TL;DR
Cayosoft Guardian threat alerts from hybrid AD and Entra ID now appear as fully enriched incidents in Microsoft Sentinel, with investigation context and remediation guidance just one click away.
We are excited to share that Cayosoft Guardian now integrates with Microsoft Sentinel. Organizations already using Guardian to detect privilege escalations, suspicious authentication activity, and other identity threats across hybrid Active Directory and Entra ID can now surface those alerts directly within Sentinel, helping security teams investigate and respond from a centralized SOC workflow.
With the new Cayosoft Guardian connector for Microsoft Sentinel, every threat Guardian detects lands directly in the Sentinel workspace as an incident, alongside the rest of the SOC’s telemetry, the moment it’s raised. No separate console to check, no alert to go looking for: just one more source feeding the queue your team already works from.
What Actually Lands in the Incident
Each Guardian threat alert arrives in Sentinel already enriched:
- Affected entities are automatically mapped in Sentinel: Accounts, hosts, security groups, DNS records, and cloud applications appear as Sentinel entities, giving analysts immediate visibility into what’s impacted.
- Severity is preserved and normalized for triage: Critical and High Guardian alerts map to High severity in Sentinel, while Medium, Low, and Informational alerts retain their appropriate priority.
- Attacker tactics are included when identified: Tactics such as credential access or persistence provide additional context about the nature and stage of the threat.
- Related alerts are grouped into a single incident: One incident reflects one threat, reducing investigation complexity and eliminating the need to manually correlate individual alerts.

Guardian's alerts work with your existing Sentinel signals and automation
Sentinel’s investigation graph links an incident to other alerts that share the same entity: an account, a host, a security group. Because Guardian maps each alert to the underlying Entra ID or Active Directory object, not just a name; that connection holds even across different products. If the same account also triggered an Entra ID protection risk detection or a Defender for Identity alert, the connection shows up automatically.
Automation rules can act on these incidents exactly like they act on every other incident type: tagging, assigning, running a playbook. Playbooks built on Azure Logic Apps can post to a Teams or Slack channel, open or update a ticket in ServiceNow or Jira, or take a containment action such as disabling an account, the moment one of Guardian’s alerts becomes an incident, without a separate integration built specifically for Guardian.
Guardian supplies identity-layer intelligence. Once that’s inside Sentinel as a properly mapped incident, it isn’t sitting apart from the rest of your tooling: it’s already positioned to feed whatever correlation and automation your SOC built for every other incident type.
From alert to remediation guidance
An alert that only says something happened still leaves the analyst to work out the response. Every incident from this connector links back to Cayosoft’s Threat Directory, so the remediation guidance for that specific threat is one click from the incident itself, not a separate search through a wiki or a support portal while the clock is running.

The connector also ships an incidents dashboard workbook, so a security lead can see severity breakdowns, alert volume, and affected systems across the environment without leaving Sentinel to build that view manually. That’s useful mid-incident, and just as useful for spotting a pattern, like the same account or host turning up across multiple alerts, before it becomes the next incident.
Microsoft Sentinel already correlates signals across a security estate. This connector means Guardian’s hybrid AD and Entra ID threat alerts are part of that correlation from the moment they’re raised, not something an analyst has to go looking for in a second console.
Get the connector today on Microsoft Marketplace, or Microsoft Security Store.
See Every Change. React Instantly
Identity Threat Detection and Response for Active Directory, Entra ID, Intune & Microsoft 365.