Azure sentinel Azure AD logs

Eduards 791 Reputation points
2020-12-11T07:31:25.407+00:00

Hello,

I have question about Azure sentinel Azure AD "data connectors".

If my Azure sentinel is in subscription number 2. And i configure azure sentinel.

I want to install Azure AD connector to get information from other AD tenant where is my Office 365. Could i do it?

So basically Azure sentinel is in tenant number 1. And i want to add data connector for azure ad tenant number 2 and get logs

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
996 questions
0 comments No comments
{count} votes

Accepted answer
  1. JamesTran-MSFT 36,466 Reputation points Microsoft Employee
    2020-12-11T21:57:31.96+00:00

    @Eduards
    Thank you for your question!

    Azure Sentinel supports data collection from Microsoft and Azure SaaS resources only within its own Azure Active Directory (Azure AD) tenant boundary. Therefore, each Azure AD tenant requires a separate workspace. However, if you're a Managed Security Service Provider (MSSP), you can use Azure Lighthouse to extend Azure Sentinel cross-workspace capabilities across tenants.

    Manage multiple tenants in Azure Sentinel as an MSSP
    47467-image.png
    For more info - https://learn.microsoft.com/en-us/azure/sentinel/extend-sentinel-across-workspaces-tenants

    If you aren't an MSSP and would like to implement this feature for non MSSP's, please feel free to leverage our Azure Sentinel GitHub page to submit a feature request.

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

0 additional answers

Sort by: Most helpful