner elected otherwise in advance. Automated revocation is dangerous when revocation semantics are vague. Ours are not.

This is the highest-risk capability on our roadmap and we would rather say so. A playbook that revokes too broadly is an outage, so it carries its own authority model, dual approval, and a blast-radius limit — and none of it ships before those do.

Status: Q4 2026 Roadmap ExtensionThird-Party Integration

Scroll to Top