Skip to content

Commit 6110c99

Browse files
committed
Arranging in alphabetical order and feedback
1 parent d541fef commit 6110c99

File tree

1 file changed

+100
-101
lines changed

1 file changed

+100
-101
lines changed

articles/sentinel/feature-availability.md

Lines changed: 100 additions & 101 deletions
Original file line numberDiff line numberDiff line change
@@ -12,162 +12,161 @@ ms.date: 02/02/2023
1212

1313
This article describes feature availability in Microsoft Sentinel across different Azure environments.
1414

15-
## Incidents
16-
17-
|Feature |Azure commercial |Azure China 21Vianet |
18-
|---------|---------|---------|
19-
|[Automation rules](automate-incident-handling-with-automation-rules.md) |Public Preview |✅ |
20-
|[Cross-tenant/Cross-workspace incidents view](multiple-workspace-view.md) |GA |✅ |
21-
|[SOC incident audit metrics](manage-soc-with-incident-metrics.md) |GA |✅ |
22-
|[Incident advanced search](investigate-cases.md#search-for-incidents) |GA |✅ |
23-
|[Microsoft 365 Defender incident integration](microsoft-365-defender-sentinel-integration.md#working-with-microsoft-365-defender-incidents-in-microsoft-sentinel-and-bi-directional-sync) |Public Preview |❌ |
24-
|[Microsoft Teams integrations](collaborate-in-microsoft-teams.md) |Public Preview |❌ |
25-
|[Run playbooks on incidents](automate-responses-with-playbooks.md) |Public Preview |✅ |
26-
|[Run playbooks on entities](respond-threats-during-investigation.md) |Public Preview |❌ |
27-
|[Playbook template gallery](use-playbook-templates.md) |Public Preview |❌ |
28-
|[Automation rules health](monitor-automation-health.md) |Public Preview |❌ |
29-
|[Incident tasks](incident-tasks.md) |Public Preview |❌ |
30-
|[Advanced and/or conditions](add-advanced-conditions-to-automation-rules.md) |Public Preview |❌ |
31-
|[Create incidents manually](create-incident-manually.md) |Public Preview |❌ |
32-
|[Add entities to threat intelligence](add-entity-to-threat-intelligence.md?tabs=incidents) |Public Preview |❌ |
33-
3415
## Analytics
3516

3617
|Feature |Azure commercial |Azure China 21Vianet |
3718
|---------|---------|---------|
38-
|[Scheduled](detect-threats-built-in.md) and [Microsoft rules](create-incidents-from-alerts.md) |GA |✅ |
39-
|[NRT rules](near-real-time-rules.md) |Public Preview |✅ |
19+
|[Analytics rules health](monitor-analytics-rule-integrity.md) |Public Preview |❌ |
4020
|[MITRE ATT&CK dashboard](mitre-coverage.md) |Public Preview |❌ |
21+
|[NRT rules](near-real-time-rules.md) |Public Preview |✅ |
4122
|[Recommendations](detection-tuning.md) |Public Preview |❌ |
42-
|[Analytics rules health](monitor-analytics-rule-integrity.md) |Public Preview |❌ |
23+
|[Scheduled](detect-threats-built-in.md) and [Microsoft rules](create-incidents-from-alerts.md) |GA |✅ |
4324

44-
## Notebooks
25+
## Content and content management
4526

4627
|Feature |Azure commercial |Azure China 21Vianet |
4728
|---------|---------|---------|
48-
|[Notebooks](notebooks.md) |GA |✅ |
49-
|[Notebook integration with Azure Synapse](notebooks-with-synapse.md) |Public Preview |✅ |
29+
|[Content hub](sentinel-solutions.md) and [solutions](sentinel-solutions-catalog.md) |Public preview |❌ |
30+
|[Repositories](ci-cd.md?tabs=github) |Public preview |❌ |
31+
|[Workbooks](monitor-your-data.md) |GA |✅ |
5032

