You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/workspaces-defender-portal.md
+22-22Lines changed: 22 additions & 22 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -30,37 +30,16 @@ When you onboard Microsoft Sentinel, you select a primary workspace. A primary w
30
30
31
31
Where you have multiple Microsoft Sentinel workspaces within a Microsoft Entra ID tenant, consider using the primary workspace for your global security operations center.
32
32
33
-
## Primary workspace changes
34
-
35
-
After you onboard Microsoft Sentinel to the Defender portal, you can change the primary workspace. When you switch the primary workspace for Microsoft Sentinel, the Defender XDR connector is connected to the new primary and disconnected from the former one automatically.
36
-
37
-
Change the primary workspace in the Defender portal by going to **System** > **Settings** > **Microsoft Sentinel** > **Workspaces**.
38
-
39
-
## Scope of workspace data in different views
40
-
41
-
If you have the appropriate permissions to view data from primary and secondary workspaces for Microsoft Sentinel, the workspace scope in following table applies for each capability.
42
-
43
-
|Capability |Workspace scope |
44
-
|---------|---------|
45
-
|**Search**| The results from the global search at the top of the browser page in the Defender portal provide an aggregated view of all relevant workspace data that you have permissions to view. |
46
-
|Investigation & response > Incidents & alerts > **Incidents**| View incidents from different workspaces in a unified queue or filter the view by workspace. |
47
-
|Investigation & response > Incidents & alerts > **Alerts**| View alerts from different workspaces in a unified queue or filter the view by workspace.<br><br> The Defender portal segments alert correlation by workspace. |
48
-
|Entities: From an incident or alert > select a device, user, or other entity asset | View all relevant entity data from multiple workspaces in a single entity page. Entity pages aggregates alerts, incidents, and timeline events from all workspaces to provide deeper insights into entity behavior. <br><br>Filter by workspace in **Incidents and alerts**, **Timeline**, and **Insights** tabs. The **Overview** tab displays entity metadata aggregated from all workspaces. |
49
-
|Investigation & response > Hunting > **Advanced hunting**| Select a workspace from the top right-hand side of the browser. Or, query across multiple workspaces by using the workspace operator in the query. See [Query multiple workspaces](extend-sentinel-across-workspaces-tenants.md#query-multiple-workspaces). The query results don't show a workspace name or ID.<br><br>Access all log data of the workspace, including queries and functions, as read only. For more information, see [Advanced hunting with Microsoft Sentinel data in Microsoft Defender portal](/defender-xdr/advanced-hunting-microsoft-defender). <br><br>Some capabilities are limited to the primary workspace:<br>- Creating custom detections<br>- Queries via API |
50
-
|**Microsoft Sentinel** experiences|View data from one workspace for each page in the Microsoft Sentinel section of the Defender portal. Switch between workspaces by selecting **Select a workspace** from the top-right hand side of the browser for most pages. The **Workbooks** page only shows data associated with the primary workspace.|
51
-
|**SOC optimization**|Data and recommendations are aggregated from multiple workspaces. |
52
-
53
33
## Permissions to manage workspaces and view workspace data
54
34
55
35
Use one of the following roles or role combinations to manage primary and secondary workspaces:
56
36
57
37
|Task |Required roles or role combinations |
58
38
|---------|---------|
59
39
|**Connect a primary workspace**| One of the following: <br>- Global Administrator AND subscription Owner <br> Security Administrator AND subscription Owner <br>- Global Administrator AND User access administrator AND Sentinel contributor <br>- Security Administrator AND User access administrator AND Sentinel contributor|
60
-
|**Select a different primary workspace**| One of the following: <br>- Global Administrator <br>- Security Administrator |
40
+
|**Change the primary workspace**| One of the following: <br>- Global Administrator <br>- Security Administrator |
61
41
|**Onboard or offboard secondary workspaces**| One of the following: <br>- Global Administrator AND subscription Owner <br> Security Administrator AND subscription Owner <br>- Global Administrator AND User access administrator AND Sentinel contributor <br>- Security Administrator AND User access administrator AND Sentinel contributor <br>- Subscription Owner <br>- User access administrator AND Sentinel contributor|
62
42
63
-
64
43
> [!IMPORTANT]
65
44
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
66
45
@@ -75,6 +54,27 @@ After you connect Microsoft Sentinel to the Defender portal, your existing Azure
75
54
76
55
For more information, see [Roles and permissions in Microsoft Sentinel](roles.md).
77
56
57
+
## Primary workspace changes
58
+
59
+
After you onboard Microsoft Sentinel to the Defender portal, you can change the primary workspace. When you switch the primary workspace for Microsoft Sentinel, the Defender XDR connector is connected to the new primary and disconnected from the former one automatically.
60
+
61
+
Change the primary workspace in the Defender portal by going to **System** > **Settings** > **Microsoft Sentinel** > **Workspaces**.
62
+
63
+
## Scope of workspace data in different views
64
+
65
+
If you have the appropriate permissions to view data from primary and secondary workspaces for Microsoft Sentinel, the workspace scope in following table applies for each capability.
66
+
67
+
|Capability |Workspace scope |
68
+
|---------|---------|
69
+
|**Search**| The results from the global search at the top of the browser page in the Defender portal provide an aggregated view of all relevant workspace data that you have permissions to view. |
70
+
|Investigation & response > Incidents & alerts > **Incidents**| View incidents from different workspaces in a unified queue or filter the view by workspace. |
71
+
|Investigation & response > Incidents & alerts > **Alerts**| View alerts from different workspaces in a unified queue or filter the view by workspace.<br><br> The Defender portal segments alert correlation by workspace. |
72
+
|Entities: From an incident or alert > select a device, user, or other entity asset | View all relevant entity data from multiple workspaces in a single entity page. Entity pages aggregates alerts, incidents, and timeline events from all workspaces to provide deeper insights into entity behavior. <br><br>Filter by workspace in **Incidents and alerts**, **Timeline**, and **Insights** tabs. The **Overview** tab displays entity metadata aggregated from all workspaces. |
73
+
|Investigation & response > Hunting > **Advanced hunting**| Select a workspace from the top right-hand side of the browser. Or, query across multiple workspaces by using the workspace operator in the query. See [Query multiple workspaces](extend-sentinel-across-workspaces-tenants.md#query-multiple-workspaces). The query results don't show a workspace name or ID.<br><br>Access all log data of the workspace, including queries and functions, as read only. For more information, see [Advanced hunting with Microsoft Sentinel data in Microsoft Defender portal](/defender-xdr/advanced-hunting-microsoft-defender). <br><br>Some capabilities are limited to the primary workspace:<br>- Creating custom detections<br>- Queries via API |
74
+
|**Microsoft Sentinel** experiences|View data from one workspace for each page in the Microsoft Sentinel section of the Defender portal. Switch between workspaces by selecting **Select a workspace** from the top-right hand side of the browser for most pages. The **Workbooks** page only shows data associated with the primary workspace.|
75
+
|**SOC optimization**|Data and recommendations are aggregated from multiple workspaces. |
76
+
77
+
78
78
## Bi-directional sync for workspaces
79
79
80
80
How incident changes sync between the Azure portal and the Defender portal depends on whether it's a primary or secondary workspace.
0 commit comments