You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
| Number of anomalies published per anomaly type | Top 3000 ranked by anomaly score | None |
75
+
| Number of alerts and/or anomalies in a single Fusion incident | 100 alerts and/or anomalies | None |
77
76
78
77
## Multi workspace limits
79
78
80
79
The following limit applies to multiple workspaces in Microsoft Sentinel. Limits here are applied when working with Sentinel features across more than workspace at a time.
| Analytics rules | 20 Sentinel workspaces per query ||
@@ -89,66 +88,67 @@ The following limit applies to multiple workspaces in Microsoft Sentinel. Limits
89
88
90
89
The following limits apply to notebooks in Microsoft Sentinel. The limits are related to the dependencies on other services used by notebooks.
91
90
92
-
|Description|Limit |Dependency|
93
-
|-------|-------|-------|
94
-
| Total count of these assets per machine learning workspace: datasets, runs, models, and artifacts |10 million assets |Azure Machine Learning|
95
-
| Default limit for total compute clusters per region. Limit is shared between a training cluster and a compute instance. A compute instance is considered a single-node cluster for quota purposes. | 200 compute clusters per region|Azure Machine Learning|
96
-
|Storage accounts per region per subscription|250 storage accounts|Azure Storage|
97
-
|Maximum size of a file share by default|5 TB|Azure Storage|
98
-
|Maximum size of a file share with large file share feature enabled|100 TB|Azure Storage|
99
-
|Maximum throughput (ingress + egress) for a single file share by default|60 MB/sec|Azure Storage|
100
-
|Maximum throughput (ingress + egress) for a single file share with large file share feature enabled|300 MB/sec|Azure Storage|
91
+
|Description|Limit |Dependency|
92
+
|-----------|----- |---------- |
93
+
| Total count of these assets per machine learning workspace: datasets, runs, models, and artifacts |10 million assets |Azure Machine Learning|
94
+
| Default limit for total compute clusters per region. Limit is shared between a training cluster and a compute instance. A compute instance is considered a single-node cluster for quota purposes. | 200 compute clusters per region|Azure Machine Learning|
95
+
|Storage accounts per region per subscription|250 storage accounts|Azure Storage|
96
+
|Maximum size of a file share by default|5 TB|Azure Storage|
97
+
|Maximum size of a file share with large file share feature enabled|100 TB|Azure Storage|
98
+
|Maximum throughput (ingress + egress) for a single file share by default|60 MB/sec|Azure Storage|
99
+
|Maximum throughput (ingress + egress) for a single file share with large file share feature enabled|300 MB/sec|Azure Storage|
101
100
102
101
## Repositories limits
103
102
104
103
The following limits apply to repositories in Microsoft Sentinel.
105
104
106
-
|Description |Limit |Dependency|
107
-
|---------|---------|---------|
108
-
|Number of repositories | 5 | Sentinel Workspace|
109
-
|Deployment history | 800 | Azure Resource Group |
105
+
|Description |Limit |Dependency|
106
+
|----------- |-----|---------- |
107
+
|Number of repositories | 5 | Sentinel Workspace|
108
+
|Deployment history | 800 | Azure Resource Group |
110
109
111
110
## Threat intelligence limits
112
111
113
112
The following limit applies to threat intelligence in Microsoft Sentinel. The limit is related to the dependency on an API used by threat intelligence.
## User and Entity Behavior Analytics (UEBA) limits
131
130
132
131
The following limit applies to UEBA in Microsoft Sentinel. The limit for UEBA in Microsoft Sentinel is related to dependencies on another service.
