Detection needs something worth detecting on.
A SIEM is only as good as the events it receives. B5’s decisions are unusually high-signal events — each one names a caller, a record, a purpose and a reason code — which makes them worth getting into Sentinel in a usable shape.
This capability is a Q4 2026 roadmap extension. The sections below describe the planned shape and evidence; production availability has not yet been declared. The status above is rendered from the Product Truth Registry.
1. What this enforces
Nothing. This is an export boundary, and naming it that way matters: B5 produces evidence, Sentinel correlates and alerts on it, and a response playbook may then act.
2. Where it enforces
After the decision. The enforcement already happened in-process; this is the path by which a pattern across many decisions becomes visible.
3. What evidence it produces
The same decision records, shaped for analytics rather than for an examiner: queryable, correlatable and retained on the SIEM’s terms as well as B5’s.
4. Why you cannot assemble this from what you already own
Sentinel cannot detect an authorization anomaly it never receives, and application logs rarely carry the authority under which an action ran. The useful signal is not ‘a request occurred’ but ‘this caller was denied this record for this reason, eleven times, in four minutes’.
5. What Q4 2026 adds
Microsoft Sentinel and Defender Content
Connector, analytics rules, hunting queries, workbooks, incident enrichment and response playbooks.
6. Acceptance criteria
The specification defines this capability against the three baseline criteria that apply to every Q4 2026 extension — documentation with failure modes and a runbook, automated coverage of primary and abuse cases, and telemetry that emits evidence without exposing prohibited data. Capability-specific criteria have not been written yet, and this page will state them when they are rather than inventing them now.
- The capability is documented with configuration, failure modes, security implications and an operational runbook.
- Automated unit, integration, negative and regression tests cover the primary and abuse cases.
- Telemetry and audit evidence are emitted without exposing prohibited sensitive data.
7. Dependencies
Beyond the platform baseline every extension depends on — the B5 security context, the evidence pipeline, configuration, the tenant model and the release registry — this capability also depends on:
- Microsoft Entra and Azure integration packages.
8. What is still open
The following are genuinely undecided rather than merely undocumented, and each one changes what the capability is:
- Which decisions are exported by default — all, denials only, or a policy-driven selection. Exporting everything is expensive; exporting denials only hides the permit that should not have been.
- Whether a response playbook may revoke through B5, and if so under what authority. Automated revocation is a powerful and dangerous capability.
- Whether Defender signals feed back in as decision context.
Every Q4 2026 extension is also held to four platform-wide requirements, six test classes and four release gates. They are published once, on the Q4 2026 roadmap, rather than repeated on every page.
Detection is half of it. Response is the other half.
Exporting decisions to a SIEM makes a pattern visible. Acting on that pattern still requires something to act through. B5 exposes revoke, suspend and tighten-limit as authorised, recorded operations a response playbook can call — so “this delegate was denied the same record eleven times in four minutes” can end with the authority withdrawn rather than with a ticket.
We are able to offer that safely for one reason: revocation here is already fail-closed, and an instruction that has been accepted but not completed fails unless the grant’s owner elected otherwise in advance. Automated revocation is dangerous when revocation semantics are vague. Ours are not.
This is the highest-risk capability on our roadmap and we would rather say so. A playbook that revokes too broadly is an outage, so it carries its own authority model, dual approval, and a blast-radius limit — and none of it ships before those do.
Status: Q4 2026 Roadmap ExtensionThird-Party Integration