You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/connect-defender-for-cloud.md
+15-7Lines changed: 15 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,6 +5,8 @@ author: yelevin
5
5
ms.topic: how-to
6
6
ms.date: 11/19/2024
7
7
ms.author: yelevin
8
+
appliesto:
9
+
- Microsoft Sentinel
8
10
9
11
10
12
#Customer intent: As a security engineer, I want to integrate and synchronize alerts from cloud security tools into Microsoft Sentinel so that analysts can efficiently monitor, analyze, and respond to security incidents across my organization's hybrid and multicloud environments.
@@ -29,21 +31,27 @@ ms.author: yelevin
29
31
30
32
## Prerequisites
31
33
32
-
- You must have read and write permissions on your MicrosoftSentinel workspace.
34
+
- You must be using Microsoft Sentinel in the Azure portal. If you're onboarded to Microsoft's unified security operations (SecOps) platform, Defender for Cloud alerts are already ingested into Microsoft Defender XDR. The **Tenant-based Microsoft Defender for Cloud (Preview)** data connector isn't listed in the **Data connectors** page in the Defender portal. For more information, see [Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md).
33
35
34
-
- You must have the **Contributor** or **Owner** role on the subscription youwant to connect to Microsoft Sentinel.
36
+
If you're onboarded to Microsoft's unifed SecOps platform, you'll still want to install the **Microsoft Defender for Cloud** solution to use built-in security content with Microsoft Sentinel.
35
37
36
-
- You'll need to enable at least one plan within Microsoft Defender for Cloud for each subscription where you want to enable the connector. To enable Microsoft Defender plans on a subscription, you must have the **Security Admin** role for that subscription.
38
+
- Youmust have the following roles and permissions:
37
39
38
-
- You'll need the `SecurityInsights` resource provider to be registered for each subscription where you want to enable the connector. Review the guidance on the [resource provider registration status](../azure-resource-manager/management/resource-providers-and-types.md#register-resource-provider) and the ways to register it.
40
+
- You must have read and write permissions on your Microsoft Sentinel workspace.
39
41
40
-
- To enable bi-directional sync, you must have the **Contributor** or **Security Admin** role on the relevant subscription.
42
+
- You must have the **Contributor** or **Owner** role on the subscription you want to connect to Microsoft Sentinel.
41
43
42
-
- Install the solution for **Microsoft Defender for Cloud** from the **Content Hub** in Microsoft Sentinel. For more information, see [Discover and manage Microsoft Sentinel out-of-the-box content](sentinel-solutions-deploy.md).
44
+
- To enable bi-directional sync, you must have the **Contributor** or **Security Admin** role on the relevant subscription.
45
+
46
+
- You'll need to enable at least one plan within Microsoft Defender for Cloud for each subscription where you want to enable the connector. To enable Microsoft Defender plans on a subscription, you must have the **Security Admin** role for that subscription.
47
+
48
+
- You'll need the `SecurityInsights` resource provider to be registered for each subscription where you want to enable the connector. Review the guidance on the [resource provider registration status](../azure-resource-manager/management/resource-providers-and-types.md#register-resource-provider) and the ways to register it.
43
49
44
50
## Connect to Microsoft Defender for Cloud
45
51
46
-
1. After installing the solution, in Microsoft Sentinel, select **Configuration > Data connectors**.
52
+
1. In Microsoft Sentinel, install the solution for **Microsoft Defender for Cloud** from the **Content Hub**. For more information, see [Discover and manage Microsoft Sentinel out-of-the-box content](sentinel-solutions-deploy.md).
53
+
54
+
1. Select **Configuration > Data connectors**.
47
55
48
56
1. From the **Data connectors** page, select either the **Subscription-based Microsoft Defender for Cloud (Legacy)** or the **Tenant-based Microsoft Defender for Cloud (Preview)** connector, and then select **Open connector page**.
0 commit comments