Skip to main content
TechExplainedTechExplained
|
Use CaseTechnology: Microsoft SentinelIndustry: Manufacturing

Manufacturing: one SOC across office, plant and cloud with Microsoft Sentinel

A global car manufacturer reduced a landscape of hundreds of custom-built tools to a single security picture across office, production, cloud and supply chain, with Microsoft Defender on the endpoints and Microsoft Sentinel as the SOC.

TechExplained 5 min readPublished: 8 August 2026
Microsoft SentinelMicrosoft Defender XDRMicrosoft PurviewMicrosoft Entra ID
#security operations#zero trust#endpoint security#OT security#security
Overview of Microsoft Defender across a data and AI chain, with security layers over ingest, storage, processing, models and analysis

Business challenge

For years, a global car manufacturer secured every domain in its own way. Hundreds of custom-built tools sat side by side: one set for the back office, one for manufacturing systems, one for cloud, and more again around the supply chain and customer data. Each piece did its job in isolation. Together they did not produce a picture.

That became a problem once ransomware began targeting production lines specifically. An attack that starts on a laptop and ends with a line standing still runs straight through the seams of that kind of landscape, and the seams were exactly where nobody was looking. At the same time the manufacturer had to demonstrate compliance with GDPR and ISO 27001 across a hybrid estate of owned datacenters and cloud, which is not possible with evidence that is assembled differently in every tool.

Architecture

The core of the design is that detection converges in one place and protection is the same everywhere.

Microsoft Defender runs on thousands of endpoints, from employee laptops to manufacturing systems. That last part is the most consequential choice here: the shop floor falls under the same regime as the office environment rather than under an exception of its own. Defender XDR feeds those endpoints with threat intelligence drawn from Microsoft's global signal volume, so a pattern already seen elsewhere does not have to be discovered again here.

Microsoft Sentinel is the layer above and acts as the centralized security operations center. Sentinel ingests signals from every domain, correlates them into a single incident and automates first-line response. That removes the main blind spot: a series of separate alerts in four environments becomes one chain with a beginning and an end.

Microsoft Purview covers the data side. Classification is automated, and data loss prevention and encryption follow from it. Microsoft Entra ID provides the identity layer that access to all of this rests on.

A Zero Trust approach sits across the whole estate: no implicit trust based on network location, including inside the plant. On the build side, the Security Development Lifecycle is the starting point, so security in the manufacturer's own software is not bolted on afterwards.

Why this choice

The premise was not that the old tools did not work, but that they did not talk to each other. In an organisation with hundreds of custom-built solutions, the exposure sits between the systems rather than inside them. Consolidating onto one SIEM is therefore not a cost exercise but a detection question: only when the signals sit together can you follow an attack that jumps from domain to domain.

The second reason is demonstrability. An audit question about GDPR or ISO 27001 cannot be answered with evidence that is built differently in every tool. One chain means one way of showing what happened.

Alternatives

Keeping the existing tools and building an integration layer on top was the cheapest route on paper. It failed because that layer has to be maintained, and with hundreds of sources it becomes a product in its own right. Every change in a source becomes a change in the integration.

Consolidating per domain, so one tool for office and one for production, is the variant closest to the existing organisation. That is precisely why it does not solve the problem: the attack that starts on a laptop and ends at a production line still falls between two pictures.

Fully outsourcing the SOC was the third option. It scales well on volume, but an external party lacks the knowledge of a manufacturing environment needed to judge what an anomaly means and what is a normal peak.

Trade-offs

  • Sending everything to one SIEM costs money per ingested gigabyte. Deciding which sources go in full and which go in summarised belongs in the design, not in the invoice afterwards.
  • Bringing manufacturing systems under the same regime as office equipment is the hardest part, technically and organisationally. An agent on a machine that drives a production line calls for a different conversation than an agent on a laptop.
  • Consolidation means letting go of custom-built tools that teams are attached to. That is not a technical objection, but it is the biggest source of delay.
  • One picture also means one place where things go wrong if ingestion falters. Monitoring the monitoring is not a luxury.

Microsoft products

Microsoft Sentinel, Microsoft Defender and Microsoft Defender XDR, Microsoft Purview, Microsoft Entra ID.

Best practices

  • Do not treat the shop floor as an exception. The moment production gets a regime of its own, you create exactly the seam an attack travels through.
  • Decide up front, per source, whether it enters the SIEM in full or summarised. Correcting ingestion cost afterwards is more expensive than choosing beforehand.
  • Let classification be the basis for prevention and encryption, not the other way round. Without knowing what is in a file, every control is a generic control.
  • Invest in training for the people who have to read the picture. Microsoft learning modules and game-based simulations work better here than an annual presentation.

Lessons learned

According to the team, the gain was less about new detection capability and more about visibility. The telemetry needed to see the full picture had not been there before, which left the security teams wrestling with the patchwork of systems rather than with the threat itself.

The driver was therefore a scale problem rather than a product requirement. It was not only about securing datacenters, but about unifying the entire approach to security across hundreds of custom-built tools. That order, approach first and tooling second, shaped the whole programme.

Manufacturing: one SOC across office, plant and cloud