Skip to content

Commit 02a1b37

Browse files
committed
Merge branch 'mult-workspace' of https://github.com/batamig/azure-docs-pr into mult-workspace
2 parents be9b39c + dfa0264 commit 02a1b37

File tree

2 files changed

+9
-6
lines changed

2 files changed

+9
-6
lines changed

articles/sentinel/whats-new.md

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -20,19 +20,22 @@ The listed features were released in the last three months. For information abou
2020

2121
## April 2025
2222

23-
- [Multi workspace support for Microsoft Sentinel (preview)](#multi-workspace-support-for-microsoft-sentinel-preview)
23+
- [Multi workspace and multi tenant support for Microsoft Sentinel in the Defender portal (preview)](#multi-workspace-and-multi-tenant-support-for-microsoft-sentinel-in-the-defender-portal-preview)
2424

25-
### Multi workspace support for Microsoft Sentinel (preview)
25+
### Multi workspace and multi tenant support for Microsoft Sentinel in the Defender portal (preview)
2626

2727
For preview, in the Defender portal, connect to one primary workspace and multiple secondary workspaces for Microsoft Sentinel. If you onboard Microsoft Sentinel with Defender XDR, a primary workspace's alerts are correlated with Defender XDR data. So incidents include alerts from Microsoft Sentinel's primary workspace and Defender XDR. All other onboarded workspaces are considered secondary workspaces. Incidents are created based on the workspace’s data and won't include Defender XDR data.
2828

29-
If you plan to use Microsoft Sentinel in the Defender portal without Defender XDR, you can manage multiple workspaces. But, the primary workspace doesn't include Defender XDR data and you won't have access to Defender XDR capabilities.
29+
- If you plan to use Microsoft Sentinel in the Defender portal without Defender XDR, you can manage multiple workspaces. But, the primary workspace doesn't include Defender XDR data and you won't have access to Defender XDR capabilities.
30+
- If you're working with multiple tenants and multiple workspaces per tenant, you can also use Microsoft Defender multitenant management to view incidents and alerts, and to hunt for data in Advanced hunting, across both multiple workspaces and tenants.
3031

3132
For more information, see the following articles:
3233

3334
- [Multiple Microsoft Sentinel workspaces in the Defender portal](workspaces-defender-portal.md)
3435
- [Connect Microsoft Sentinel to the Microsoft Defender portal](/unified-secops-platform/microsoft-sentinel-onboard)
35-
36+
- [Microsoft Defender multitenant management](/unified-secops-platform/mto-overview.md)
37+
- [View and manage incidents and alerts in Microsoft Defender multitenant management](/unified-secops-platform/mto-incidents-alerts.md)
38+
- [Advanced hunting in Microsoft Defender multitenant management](/unified-secops-platform/mto-advanced-hunting.md)
3639

3740
## March 2025
3841

articles/sentinel/workspaces-defender-portal.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -36,9 +36,9 @@ Use one of the following roles or role combinations to manage primary and second
3636

3737
|Task |Required roles or role combinations |
3838
|---------|---------|
39-
|**Connect a primary workspace** | One of the following: <br>- Global Administrator AND subscription Owner <br> Security Administrator AND subscription Owner <br>- Global Administrator AND User access administrator AND Sentinel contributor <br>- Security Administrator AND User access administrator AND Sentinel contributor|
39+
|**Connect a primary workspace** | One of the following: <br>- Global Administrator AND subscription Owner <br>- Security Administrator AND subscription Owner <br>- Global Administrator AND User access administrator AND Sentinel contributor <br>- Security Administrator AND User access administrator AND Sentinel contributor|
4040
|**Change the primary workspace** | One of the following: <br>- Global Administrator <br>- Security Administrator |
41-
|**Onboard or offboard secondary workspaces** | One of the following: <br>- Global Administrator AND subscription Owner <br> Security Administrator AND subscription Owner <br>- Global Administrator AND User access administrator AND Sentinel contributor <br>- Security Administrator AND User access administrator AND Sentinel contributor <br>- Subscription Owner <br>- User access administrator AND Sentinel contributor|
41+
|**Onboard or offboard secondary workspaces** | One of the following: <br>- Global Administrator AND subscription Owner <br>- Security Administrator AND subscription Owner <br>- Global Administrator AND User access administrator AND Sentinel contributor <br>- Security Administrator AND User access administrator AND Sentinel contributor <br>- Subscription Owner <br>- User access administrator AND Sentinel contributor|
4242

4343
> [!IMPORTANT]
4444
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.

0 commit comments

Comments
 (0)