This tutorial shows how to set up Jupyter Notebooks for the Microsoft Sentinel data lake using Visual Studio Code. Starting from the Notebooks page in the Defender portal, it explains why notebooks are created outside the portal and then installs the Microsoft Sentinel extension for Visual Studio Code with Auto Update enabled. The video explores the extension’s Lake Tables, Jobs, and Notebook Samples panes; signs in to the data lake; and reviews schemas for system tables and connected workspaces, including EntraUsers and DeviceInfo. It then opens an IPYNB file, demonstrates how notebooks combine markdown, documentation, images, and executable Python code, initializes the Microsoft Sentinel Provider SDK, selects the Sentinel kernel, and chooses a small, medium, or large compute pool to start the session.
For this installment, we turned a highly procedural setup recording into an onboarding experience with fewer opportunities to wander into the weeds and begin questioning one’s life choices. The editorial structure introduces each tool just before it becomes useful, while close framing and deliberate pauses keep extension panes, schemas, code cells, and kernel choices easy to follow. Voiceover recorded in our studio supplies the friendly hand-holding, and the finished mix keeps every instruction crisp. A technical setup video, yes—but one that behaves itself.



