You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/extend-sentinel-across-workspaces-tenants.md
+5-3Lines changed: 5 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,10 +1,10 @@
1
1
---
2
2
title: Extend Microsoft Sentinel across workspaces and tenants
3
3
description: How to use Microsoft Sentinel to query and analyze data across workspaces and tenants.
4
-
author: yelevin
4
+
author: batamig
5
5
ms.topic: concept-article
6
-
ms.date: 03/17/2025
7
-
ms.author: yelevin
6
+
ms.date: 06/10/2025
7
+
ms.author: bagol
8
8
appliesto:
9
9
- Microsoft Sentinel in the Microsoft Defender portal
10
10
- Microsoft Sentinel in the Azure portal
@@ -54,6 +54,8 @@ Query [multiple workspaces](/azure/azure-monitor/logs/cross-workspace-query) to
54
54
55
55
Then, write a query across both workspaces by beginning with `unionSecurityEvent | where ...` .
56
56
57
+
Cross-workspace queries for Log Analytics data remain subject to [Log Analytics limitations](/azure/azure-monitor/logs/cross-workspace-query#limitations).
58
+
57
59
### Include cross-workspace queries in scheduled analytics rules<aname="scheduled-alerts"></a>
58
60
59
61
<!-- Bookmark added for backward compatibility with old heading -->
Copy file name to clipboardExpand all lines: articles/sentinel/whats-new.md
+24-8Lines changed: 24 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ description: Learn about the latest new features and announcement in Microsoft S
4
4
author: batamig
5
5
ms.author: bagol
6
6
ms.topic: concept-article
7
-
ms.date: 07/01/2025
7
+
ms.date: 07/08/2025
8
8
#Customer intent: As a security team member, I want to stay updated on the latest features and enhancements in Microsoft Sentinel so that I can effectively manage and optimize my organization's security posture.
9
9
ms.custom:
10
10
- build-2025
@@ -20,27 +20,43 @@ The listed features were released in the last six months. For information about
20
20
21
21
## July 2025
22
22
23
+
-[No limit on the number of workspaces you can onboard to the Defender portal](#no-limit-on-the-number-of-workspaces-you-can-onboard-to-the-defender-portal)
24
+
-[Microsoft Sentinel in the Azure portal to be retired July 2026](#microsoft-sentinel-in-the-azure-portal-to-be-retired-july-2026)
25
+
26
+
### No limit on the number of workspaces you can onboard to the Defender portal
27
+
28
+
There is no longer any limit to the number of workspaces you can onboard to the Defender portal.
29
+
30
+
Limitations still apply to the number of workspaces you can include in a Log Analytics query, and in the number of workspaces you can or should include in a scheduled analytics rule.
31
+
32
+
For more information, see:
33
+
34
+
-[Connect Microsoft Sentinel to the Microsoft Defender portal](/unified-secops-platform/microsoft-sentinel-onboard?toc=%2Fazure%2Fsentinel%2FTOC.json&bc=%2Fazure%2Fsentinel%2Fbreadcrumb%2Ftoc.json)
35
+
-[Multiple Microsoft Sentinel workspaces in the Defender portal](workspaces-defender-portal.md)
36
+
-[Extend Microsoft Sentinel across workspaces and tenants](extend-sentinel-across-workspaces-tenants.md)
37
+
23
38
### Microsoft Sentinel in the Azure portal to be retired July 2026
The Microsoft Sentinel Codeless Connector Platform (CCP) has been renamed to **Codeless Connector Framework (CCF)**. The new name reflects the platform's evolution and avoids confusion with other platform-orineted services, while still providing the same ease of use and flexibility that users have come to expect.
50
+
The Microsoft Sentinel Codeless Connector Platform (CCP) has been renamed to **Codeless Connector Framework (CCF)**. The new name reflects the platform's evolution and avoids confusion with other platform-oriented services, while still providing the same ease of use and flexibility that users have come to expect.
36
51
37
-
For more information, see [Create a codeless connector](create-codeless-connector.md) and [Unlock the potential of Microsoft Sentinel’s Codeless Connector Framework and do more with Microsoft Sentinel faster](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/exciting-announcements-new-data-connectors-released-using-the-codeless-connector/4421104).
52
+
For more information, see [Create a codeless connector for Microsoft Sentinel](create-codeless-connector.md).
38
53
39
-
### Connector documentation consolidation
54
+
### Consolidated Microsoft Sentinel data connector reference
40
55
41
-
We have consolidated the connector reference documentation, merging the separate connector articles into a single, comprehensive reference table. You can find the new connector reference at [Microsoft Sentinel data connectors](/azure/sentinel/data-connectors-reference#sentinel-data-connectors).
56
+
We've consolidated the connector reference documentation, merging the separate connector articles into a single, comprehensive reference table.
42
57
43
-
Select the connector name to expand the row and see the details.
