Organizations can use Microsoft Sentinel also to perform 'dragnet' searches for certain behaviors across log data sources according to various criteria in real time.
Via the query language KQL, they can search, for example, for employees who access certain resources or use 'noisy language' in emails.
Almost any functionality in Sentinel, including pre-built detections and reports, is based on KQL. Employers can search up to seven years of log data and 'bring' their 'own' ML models to Sentinel.
Yes, organizations must protect themselves from cyberattacks, data loss and criminal misconduct. This is not optional, and, in several ways, mandated by law (which itself may be problematic in some cases, e.g. NIS-2).
Nevertheless, intrusive security and risk surveillance raises serious concerns about misuse by employers, disproportionate monitoring and profiling across purposes, flawed risk assessments and arbitrary suspicions.