Forum Discussion

christian-knipping's avatar
christian-knipping
Copper Contributor
Mar 28, 2019

Multiple Subscriptions in Sentinel

Hello all,

 

Can I set up a central Azure Sentinel to monitor multiple subscriptions?

 

Or is one Azure Sentinel recommended per subscription?


Best

Christian

  • christian-knipping 

     

    At this time it's one Azure Sentinel Workspace per Tenant, Azure Sentinel works across subscriptions. Microsoft is in the process of looking into MSP (Managed Service Provider ) solutions but nothing has been publicly released at this time. Please feel free to reach out if you have any more questions.

    • Thuan Ng's avatar
      Thuan Ng
      Brass Contributor
      Could you elaborate on "across subscription"?
      • Chris Boehm's avatar
        Chris Boehm
        Icon for Microsoft rankMicrosoft
        Azure Sentinel is using Log Analytics within one tenant with one to multiple subscriptions. If you have multiple subscriptions they can interact with each other with RBAC permissions of data when pulling into a sentinel workspace. If you're wanting to know how to do “cross-tenant” data monitoring you’re required to use the MSSP solution “Azure Lighthouse” with Azure Sentinel.

        Is there a specific question to subscriptions that’s not clear in our documentation that we can improve upon?
    • Jarrod Winsor's avatar
      Jarrod Winsor
      Copper Contributor

      Chris Boehm is there any beta program an MSP could take part in to assist in trialing features :) Any idea of when something public may be released? For now if we set up a Azure tenant for the customer will there be a migration tool to bring into multi-tenant when that option is available?

       

       

      • Chris Boehm's avatar
        Chris Boehm
        Icon for Microsoft rankMicrosoft

        Jarrod Winsor 

         

        We'll most likely make the announcement within this communities page for the preview functionality, you're already looking in the best location at this time :)

         

        I don't have an answer at this time on the migration path if it'll just be a connection between workspaces with the key or if it'll be a different interface to integrate them. I'm sure we'll announce the details whenever they've been established.

         

        Great question!

         

        Thanks,

    • AndreaFisher's avatar
      AndreaFisher
      Icon for Microsoft rankMicrosoft

      Chris Boehm  Does it work across multiple subscriptions? Maybe I don't understand what you mean by that but I would like to bring in MCAS data from multiple tenants and that doesn't seem to be possible.

      • Chris Boehm's avatar
        Chris Boehm
        Icon for Microsoft rankMicrosoft

        AndreaFisher 

        We don't have multi-tenant support at this point. If all subs are on the same tenant, than it should work.

Resources