Skip to content

Commit 06583ba

Browse files
committed
Added warnings about Group Membership
1 parent 44e5fcc commit 06583ba

File tree

2 files changed

+51
-47
lines changed

2 files changed

+51
-47
lines changed

articles/sentinel/sentinel-service-limits.md

Lines changed: 46 additions & 46 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
---
22
title: Microsoft Sentinel service limits
3-
description: This article provides a list of service limits for Microsoft Sentinel.
3+
description: This article provides a list of service limits for Microsoft Sentinel, divided into the different service areas.
44
author: yelevin
5-
ms.topic: conceptual
5+
ms.topic: reference
66
ms.date: 03/19/2025
77
ms.author: yelevin
88
ms.service: microsoft-sentinel
@@ -20,8 +20,8 @@ This article lists the most common service limits you might encounter as you use
2020

2121
The following limit applies to analytics rules in Microsoft Sentinel.
2222

23-
| Description | Limit | Dependency |
24-
| --------- | --------- | --------- |
23+
| Description | Limit | Dependency |
24+
| ----------- | ----- | ---------- |
2525
| Number of [scheduled rules](scheduled-rules-overview.md) | 512 *enabled* rules | Counted separately from NRT rules |
2626
| Number of [near-real-time (NRT) rules](near-real-time-rules.md) | 50 *enabled* rules | Counted separately from scheduled rules |
2727
| [Entity mappings](map-data-fields-to-entities.md) | 10 mappings per rule | None |
@@ -37,15 +37,15 @@ The following limit applies to analytics rules in Microsoft Sentinel.
3737
The following limits apply to Hunts in Microsoft Sentinel.
3838

3939
| Description | Limit | Dependency |
40-
| --------- | --------- | ------- |
40+
| ----------- | ----- | ---------- |
4141
|Number of Hunts | 100 | None |
4242

4343
## Incident limits
4444

4545
The following limits apply to incidents in Microsoft Sentinel.
4646

4747
| Description | Limit | Dependency |
48-
| --------- | --------- | ------- |
48+
| ----------- | ----- | ---------- |
4949
| Investigation experience availability | 90 days from the incident last update time | None |
5050
| Retention period for incident entities | 180 days | Entities database retention |
5151
| Number of alerts | 150 alerts | None |
@@ -69,18 +69,17 @@ However, a SOC that experiences the creation of more than *around* 3,000 new inc
6969

7070
The following limits apply to machine learning-based features in Microsoft Sentinel like customizable anomalies and Fusion.
7171

72-
| Description | Limit |Dependency|
73-
|---------------------------------------------------------------|-------------------------------------------------|-------|
74-
| Number of anomalies published per anomaly type | Top 3000 ranked by anomaly score |None|
75-
| Number of alerts and/or anomalies in a single Fusion incident | 100 alerts and/or anomalies |None|
76-
72+
| Description | Limit | Dependency |
73+
| ------------------------------------------------------------- | -------------------------------- | ---------- |
74+
| Number of anomalies published per anomaly type | Top 3000 ranked by anomaly score | None |
75+
| Number of alerts and/or anomalies in a single Fusion incident | 100 alerts and/or anomalies | None |
7776

7877
## Multi workspace limits
7978

8079
The following limit applies to multiple workspaces in Microsoft Sentinel. Limits here are applied when working with Sentinel features across more than workspace at a time.
8180

82-
|Description | Limit |Dependency|
83-
-------------------------|--------------------|--------------------|
81+
| Description | Limit | Dependency |
82+
| ----------- | ----- | ---------- |
8483
| Incident view | 100 concurrently displayed workspaces | |
8584
| Log query | 100 Sentinel workspaces | [Log Analytics](/azure/azure-monitor/logs/cross-workspace-query#limitations) |
8685
| Analytics rules | 20 Sentinel workspaces per query | |
@@ -89,66 +88,67 @@ The following limit applies to multiple workspaces in Microsoft Sentinel. Limits
8988

9089
The following limits apply to notebooks in Microsoft Sentinel. The limits are related to the dependencies on other services used by notebooks.
9190

