@@ -15,56 +15,69 @@ Read more about [data type support for different clouds in Microsoft Sentinel](d
15
15
16
16
## Microsoft Defender for Endpoint
17
17
18
- | Data type | Commercial | GCC | GCC-High | DoD |
19
- | ---------| ---------| ---------| ---------| ---------|
20
- | DeviceInfo | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > |
21
- | DeviceNetworkInfo | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li > | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li > Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > |
22
- | DeviceProcessEvents | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li > Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ ul ></ li > | < ul >< li >Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > |
23
- | DeviceNetworkEvents | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li > Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li > |
24
- | DeviceFileEvents | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li > Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > |
25
- | DeviceRegistryEvents | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li > | < ul >< li > Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li > | < ul >< li >Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > |
26
- | DeviceLogonEvents | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li > Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li > | < ul >< li >Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > |
27
- | DeviceImageLoadEvents | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li > Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > |
28
- | DeviceEvents | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > |
29
- | DeviceFileCertificateInfo | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li > | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li > Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > | < ul >< li >Microsoft 365 Defender: GA</ li >< li > Microsoft Sentinel: Public Preview</ li ></ ul > |
18
+ | Data type | Commercial | GCC | GCC-High | DoD |
19
+ | --------- | ---------- | --------- | --------- | --------- |
20
+ | ** DeviceInfo** | GA | GA | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview |
21
+ | ** DeviceNetworkInfo** | GA | GA | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview |
22
+ | ** DeviceProcessEvents** | GA | GA | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview |
23
+ | ** DeviceNetworkEvents** | GA | GA | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview |
24
+ | ** DeviceFileEvents** | GA | GA | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview |
25
+ | ** DeviceRegistryEvents** | GA | GA | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview |
26
+ | ** DeviceLogonEvents** | GA | GA | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview |
27
+ | ** DeviceImageLoadEvents** | GA | GA | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview |
28
+ | ** DeviceEvents** | GA | GA | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview |
29
+ | ** DeviceFileCertificateInfo** | GA | GA | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview | < li >** Microsoft 365 Defender:** GA<li >** Microsoft Sentinel:** Public preview |
30
30
31
31
## Microsoft Defender for Identity
32
32
33
- | Data type | Commercial | GCC | GCC-High | DoD |
34
- | ---------| ---------| ---------| ---------| ---------|
35
- | IdentityDirectoryEvents | < ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > | Unsupported | Unsupported | Unsupported |
36
- IdentityLogonEvents|< ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li ></ ul > |Unsupported | Unsupported |Unsupported |
37
- IdentityQueryEvents|< ul >< li >Microsoft 365 Defender: GA</ li >< li >Microsoft Sentinel: Public Preview</ li > |Unsupported | Unsupported |Unsupported |
33
+ | Data type | Commercial | GCC | GCC-High | DoD |
34
+ | --------------------------- | ---------- | --- | ----------- | ----------- |
35
+ | ** IdentityDirectoryEvents** | GA | GA | Unsupported | Unsupported |
36
+ | ** IdentityLogonEvents ** | GA | GA | Unsupported | Unsupported |
37
+ | ** IdentityQueryEvents ** | GA | GA | Unsupported | Unsupported |
38
38
39
39
## Microsoft Defender for Cloud Apps
40
40
41
- | Data type | Commercial | GCC | GCC-High | DoD |
42
- | ---------| ---------| ---------| ---------| ---------|
