Skip to content

Commit 0d4587f

Browse files
Merge pull request #191869 from yelevin/patch-5
Update removal procedure
2 parents 5031cb4 + 03b154c commit 0d4587f

File tree

5 files changed

+15
-7
lines changed

5 files changed

+15
-7
lines changed
Binary file not shown.
Binary file not shown.
201 KB
Loading
211 KB
Loading

articles/sentinel/offboard.md

Lines changed: 15 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -18,13 +18,21 @@ If you no longer want to use Microsoft Sentinel, this article explains how to re
1818

1919
Follow this process to remove Microsoft Sentinel from your workspace:
2020

21-
1. Go to **Microsoft Sentinel**, followed by **Settings**, and select the tab **Remove Microsoft Sentinel**.
21+
1. From the Microsoft Sentinel navigation menu, under **Configuration**, select **Settings**.
2222

23-
1. Before you remove Microsoft Sentinel, please use the checkboxes to let us know why you're removing it.
23+
1. In the **Settings** pane, select the **Settings** tab.
24+
25+
1. Locate and expand the **Remove Microsoft Sentinel** expander (at the bottom of the list of expanders).
26+
27+
:::image type="content" source="media/offboard/locate-remove-sentinel.png" alt-text="Screenshot to find the setting to remove Microsoft Sentinel from your workspace.":::
28+
29+
1. Read the **Know before you go...** section and the rest of this document carefully, making sure that you understand the implications of removing Microsoft Sentinel, and that you take all the necessary actions before proceeding.
30+
31+
1. Before you remove Microsoft Sentinel, please mark the relevant checkboxes to let us know why you're removing it. Enter any additional details in the space provided, and indicate whether you want Microsoft to email you in response to your feedback.
2432

2533
1. Select **Remove Microsoft Sentinel from your workspace**.
2634

27-
![Delete the SecurityInsights solution](media/offboard/delete-solution.png)
35+
:::image type="content" source="media/offboard/remove-sentinel-reasons.png" alt-text="Screenshot to remove the Microsoft Sentinel solution from your workspace and specify reasons.":::
2836

2937
## What happens behind the scenes?
3038

@@ -37,27 +45,27 @@ After the disconnection is identified, the offboarding process begins.
3745

3846
- AWS
3947

40-
- Microsoft services security alerts: Microsoft Defender for Identity (*formerly Azure ATP*), Microsoft Defender for Cloud Apps including Cloud Discovery Shadow IT reporting, Azure AD Identity Protection, Microsoft Defender for Endpoint (*formerly Microsoft Defender ATP*), security alerts from Microsoft Defender for Cloud
48+
- Microsoft services security alerts: Microsoft Defender for Identity, Microsoft Defender for Cloud Apps (*formerly Microsoft Cloud App Security*) including Cloud Discovery Shadow IT reporting, Azure AD Identity Protection, Microsoft Defender for Endpoint, security alerts from Microsoft Defender for Cloud (*formerly Azure Defender*)
4149

4250
- Threat Intelligence
4351

4452
- Common security logs (including CEF-based logs, Barracuda, and Syslog) (If you get security alerts from Microsoft Defender for Cloud, these logs will continue to be collected.)
4553

4654
- Windows Security Events (If you get security alerts from Microsoft Defender for Cloud, these logs will continue to be collected.)
4755

48-
Within the first 48 hours, the data and analytic rules (including real-time automation configuration) will no longer be accessible or queryable in Microsoft Sentinel.
56+
Within the first 48 hours, the data and analytics rules (including real-time automation configuration) will no longer be accessible or queryable in Microsoft Sentinel.
4957

5058
**After 30 days these resources are removed:**
5159

5260
- Incidents (including investigation metadata)
5361

54-
- Analytic rules
62+
- Analytics rules
5563

5664
- Bookmarks
5765

5866
Your playbooks, saved workbooks, saved hunting queries, and notebooks are not removed. **Some may break due to the removed data. You can remove those manually.**
5967

60-
After you remove the service, there is a grace period of 30 days during which you can re-enable the solution and your data and analytic rules will be restored but the configured connectors that were disconnected must be reconnected.
68+
After you remove the service, there is a grace period of 30 days during which you can re-enable the solution. Your data and analytics rules will be restored, but the configured connectors that were disconnected must be reconnected.
6169

6270
> [!NOTE]
6371
> If you remove the solution, your subscription will continue to be registered with the Microsoft Sentinel resource provider. **You can remove it manually.**

0 commit comments

Comments
 (0)