Skip to content

Commit 17174fc

Browse files
committed
evgeny's comments
1 parent d992c62 commit 17174fc

File tree

1 file changed

+23
-24
lines changed

1 file changed

+23
-24
lines changed
Lines changed: 23 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
title: BCDR recommendations for working with Microsoft Sentinel
2+
title: BCDR Recommendations for Working With Microsoft Sentinel
33
description: Learn about Business Continuity and Disaster Recovery (BCDR) in Microsoft Sentinel, including availability zones and cross-region disaster recovery strategies.
44
author: batamig
55
ms.author: bagol
@@ -16,67 +16,66 @@ ms.collection: usx-security
1616

1717
# Business continuity and disaster recovery for Microsoft Sentinel
1818

19-
This article describes reliability support in Microsoft Sentinel and covers both regional resiliency with availability zones and cross-region resiliency with business continuity and disaster recovery (BCDR). While this article is mainly directed at Microsoft Sentinel customers working in the Azure portal, this guidance also covers data currently covered by Azure services after having onboarded to the [Microsoft Defender portal](/unified-secops-platform/overview-unified-security). <!--last sentence i added-->
19+
This article describes reliability support in Microsoft Sentinel and covers both regional resiliency with availability zones and cross-region resiliency with business continuity and disaster recovery (BCDR). While this article is mainly directed at Microsoft Sentinel customers working in the Azure portal, this guidance also covers data currently managed by Azure services after onboarding to the [Microsoft Defender portal](/unified-secops-platform/overview-unified-security).
2020

2121
For more information, see [Azure reliability](/azure/well-architected/resiliency/).
2222

2323
## Availability zone support
2424

25-
Availability zones are physically separate groups of data centers within each region. When one zone fails, services can fail over to one of the remaining zones.
25+
Availability zones are physically separate groups of data centers within each region. When one zone fails, services fail over to one of the remaining zones.
2626

27-
Microsoft Sentinel uses availability zones in regions where they're available to provide high-availability protection for your applications and data from data center failures.
27+
Microsoft Sentinel uses availability zones in regions where they're available to provide high availability protection for your applications and data from data center failures.
2828

2929
For more information, see [What are availability zones?](/azure/reliability/availability-zones-overview).
3030

3131
## Cross-region disaster recovery
3232

33-
Disaster recovery (DR) is about recovering from high-impact events, such as natural disasters or failed deployments that result in downtime and data loss. Regardless of the cause, the best remedy for a disaster is a well-defined and tested DR plan and an application design that actively supports DR. Before you begin to think about creating your disaster recovery plan, see [Recommendations for designing a disaster recovery strategy](/azure/well-architected/reliability/disaster-recovery).
33+
Disaster recovery (DR) is about recovering from high-impact events, such as natural disasters or failed deployments that result in downtime and data loss. Regardless of the cause, the best remedy for a disaster is a well-defined and tested DR plan and an application design that actively supports DR. Before you create your disaster recovery plan, see [Recommendations for designing a disaster recovery strategy](/azure/well-architected/reliability/disaster-recovery).
3434

35-
When it comes to DR, Microsoft uses the [shared responsibility model](/azure/reliability/concept-shared-responsibility). In a shared responsibility model, Microsoft ensures that the baseline infrastructure and platform services are available. At the same time, many Azure services don't automatically replicate data or fall back from a failed region to cross-replicate to another enabled region. For those services, customers are responsible for setting up a disaster recovery plan that works for their environment. <!--changed from workload-->Most services that run on Azure platform as a service (PaaS) offerings provide features and guidance to support DR and you can [use service-specific features](/azure/reliability/reliability-guidance-overview) to support fast recovery to help develop your DR plan.
35+
When it comes to DR, Microsoft uses the shared responsibility model. In this model:
3636

37-
In the unlikely event of a full region outage, customers have the option of using one of two strategies:
37+
- Microsoft ensures that the baseline infrastructure and platform services are available.
38+
- Many Azure services don't automatically replicate data or fall back from a failed region to cross-replicate to another enabled region. For those services, customers are responsible for setting up a disaster recovery plan that works for their environment.
3839

39-
- **Manual recovery:** Manually deploy to a new region, or wait for the region to recover, and then manually redeploy all environments and apps.
40-
- **Resilient recovery:** First, deploy your container apps in advance to multiple regions. Next, use Azure Front Door or Azure Traffic Manager to handle incoming requests, pointing traffic to your primary region. Then, should an outage occur, customers can redirect traffic away from the affected region. For more information, see [Cross-region replication in Azure](/azure/reliability/cross-region-replication-azure).
40+
Most services that run on Azure platform as a service (PaaS) offerings provide features and guidance to support DR. You can [use service-specific features](/azure/reliability/reliability-guidance-overview) to support fast recovery and help develop your DR plan.
4141