43
- | CloudAppEvents | <ul ><li >Microsoft 365 Defender: GA</li ><li >Microsoft Sentinel: Public Preview</li ></ul > | Unsupported | Unsupported | Unsupported |
41
+ | Data type | Commercial | GCC | GCC-High | DoD |
42
+ | ------------------ | ---------- | --- | ----------- | ----------- |
43
+ | ** CloudAppEvents** | GA | GA | Unsupported | Unsupported |
44
+
45
+ ## Microsoft Defender for Office 365
46
+
47
+ | Data type | Commercial | GCC | GCC-High | DoD |
48
+ | --------------------------- | ---------- | --- | -------------- | -------------- |
49
+ | ** EmailEvents** | GA | GA | Public preview | Public preview |
50
+ | ** EmailAttachmentInfo** | GA | GA | Public preview | Public preview |
51
+ | ** EmailUrlInfo** | GA | GA | Public preview | Public preview |
52
+ | ** EmailPostDeliveryEvents** | GA | GA | Public preview | Public preview |
53
+ | ** UrlClickEvents** | GA | GA | Public preview | Public preview |
44
54
45
55
## Microsoft 365 Defender incidents
46
56
47
- | Data type | Commercial | GCC | GCC-High | DoD |
48
- | ---------| ---------| ---------| ---------| ---------|
49
- | SecurityIncident | Microsoft Sentinel: Public Preview | Microsoft Sentinel: Public Preview | Microsoft Sentinel: Public Preview | Microsoft Sentinel: Public Preview |
57
+ | Data type | Commercial | GCC | GCC-High | DoD |
58
+ | ---------------- | -------------- | -------------- | -------------- | -------------- |
59
+ | SecurityIncident | Public preview | Public preview | Public preview | Public preview |
50
60
51
61
## Alerts
52
62
53
- | Connector/Data type | Commercial | GCC | GCC-High | DoD |
54
- | ---------| ---------| ---------| ---------| ---------|
55
- | Microsoft 365 Defender Alerts: SecurityAlert | Public Preview | Public Preview | Public Preview | Public Preview |
56
- | Microsoft Defender for Endpoint Alerts (standalone connector): SecurityAlert (MDATP) | Public Preview | Public Preview | Public Preview | Public Preview |
57
- | Microsoft Defender for Office 365 Alerts (standalone connector): SecurityAlert (OATP) | Public Preview | Public Preview | Public Preview | Public Preview |
58
- Microsoft Defender for Identity Alerts (standalone connector): SecurityAlert (AATP) |Public Preview |Unsupported |Unsupported |Unsupported |
59
- Microsoft Defender for Cloud Apps Alerts (standalone connector): SecurityAlert (MCAS), |Public Preview |Unsupported |Unsupported |Unsupported |
60
- | Microsoft Defender for Cloud Apps Alerts (standalone connector): McasShadowItReporting | Public Preview | Unsupported | Unsupported | Unsupported |
63
+ | Data type | Commercial | GCC | GCC-High | DoD |
64
+ | ----------------- | ---------- | --- | -------------- | -------------- |
65
+ | ** AlertInfo** | GA | GA | Public preview | Public preview |
66
+ | ** AlertEvidence** | GA | GA | Public preview | Public preview |
67
+ |
68
+ | Microsoft 365 Defender Alerts:<br >SecurityAlert | Public preview | Public preview | Public preview | Public preview |
69
+ | Microsoft Defender for Endpoint Alerts (standalone connector):<br >SecurityAlert (MDATP) | Public preview | Public preview | Public preview | Public preview |
70
+ | Microsoft Defender for Office 365 Alerts (standalone connector):<br >SecurityAlert (OATP) | Public preview | Public preview | Public preview | Public preview |
71
+ | Microsoft Defender for Identity Alerts (standalone connector):<br >SecurityAlert (AATP) | Public preview | Unsupported | Unsupported | Unsupported |
72
+ | Microsoft Defender for Cloud Apps Alerts (standalone connector):<br >SecurityAlert (MCAS), | Public preview | Unsupported | Unsupported | Unsupported |
73
+ | Microsoft Defender for Cloud Apps Alerts (standalone connector):<br >McasShadowItReporting | Public preview | Unsupported | Unsupported | Unsupported |
61
74
62
75
## Azure Active Directory Identity Protection
63
76
64
77
| Data type | Commercial | GCC | GCC-High | DoD |
65
78
| ---------| ---------| ---------| ---------| ---------|
66
- | SecurityAlert (IPC) | Public Preview /GA | Supported | Supported | Supported |
67
- | AlertEvidence | Public Preview | Unsupported | Unsupported | Unsupported |
79
+ | SecurityAlert (IPC) | Public preview /GA | Supported | Supported | Supported |
80
+ | AlertEvidence | Public preview | Unsupported | Unsupported | Unsupported |
68
81
69
82
## Next steps
70
83
0 commit comments