Skip to content

Commit 136ec92

Browse files
committed
fixing order
1 parent ff8b267 commit 136ec92

File tree

1 file changed

+22
-22
lines changed

1 file changed

+22
-22
lines changed

articles/sentinel/workspaces-defender-portal.md

Lines changed: 22 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -30,37 +30,16 @@ When you onboard Microsoft Sentinel, you select a primary workspace. A primary w
3030

3131
Where you have multiple Microsoft Sentinel workspaces within a Microsoft Entra ID tenant, consider using the primary workspace for your global security operations center.
3232

33-
## Primary workspace changes
34-
35-
After you onboard Microsoft Sentinel to the Defender portal, you can change the primary workspace. When you switch the primary workspace for Microsoft Sentinel, the Defender XDR connector is connected to the new primary and disconnected from the former one automatically.
36-
37-
Change the primary workspace in the Defender portal by going to **System** > **Settings** > **Microsoft Sentinel** > **Workspaces**.
38-
39-
## Scope of workspace data in different views
40-
41-
If you have the appropriate permissions to view data from primary and secondary workspaces for Microsoft Sentinel, the workspace scope in following table applies for each capability.
42-
43-
|Capability |Workspace scope |
44-
|---------|---------|
45-
|**Search** | The results from the global search at the top of the browser page in the Defender portal provide an aggregated view of all relevant workspace data that you have permissions to view. |
46-
|Investigation & response > Incidents & alerts > **Incidents** | View incidents from different workspaces in a unified queue or filter the view by workspace. |
47-
|Investigation & response > Incidents & alerts > **Alerts** | View alerts from different workspaces in a unified queue or filter the view by workspace.<br><br> The Defender portal segments alert correlation by workspace. |
48-
|Entities: From an incident or alert > select a device, user, or other entity asset | View all relevant entity data from multiple workspaces in a single entity page. Entity pages aggregates alerts, incidents, and timeline events from all workspaces to provide deeper insights into entity behavior. <br><br>Filter by workspace in **Incidents and alerts**, **Timeline**, and **Insights** tabs. The **Overview** tab displays entity metadata aggregated from all workspaces. |
49-
|Investigation & response > Hunting > **Advanced hunting** | Select a workspace from the top right-hand side of the browser. Or, query across multiple workspaces by using the workspace operator in the query. See [Query multiple workspaces](extend-sentinel-across-workspaces-tenants.md#query-multiple-workspaces). The query results don't show a workspace name or ID.<br><br>Access all log data of the workspace, including queries and functions, as read only. For more information, see [Advanced hunting with Microsoft Sentinel data in Microsoft Defender portal](/defender-xdr/advanced-hunting-microsoft-defender). <br><br>Some capabilities are limited to the primary workspace:<br>- Creating custom detections<br>- Queries via API |
50-
|**Microsoft Sentinel** experiences|View data from one workspace for each page in the Microsoft Sentinel section of the Defender portal. Switch between workspaces by selecting **Select a workspace** from the top-right hand side of the browser for most pages. The **Workbooks** page only shows data associated with the primary workspace.|
51-
|**SOC optimization**|Data and recommendations are aggregated from multiple workspaces. |
52-
5333
## Permissions to manage workspaces and view workspace data
5434

5535
Use one of the following roles or role combinations to manage primary and secondary workspaces:
5636

5737
|Task |Required roles or role combinations |
5838
|---------|---------|
5939
|**Connect a primary workspace** | One of the following: <br>- Global Administrator AND subscription Owner <br> Security Administrator AND subscription Owner <br>- Global Administrator AND User access administrator AND Sentinel contributor <br>- Security Administrator AND User access administrator AND Sentinel contributor|
60-
|**Select a different primary workspace** | One of the following: <br>- Global Administrator <br>- Security Administrator |
40+
|**Change the primary workspace** | One of the following: <br>- Global Administrator <br>- Security Administrator |
6141
|**Onboard or offboard secondary workspaces** | One of the following: <br>- Global Administrator AND subscription Owner <br> Security Administrator AND subscription Owner <br>- Global Administrator AND User access administrator AND Sentinel contributor <br>- Security Administrator AND User access administrator AND Sentinel contributor <br>- Subscription Owner <br>- User access administrator AND Sentinel contributor|
6242

63-
6443
> [!IMPORTANT]
6544
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
6645
@@ -75,6 +54,27 @@ After you connect Microsoft Sentinel to the Defender portal, your existing Azure
7554

7655
For more information, see [Roles and permissions in Microsoft Sentinel](roles.md).
7756

57+
## Primary workspace changes
58+
59+
After you onboard Microsoft Sentinel to the Defender portal, you can change the primary workspace. When you switch the primary workspace for Microsoft Sentinel, the Defender XDR connector is connected to the new primary and disconnected from the former one automatically.
60+
61+
Change the primary workspace in the Defender portal by going to **System** > **Settings** > **Microsoft Sentinel** > **Workspaces**.
62+
63+
## Scope of workspace data in different views
64+
65+
If you have the appropriate permissions to view data from primary and secondary workspaces for Microsoft Sentinel, the workspace scope in following table applies for each capability.
66+
67+
|Capability |Workspace scope |
68+
|---------|---------|
69+
|**Search** | The results from the global search at the top of the browser page in the Defender portal provide an aggregated view of all relevant workspace data that you have permissions to view. |
70+
|Investigation & response > Incidents & alerts > **Incidents** | View incidents from different workspaces in a unified queue or filter the view by workspace. |
71+
|Investigation & response > Incidents & alerts > **Alerts** | View alerts from different workspaces in a unified queue or filter the view by workspace.<br><br> The Defender portal segments alert correlation by workspace. |
72+
|Entities: From an incident or alert > select a device, user, or other entity asset | View all relevant entity data from multiple workspaces in a single entity page. Entity pages aggregates alerts, incidents, and timeline events from all workspaces to provide deeper insights into entity behavior. <br><br>Filter by workspace in **Incidents and alerts**, **Timeline**, and **Insights** tabs. The **Overview** tab displays entity metadata aggregated from all workspaces. |
73+
|Investigation & response > Hunting > **Advanced hunting** | Select a workspace from the top right-hand side of the browser. Or, query across multiple workspaces by using the workspace operator in the query. See [Query multiple workspaces](extend-sentinel-across-workspaces-tenants.md#query-multiple-workspaces). The query results don't show a workspace name or ID.<br><br>Access all log data of the workspace, including queries and functions, as read only. For more information, see [Advanced hunting with Microsoft Sentinel data in Microsoft Defender portal](/defender-xdr/advanced-hunting-microsoft-defender). <br><br>Some capabilities are limited to the primary workspace:<br>- Creating custom detections<br>- Queries via API |
74+
|**Microsoft Sentinel** experiences|View data from one workspace for each page in the Microsoft Sentinel section of the Defender portal. Switch between workspaces by selecting **Select a workspace** from the top-right hand side of the browser for most pages. The **Workbooks** page only shows data associated with the primary workspace.|
75+
|**SOC optimization**|Data and recommendations are aggregated from multiple workspaces. |
76+
77+
7878
## Bi-directional sync for workspaces
7979

8080
How incident changes sync between the Azure portal and the Defender portal depends on whether it's a primary or secondary workspace.

0 commit comments

Comments
 (0)