92-
|Description|Limit |Dependency|
93-
|-------|-------|-------|
94-
| Total count of these assets per machine learning workspace: datasets, runs, models, and artifacts |10 million assets |Azure Machine Learning|
95-
| Default limit for total compute clusters per region. Limit is shared between a training cluster and a compute instance. A compute instance is considered a single-node cluster for quota purposes. | 200 compute clusters per region|Azure Machine Learning|
96-
|Storage accounts per region per subscription|250 storage accounts|Azure Storage|
97-
|Maximum size of a file share by default|5 TB|Azure Storage|
98-
|Maximum size of a file share with large file share feature enabled|100 TB|Azure Storage|
99-
|Maximum throughput (ingress + egress) for a single file share by default|60 MB/sec|Azure Storage|
100-
|Maximum throughput (ingress + egress) for a single file share with large file share feature enabled|300 MB/sec|Azure Storage|
91+
| Description | Limit | Dependency |
92+
| ----------- | ----- | ---------- |
93+
| Total count of these assets per machine learning workspace: datasets, runs, models, and artifacts |10 million assets | Azure Machine Learning |
94+
| Default limit for total compute clusters per region. Limit is shared between a training cluster and a compute instance. A compute instance is considered a single-node cluster for quota purposes. | 200 compute clusters per region | Azure Machine Learning |
95+
| Storage accounts per region per subscription | 250 storage accounts | Azure Storage |
96+
| Maximum size of a file share by default | 5 TB | Azure Storage |
97+
| Maximum size of a file share with large file share feature enabled | 100 TB | Azure Storage |
98+
| Maximum throughput (ingress + egress) for a single file share by default | 60 MB/sec | Azure Storage |
99+
| Maximum throughput (ingress + egress) for a single file share with large file share feature enabled | 300 MB/sec | Azure Storage |
101100

102101
## Repositories limits
103102

104103
The following limits apply to repositories in Microsoft Sentinel.
105104

106-
|Description |Limit |Dependency|
107-
|---------|---------|---------|
108-
|Number of repositories | 5 | Sentinel Workspace|
109-
|Deployment history | 800 | Azure Resource Group |
105+
| Description | Limit | Dependency |
106+
| ----------- | ----- | ---------- |
107+
| Number of repositories | 5 | Sentinel Workspace |
108+
| Deployment history | 800 | Azure Resource Group |
110109

111110
## Threat intelligence limits
112111

113112
The following limit applies to threat intelligence in Microsoft Sentinel. The limit is related to the dependency on an API used by threat intelligence.
114113

115-
|Description | Limit |Dependency|
116-
-------------------------|--------------------|--------------------|
117-
| Indicators per call that use Graph security API | 100 indicators |Microsoft Graph security API|
118-
| CSV TI object file import size | 50MB | none|
119-
| JSON TI object file import size | 250MB | none|
114+
| Description | Limit | Dependency |
115+
| ----------- | ----- | ---------- |
116+
| Indicators per call that use Graph security API | 100 indicators | Microsoft Graph security API |
117+
| CSV TI object file import size | 50MB | none |
118+
| JSON TI object file import size | 250MB | none |
120119

121120
## TI upload API limits
122121

123122
The following limit applies to the threat intelligence upload API in Microsoft Sentinel.
124123

125-
|Description | Limit |Dependency|
126-
-------------------------|--------------------|--------------------|
124+
| Description | Limit | Dependency |
125+
| ----------- | ----- | ---------- |
127126
| STIX objects per request | 100 objects | |
128127
| Requests per minute | 100 | |
129128

130129
## User and Entity Behavior Analytics (UEBA) limits
131130

132131
The following limit applies to UEBA in Microsoft Sentinel. The limit for UEBA in Microsoft Sentinel is related to dependencies on another service.
133132

134-
|Description |Limit |Dependency|
135-
|---------|---------|---------|
136-
|Lowest retention configuration in days for the [IdentityInfo](/azure/azure-monitor/reference/tables/identityinfo) table. All data stored on the IdentityInfo table in Log Analytics is refreshed every 14 days. | 14 days |Log Analytics|
133+
| Description | Limit | Dependency |
134+
| ----------- | ----- | ---------- |
135+
| Lowest retention configuration in days for the [IdentityInfo](/azure/azure-monitor/reference/tables/identityinfo) table. All data stored on the IdentityInfo table in Log Analytics is refreshed every 14 days. | 14 days | Log Analytics |
136+
| Groups listed in the *GroupMembership* field in the [IdentityInfo](ueba-reference.md#identityinfo-table) table | 500 | |
137137