42-
<!--removed business continuity from title - here we only talk about dr-->
42+
For more information, see [Shared responsibility for reliability](/azure/reliability/concept-shared-responsibility).
4343

4444
## BCDR implementation for Microsoft Sentinel
4545

46-
Microsoft Sentinel uses Microsoft best practices for resiliency, safe deployment, and BCDR with Azure Availability Zones (AZs).
46+
Microsoft Sentinel uses Microsoft's best practices for resiliency, safe deployment, and BCDR with Azure Availability Zones (AZs).
4747

48-
To support BCDR in case of a regional outage, Microsoft Sentinel employs a customer-enabled BCDR approach, which means that customers are responsible for setting up disaster recovery. To ensure continuous business operations, customers must configure their Microsoft Sentinel environment in an active-active or mirrored fashion across the two paired regions relevant to them, depending on the cloud environment.
48+
To support BCDR in case of a regional outage, Microsoft Sentinel uses a customer-enabled BCDR approach, which means customers are responsible for setting up disaster recovery. To ensure continuous business operations, customers must configure their Microsoft Sentinel environment in an active-active (mirrored) fashion across the two paired regions relevant to them, depending on the cloud environment.
4949

5050
Customer-enabled BCDR involves:
5151

5252
- Creating two identical Log Analytics workspaces enabled for Microsoft Sentinel in the appropriate regions. For more information, see [Quickstart: Onboard Microsoft Sentinel](quickstart-onboard.md).
5353
- Ensuring that the same data sources, analytic rules, and all other settings and configurations are mirrored between the regions, and maintained consistently throughout the continuous operations of these workspaces.
5454

55-
These activities must be done manually by the customer and do not happen automatically.
55+
These activities must be done manually by the customer and don't happen automatically.
5656

57-
A customer-enabled BCDR setup ensures that if an Azure regional outage occurs in one of the customer's regions, the other paired region, which is geographically and physically separate from the impacted region, will remain unaffected. As a result, continuous business operations can proceed without any downtime or data loss.
57+
A customer-enabled BCDR setup ensures that if an Azure regional outage occurs in one of the customer's regions, the other paired region, which is geographically and physically separate from the impacted region, remains unaffected. As a result, continuous business operations can proceed without any downtime or data loss.
5858

5959
## Regional and cloud support
6060

6161
The following table describes the recommended actions for setting up BCDR in different regions and cloud environments:
6262

6363
|Cloud type |Guidance |
6464
|---------|---------|
65-
|Public | We recommend that customers outside of Europe create one workspace in their local region and another in any of the supported European regions. |
66-
|Azure Government | We recommend that customers in US government clouds create one workspace in Arizona and another in Virginia. |
67-
|Air-gapped clouds | We recommend that customers in air-gapped US government clouds create one workspace in USSEC East and another workspace in USSEC West, or in USNAT East and USNAT West. |
65+
|**Public** | We recommend customers outside of Europe create one workspace in their local region and another in any of the supported European regions. |
66+
|**Azure Government** | We recommend customers in US government clouds create two workspaces, one in each of their relevant regions. For details about air-gapped clouds, contact your account team.|
6867

69-
For more information, see [Geographical availability and data residency in Microsoft Sentinel](geographical-availability-data-residency.md).
68+
For more information, see [Geographical availability and data residency in Microsoft Sentinel](geographical-availability-data-residency.md).
7069

71-
The following geographical regions are not currently supported for the customer-enabled BCDR approach described in this artice:
70+
The following geographical regions are not currently supported for the customer-enabled BCDR approach described in this article:
7271

73-
- EU customers, due to EUDB compliance limitations
74-
- Israel
75-
- Azure China 21Vianet
72+
- EU customers due to EUDB compliance limitations.
73+
- Israel.
74+
- Azure China 21Vianet.
7675

7776
## Related content
7877

7978
For more information, see:
8079

81-
- [Geographical availability and data residency in Microsoft Sentinel](geographical-availability-data-residency.md)
82-
- [Microsoft Sentinel feature support for Azure commercial/other clouds](feature-availability.md)
80+
- [Geographical availability and data residency in Microsoft Sentinel](geographical-availability-data-residency.md)
81+
- [Microsoft Sentinel feature support for Azure commercial / other clouds](feature-availability.md)

0 commit comments

Comments
 (0)