MS Sentinel and B2C Tenant Identity Protection Connector

Shim Kwan 301 Reputation points
2022-10-04T06:51:30.673+00:00

Hi,

We know how to deploy the MS Sentinel AAD Identity Protection Connector.
However, we are wanting to monitor our AAD B2C tenant using MS Sentinel (which is running in our regular AAD tenant).
Since the B2C Tenant also has its own Identity Protection (https://learn.microsoft.com/en-us/azure/active-directory-b2c/identity-protection-investigate-risk?pivots=b2c-user-flow), is there a way to deploy a MS Sentinel Connector for the B2C Tenant's Identity Protection?

Thank you,
SK

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Microsoft Security | Microsoft Sentinel
{count} votes

Accepted answer
  1. JamesTran-MSFT 36,911 Reputation points Microsoft Employee Moderator
    2022-10-06T22:46:51.173+00:00

    @Shim Kwan
    Thank you for your post!

    When it comes to deploying the Microsoft Sentinel Connector to a B2C Tenant for Identity Protection, you should be able to accomplish this by following the tutorial to Configure security analytics for Azure Active Directory B2C data with Microsoft Sentinel.

    Configure security analytics for Azure Active Directory B2C data with Microsoft Sentinel:

    1. Prior to deploying a Microsoft Sentinel instance, you'll have to define where logs and metrics for a resource should be sent. For more info - Configure Azure AD B2C to send logs to Azure Monitor.
      Once you've enabled Diagnostic settings in Azure AD within your Azure AD B2C tenant:
      248276-image.png
    2. You can Deploy a Microsoft Sentinel instance
    3. Once your deployment is complete, you can then Create a Microsoft Sentinel rule for your Azure AD B2C tenant.
      248331-image.png

    Additional Links:
    Azure AD B2C Reports & Alerts Sentinel Workbooks
    Monitor Azure AD B2C with Azure Monitor

    I hope this helps!

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.


1 additional answer

Sort by: Most helpful
  1. George Moise 2,361 Reputation points Microsoft Employee
    2022-10-04T09:30:40.377+00:00

    Hello,

    The Azure Active Directory Identity Protection Data Connector will work only with the AAD Identity Protection from the same tenant as the Sentinel instance.
    In your scenario, you will need two Sentinel deployments (one in each tenant).
    In multi-tenant scenarios, you can still have the "Single pane of glass" by looking at all incidents from all Sentinel deployments from the same page: like presented here.

    I hope this helps!
    BR,
    George

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.