138138
## Watchlist limits
139139

140140
The following limits apply to watchlists in Microsoft Sentinel. The limits are related to the dependencies on other services used by watchlists.
141141

142-
|Description | Limit |Dependency|
143-
|--|-------------------------|--------------------|
144-
|Upload size limit for local file</br>files over this limit are considered `large`| 3.8 MB per file |Azure Resource Manager
145-
|Line entry in the CSV file |10,240 characters per line|Azure Resource Manager|
146-
|Total size of a single row | 10 Kb | Log Analytics|
147-
|Upload size for large watchlist files in Azure Storage |500 MB per file|Azure Storage|
148-
|Total number of active watchlist items per workspace</br>When the max count is reached, delete some existing items to add a new watchlist.|10 million active watchlist items|Log Analytics|
149-
|Total rate of change of all watchlist items per workspace</br>(create, update, and delete operations) | 100,000 changes per month</br>(1% of max active watchlist items)|Log Analytics|
150-
|Number of `large` watchlist uploads per workspace at a time</br>See upload size limit for what makes a watchlist `large` |One `large` watchlist | Azure Cosmos DB|
151-
|Number of large watchlist deletions per workspace at a time</br>See upload size limit for what makes a watchlist `large` | One `large` watchlist | Azure Cosmos DB|
142+
| Description | Limit | Dependency |
143+
| ----------- | ----- | ---------- |
144+
| Upload size limit for local file</br>files over this limit are considered `large`| 3.8 MB per file | Azure Resource Manager |
145+
| Line entry in the CSV file | 10,240 characters per line | Azure Resource Manager |
146+
| Total size of a single row | 10 Kb | Log Analytics |
147+
| Upload size for large watchlist files in Azure Storage | 500 MB per file | Azure Storage |
148+
| Total number of active watchlist items per workspace</br>When the max count is reached, delete some existing items to add a new watchlist. | 10 million active watchlist items | Log Analytics |
149+
| Total rate of change of all watchlist items per workspace</br>(create, update, and delete operations) | 100,000 changes per month</br>(1% of max active watchlist items) | Log Analytics |
150+
| Number of `large` watchlist uploads per workspace at a time</br>See upload size limit for what makes a watchlist `large` | One `large` watchlist | Azure Cosmos DB |
151+
| Number of large watchlist deletions per workspace at a time</br>See upload size limit for what makes a watchlist `large` | One `large` watchlist | Azure Cosmos DB |
152152

153153
## Workbook limits
154154

articles/sentinel/ueba-reference.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -215,14 +215,18 @@ While the initial synchronization may take a few days, once the data is fully sy
215215

216216
- Changes made to your user profiles, groups, and roles in Microsoft Entra ID are updated in the **IdentityInfo** table within 15-30 minutes.
217217

218-
- Every 14 days, Microsoft Sentinel re-synchronizes with your entire Microsoft Entra ID to ensure that stale records are fully updated.
218+
- Every 14 days, Microsoft Sentinel re-synchronizes with your entire Microsoft Entra ID to ensure that stale records are fully updated. See note in the next section about changes to groups.
219219

220220
- Default retention time in the **IdentityInfo** table is 30 days.
221221

222222
#### Limitations
223223

224224
- Currently, only built-in roles are supported.
225225

226+
- Support for groups (as listed in the *GroupMembership* field) is limited to 500 groups. These groups are transitive, not direct.
227+
228+
- Changes made to groups in your [Active Directory or (?)] Microsoft Entra ID result in updates to the *IdentityInfo* table for any users who are members of the changed groups. **These updates carry a synchronization charge.**
229+
226230
- Data about deleted groups, where a user was removed from a group, is not currently supported.
227231

228232
#### Versions of the IdentityInfo table

0 commit comments

Comments
 (0)