While Microsoft Purview combines various tools for security, risk profiling and compliance, Microsoft Sentinel specifically promises to help organizations prevent cyberattacks, including by 'insiders'.
At its core, Sentinel is a 'security information and event management' (SIEM) system. It analyzes log data on device, file, process, network and mail activity, up to millions of log records per second, including activity logs from Office, Exchange, Teams, Salesforce, SAP, Confluence/Jira, Zoom...
Sentinel can analyze log data from an organization's entire IT infrastructure.
As it can process alerts about suspicious employees from Purview (communication compliance, insider risk), Forcepoint/Everfox and other systems, it becomes a combined security and risk surveillance system.
Section 6 in my report summarizes the data practices/sources/purposes identified for Microsoft Sentinel.