Flytja til Innovate Summit:
Lærðu hvernig flutningur og nútímavæðing í Azure getur aukið afköst, seiglu og öryggi fyrirtækisins, sem gerir þér kleift að tileinka þér gervigreind að fullu.Nýskrá núna
Þessi vafri er ekki lengur studdur.
Uppfærðu í Microsoft Edge til að nýta þér nýjustu eiginleika, öryggisuppfærslur og tæknilega aðstoð.
Connect Microsoft Power Platform and Microsoft Dynamics 365 Customer Engagement to Microsoft Sentinel
Grein
This article describes how to deploy the Microsoft Sentinel solution for Microsoft Business Apps to connect your Microsoft Power Platform and Microsoft Dynamics 365 Customer Engagement system to Microsoft Sentinel. The solution collects audit and activity logs to detect threats, suspicious activities, illegitimate activities, and more.
Mikilvægt
The Microsoft Sentinel solution for Microsoft Business Apps is currently in PREVIEW. The Azure Preview Supplemental Terms include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
The solution is a premium offering. Pricing information will be available before the solution becomes generally available.
Prerequisites
Before deploying the Microsoft Sentinel solution for Microsoft Business Apps, ensure that you meet the following prerequisites:
Your Log Analytics workspace must be enabled for Microsoft Sentinel
You must have read and write access to the workspace. You must be able to create:
Data Collection Rules/Endpoints, with the Microsoft.Insights/DataCollectionEndpoints, and Microsoft.Insights/DataCollectionRules
Your organization must use Dynamics 365 Customer Engagement and/or one or more of the Power Platform workloads.
Select Configuration > Data connectors, and locate any of the following data connectors you want to deploy:
Microsoft Dataverse
Microsoft Power Platform Admin Activity
Microsoft Power Automate
For each data connector, on the side pane, select Open connector page > Connect.
Configure data collection for Dataverse
When working with Microsoft Dataverse, Dataverse activity logging is available only for production environments, and isn't enabled by default. Enable auditing at both the global level for Dataverse, and for each Dataverse entity:
To enable auditing on default entities, import one of the following Power Platform managed solutions:
To enable auditing on custom entities, you must manually enable detailed auditing on each of the custom entities. For more information, see Manage Dataverse auditing.
To get the full incident detection value of the solution, we recommend that you enable, for each Dataverse entity you want to audit, the following options in the General tab of the Dataverse entity settings page:
Under the Data Services section, select Auditing.
Under the Auditing section, select Single record auditing and Multiple record auditing.
Make sure to save and publish your customizations.
Verify log ingestion to Microsoft Sentinel
After deploying your data connectors and configuring data collection, run activities like create, update, and delete to generate logs for data that you enabled for monitoring.
For Power Platform activity logs, wait 60 minutes for Microsoft Sentinel to ingest the data.
To verify that Microsoft Sentinel is getting the data you expect, run KQL queries against the data tables that collect logs from your data connectors.
For Microsoft Sentinel in the Azure portal, run KQL queries on the General > Logs page. In the Defender portal, run KQL queries in the Investigation & response > Hunting > Advanced hunting.
For example, to verify your Power Platform log ingestion, run the following query to return 50 rows from the table with the Power Apps activity logs.
Kusto
PowerPlatformAdminActivity
| take50
The following table lists the Log Analytics tables to query.
Demonstrate the use of Microsoft Power Platform solutions to simplify, automate, and empower business processes for organizations in the role of a Functional Consultant.
Learn about the Microsoft Sentinel solution for MS Business Apps, including Microsoft Power Platform, Microsoft Dynamics 365 Customer Engagement, and Microsoft Dynamics 365 Finance and Operations.