Can we send Defender for Cloud's logs to Sentinel's LAW without "Defender for cloud connector" configured in Sentinel?

Rakesh Singh 390 Reputation points
2024-11-12T14:28:00.0966667+00:00

Question: While deploying Defender for Cloud, if we select the same LAW (workspace) that Sentinel is using, do we still need to configure Defender for Cloud connector and configure it in Sentinel? In this scenario, do Defender for Cloud and Sentinel's LAW should be in the same Subscription?

And also, if we use a different LAW for Defender for cloud, can we add another LAW in Defender for cloud which would be the same LAW used by Sentinel? If yes, can you share a link that explains Defender for cloud's workspace configurations?

Regards,
Rakesh Singh

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Microsoft Security | Microsoft Sentinel
{count} votes

1 answer

Sort by: Most helpful
  1. Andrew Blumhardt 10,051 Reputation points Microsoft Employee
    2024-11-25T13:31:21.0433333+00:00

    Good question. :-)

    Think of Def for Cloud as having three datasets. You have the alerts, the data behind to visuals like recommendations, and the Defender for Servers data.

    Alerts are sent to Sentinel using a data connector. It is a common misconception that this connector contains data. Alerts from 1st party Microsoft services are free in Sentinel. The Sentinel-MDC connector is going away, replaced by the new Unified XDR portal. If and when you activate the unified portal, MDC alerts will flow into Unified XDR first with no additional configuration or connector required. The MDC alerts become part of Sentinel via the XDR connector. Point being that the MDC connector in Sentinel is going away.

    Your MDC background data like recommendations and attack paths are stored in each subscription in the resource graph. This data does not contain much in the way of hunting but you may want to store this in a workspace for retention, compliance, or easier reporting. Some of the MDC reports also require that you export this data. Best practice is to choose a central workspace like Sentinel. This data is negligible in size but not free. https://learn.microsoft.com/en-us/azure/defender-for-cloud/benefits-of-continuous-export

    Defender for Servers will create a default workspace for each subscription at activation. You can redirect D4S to use a different workspace. It is a best practice to redirect all subscriptions to a central workspace and if you choose Sentinel, there is a potential cost savings. The 500MB discount associated for MDC only applies to specific tables and only to the linked workspace(s), preferably Sentinel. This is configured in environmental settings for each subscription or by policy. This data can be larger but mostly covered by the 500MB discount. Most notably, Windows Security Events is the only table involved of significant size.

    Defender for Servers has an option to collect Windows Security Event logs, though it is highly recommended that you do not use this option if collecting security events with Sentinel. I think the MDC option may even be auto disabled when using Sentinel. Doing so would duplicate a potentially expensive dataset. If you link Defender for Servers to Sentinel by sharing the same workspace, the 500MB discount will help to offset security event ingestion costs, even if collected by the Sentinel connector. Also, with Sentinel split pricing the 500MB discount applies only to the workspace cost but with Sentinel simplified pricing the discount applies to both.

    Lastly, there is a roadmap in development that has largely been deployed to eliminate the reliance on the deprecated Microsoft Monitoring Agent and Azure Monitoring Agent. Replacing reliance on an agent with agentless and Defender for Endpoint capabilities. Since the MDE sensor is part of the OS. It should be possible to use Defender for Servers without an agent and therefore without a workspace. Though there are some lingering workspace dependencies like Defender for SQL. The 500MB discount will continue to be available, even when a workspace is not specifically defined.

    Complicated right? :-)

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.