58
+
You can find the new connector reference at [Microsoft Sentinel data connectors](/azure/sentinel/data-connectors-reference#sentinel-data-connectors).
59
+
For more information, see [Create a codeless connector](create-codeless-connector.md) and [Unlock the potential of Microsoft Sentinel’s Codeless Connector Framework and do more with Microsoft Sentinel faster](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/exciting-announcements-new-data-connectors-released-using-the-codeless-connector/4421104).
Copy file name to clipboardExpand all lines: articles/sentinel/workspaces-defender-portal.md
+6-5Lines changed: 6 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ description: Learn about the support of multiple workspaces for Microsoft Sentin
4
4
author: batamig
5
5
ms.author: bagol
6
6
ms.topic: concept-article
7
-
ms.date: 05/26/2025
7
+
ms.date: 06/10/2025
8
8
appliesto:
9
9
- Microsoft Sentinel with Defender XDR in the Defender portal
10
10
@@ -77,9 +77,9 @@ If you have the appropriate permissions to view data from primary and secondary
77
77
|**Search**| The results from the global search at the top of the browser page in the Defender portal provide an aggregated view of all relevant workspace data that you have permissions to view. |
78
78
|Investigation & response > Incidents & alerts > **Incidents**| View incidents from different workspaces in a unified queue or filter the view by workspace. |
79
79
|Investigation & response > Incidents & alerts > **Alerts**| View alerts from different workspaces in a unified queue or filter the view by workspace.<br><br> The Defender portal segments alert correlation by workspace. |
80
-
|Entities: From an incident or alert > select a device, user, or other entity asset | View all relevant entity data from multiple workspaces in a single entity page. Entity pages aggregates alerts, incidents, and timeline events from all workspaces to provide deeper insights into entity behavior. <br><br>Filter by workspace in **Incidents and alerts**, **Timeline**, and **Insights** tabs. The **Overview** tab displays entity metadata aggregated from all workspaces. |
81
-
|Investigation & response > Hunting > **Advanced hunting**| Select a workspace from the top right-hand side of the browser. Or, query across multiple workspaces by using the workspace operator in the query. See [Query multiple workspaces](extend-sentinel-across-workspaces-tenants.md#query-multiple-workspaces). The query results don't show a workspace name or ID.<br><br>Access all log data of the workspace, including queries and functions, as read only. For more information, see [Advanced hunting with Microsoft Sentinel data in Microsoft Defender portal](/defender-xdr/advanced-hunting-microsoft-defender). <br><br>Some capabilities are limited to the primary workspace:<br>- Creating custom detections<br>- Queries via API |
82
-
|**Microsoft Sentinel** experiences|View data from one workspace for each page in the Microsoft Sentinel section of the Defender portal. Switch between workspaces by selecting **Select a workspace** from the top-right hand side of the browser for most pages. The **Workbooks** page only shows data associated with the primary workspace.|
80
+
|**Entities**: From an incident or alert > select a device, user, or other entity asset | View all relevant entity data from multiple workspaces in a single entity page. Entity pages aggregates alerts, incidents, and timeline events from all workspaces to provide deeper insights into entity behavior. <br><br>Filter by workspace in **Incidents and alerts**, **Timeline**, and **Insights** tabs. The **Overview** tab displays entity metadata aggregated from all workspaces. |
81
+
|Investigation & response > Hunting > **Advanced hunting**| Select a workspace from the top right-hand side of the browser. Or, query across multiple workspaces by using the workspace operator in the query. See [Query multiple workspaces](extend-sentinel-across-workspaces-tenants.md#query-multiple-workspaces). The query results don't show a workspace name or ID.<br><br>Access all log data of the workspace, including queries and functions, as read only. For more information, see [Advanced hunting with Microsoft Sentinel data in Microsoft Defender portal](/defender-xdr/advanced-hunting-microsoft-defender). <br><br>Some capabilities are limited to the primary workspace:<br>- Creating custom detections<br>- Queries via API <br><br>Cross-workspace queries for Log Analytics data remain subject to [Log Analytics limitations](/azure/azure-monitor/logs/cross-workspace-query#limitations). |
82
+
|**Microsoft Sentinel** experiences|View data from one workspace for each page in the Microsoft Sentinel section of the Defender portal. Switch between workspaces by selecting **Select a workspace** from the top-right hand side of the browser for most pages. <br><br>- The **Workbooks** page only shows data associated with the primary workspace. <br><br>Cross-workspace analytics rules remain subject to [cross-workspace analytics rules limitations and recommendations](extend-sentinel-across-workspaces-tenants.md#include-cross-workspace-queries-in-scheduled-analytics-rules). |
83
83
|**SOC optimization**|Data and recommendations are aggregated from multiple workspaces. |
84
84
85
85
@@ -101,4 +101,5 @@ Also, if the direct [Microsoft 365 Insider Risk Management connector for Microso
0 commit comments