133
132
134
-
|Description |Limit |Dependency|
135
-
|---------|---------|---------|
136
-
|Lowest retention configuration in days for the [IdentityInfo](/azure/azure-monitor/reference/tables/identityinfo) table. All data stored on the IdentityInfo table in Log Analytics is refreshed every 14 days. | 14 days |Log Analytics|
133
+
| Description | Limit | Dependency |
134
+
| ----------- | ----- | ---------- |
135
+
| Lowest retention configuration in days for the [IdentityInfo](/azure/azure-monitor/reference/tables/identityinfo) table. All data stored on the IdentityInfo table in Log Analytics is refreshed every 14 days. | 14 days | Log Analytics |
136
+
| Groups listed in the *GroupMembership* field in the [IdentityInfo](ueba-reference.md#identityinfo-table) table | 500 ||
137
137
138
138
## Watchlist limits
139
139
140
140
The following limits apply to watchlists in Microsoft Sentinel. The limits are related to the dependencies on other services used by watchlists.
|Upload size limit for local file</br>files over this limit are considered `large`| 3.8 MB per file |Azure Resource Manager
145
-
|Line entry in the CSV file |10,240 characters per line|Azure Resource Manager|
146
-
|Total size of a single row | 10 Kb | Log Analytics|
147
-
|Upload size for large watchlist files in Azure Storage |500 MB per file|Azure Storage|
148
-
|Total number of active watchlist items per workspace</br>When the max count is reached, delete some existing items to add a new watchlist.|10 million active watchlist items|Log Analytics|
149
-
|Total rate of change of all watchlist items per workspace</br>(create, update, and delete operations) | 100,000 changes per month</br>(1% of max active watchlist items)|Log Analytics|
150
-
|Number of `large` watchlist uploads per workspace at a time</br>See upload size limit for what makes a watchlist `large`|One `large` watchlist | Azure Cosmos DB|
151
-
|Number of large watchlist deletions per workspace at a time</br>See upload size limit for what makes a watchlist `large`| One `large` watchlist |Azure Cosmos DB|
142
+
|Description | Limit |Dependency|
143
+
| -----------|-----|----------|
144
+
|Upload size limit for local file</br>files over this limit are considered `large`| 3.8 MB per file |Azure Resource Manager|
145
+
|Line entry in the CSV file |10,240 characters per line|Azure Resource Manager|
146
+
|Total size of a single row | 10 Kb | Log Analytics|
147
+
|Upload size for large watchlist files in Azure Storage |500 MB per file|Azure Storage|
148
+
|Total number of active watchlist items per workspace</br>When the max count is reached, delete some existing items to add a new watchlist.|10 million active watchlist items|Log Analytics|
149
+
|Total rate of change of all watchlist items per workspace</br>(create, update, and delete operations) | 100,000 changes per month</br>(1% of max active watchlist items)|Log Analytics|
150
+
|Number of `large` watchlist uploads per workspace at a time</br>See upload size limit for what makes a watchlist `large`|One `large` watchlist | Azure Cosmos DB|
151
+
|Number of large watchlist deletions per workspace at a time</br>See upload size limit for what makes a watchlist `large`| One `large` watchlist | Azure Cosmos DB|
Copy file name to clipboardExpand all lines: articles/sentinel/ueba-reference.md
+5-1Lines changed: 5 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -215,14 +215,18 @@ While the initial synchronization may take a few days, once the data is fully sy
215
215
216
216
- Changes made to your user profiles, groups, and roles in Microsoft Entra ID are updated in the **IdentityInfo** table within 15-30 minutes.
217
217
218
-
- Every 14 days, Microsoft Sentinel re-synchronizes with your entire Microsoft Entra ID to ensure that stale records are fully updated.
218
+
- Every 14 days, Microsoft Sentinel re-synchronizes with your entire Microsoft Entra ID to ensure that stale records are fully updated. See note in the next section about changes to groups.
219
219
220
220
- Default retention time in the **IdentityInfo** table is 30 days.
221
221
222
222
#### Limitations
223
223
224
224
- Currently, only built-in roles are supported.
225
225
226
+
- Support for groups (as listed in the *GroupMembership* field) is limited to 500 groups. These groups are transitive, not direct.
227
+
228
+
- Changes made to groups in your [Active Directory or (?)] Microsoft Entra ID result in updates to the *IdentityInfo* table for any users who are members of the changed groups. **These updates carry a synchronization charge.**
229
+
226
230
- Data about deleted groups, where a user was removed from a group, is not currently supported.
0 commit comments