51-
## Watchlists
33+
## Data collection
5234

5335
|Feature |Azure commercial |Azure China 21Vianet |
5436
|---------|---------|---------|
55-
|[Watchlists](watchlists.md) |GA |✅ |
56-
|[Large watchlists from Azure Storage](watchlists.md) |Public Preview |❌ |
57-
|[Watchlist templates](watchlist-schemas.md) |Public Preview |❌ |
37+
|[Amazon Web Services](connect-aws.md?tabs=ct) |GA |❌ |
38+
|[Amazon Web Services S3 (Preview)](connect-aws.md?tabs=s3) |Public Preview |❌ |
39+
|[Azure Active Directory](connect-azure-active-directory.md) |GA |&#x2705; <sup>[1](#logsavailable)</sup> |
40+
|[Azure Active Directory Identity Protection](connect-services-api-based.md) |GA |&#10060; |
41+
|[Azure Activity](data-connectors/azure-activity.md) |GA |&#x2705; |
42+
|[Azure DDoS Protection](connect-services-diagnostic-setting-based.md) |GA |&#10060; |
43+
|[Azure Firewall](data-connectors/azure-firewall.md) |GA |&#x2705; |
44+
|[Azure Information Protection (Preview)](data-connectors/azure-information-protection.md) |Deprecated |&#10060; |
45+
|[Azure Key Vault](data-connectors/azure-key-vault.md) |Public Preview |&#x2705; |
46+
|[Azure Kubernetes Service (AKS)](data-connectors/azure-kubernetes-service-aks.md) |Public Preview |&#x2705; |
47+
|[Azure SQL Databases](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/azure-sentinel-sql-solution-query-deep-dive/ba-p/2597961) |GA |&#x2705; |
48+
|[Azure Web Application Firewall (WAF)](data-connectors/azure-web-application-firewall-waf.md) |GA |&#x2705; |
49+
|[Cisco ASA](data-connectors/cisco-asa.md) |GA |&#x2705; |
50+
|[Codeless Connectors Platform](create-codeless-connector.md?tabs=deploy-via-arm-template%2Cconnect-via-the-azure-portal) |Public Preview |&#10060; |
51+
|[Common Event Format (CEF)](connect-common-event-format.md) |GA |&#x2705; |
52+
|[Common Event Format (CEF) via AMA (Preview)](connect-cef-ama.md) |Public Preview |&#x2705; |
53+
|[Data Connectors health](monitor-data-connector-health.md#use-the-sentinelhealth-data-table-public-preview) |Public Preview |&#10060; |
54+
|[DNS](data-connectors/dns.md) |Public Preview |&#x2705; |
55+
|[GCP Pub/Sub Audit Logs](connect-google-cloud-platform.md) |Public Preview |&#10060; |
56+
|[Microsoft 365 Defender](connect-microsoft-365-defender.md?tabs=MDE) |GA |&#10060; |
57+
|[Microsoft 365 Insider Risk Management (Preview)](sentinel-solutions-catalog.md#domain-solutions) |Public Preview |&#10060; |
58+
|[Microsoft Defender for Cloud](connect-defender-for-cloud.md) |GA |&#x2705; |
59+
|[Microsoft Defender for IoT](connect-services-api-based.md) |GA |&#10060; |
60+
|[Microsoft PowerBI (Preview)](data-connectors/microsoft-powerbi.md) |Public Preview |&#10060; |
61+
|[Microsoft Project (Preview)](data-connectors/microsoft-project.md) |Public Preview |&#10060; |
62+
|[Microsoft Purview (Preview)](connect-services-diagnostic-setting-based.md) |Public Preview |&#10060; |
63+
|[Microsoft Purview Information Protection](connect-microsoft-purview.md) |Public Preview |&#10060; |
64+
|[Office 365](connect-services-api-based.md) |GA |&#x2705; |
65+
|[Security Events via Legacy Agent](connect-services-windows-based.md#log-analytics-agent-legacy) |GA |&#x2705; |
66+
|[Syslog](connect-syslog.md) |GA |&#x2705; |
67+
|[Windows DNS Events via AMA (Preview)](connect-dns-ama.md) |Public Preview |&#10060; |
68+
|[Windows Firewall](data-connectors/windows-firewall.md) |GA |&#x2705; |
69+
|[Windows Forwarded Events (Preview)](connect-services-windows-based.md) |Public Preview |&#x2705; |
70+
|[Windows Security Events via AMA](connect-services-windows-based.md) |GA |&#x2705; |
71+
72+
<sup><a name="logsavailable"></a>1</sup> Supports only sign-in logs and audit logs.
5873

5974
## Hunting
6075

6176
|Feature |Azure commercial |Azure China 21Vianet |
6277
|---------|---------|---------|
6378
|[Hunting blade](hunting.md) |GA |&#x2705; |
64-
|[Search large datasets](search-jobs.md) |GA |&#x2705; |
6579
|[Restore historical data](restore.md) |GA |&#x2705; |
80+
|[Search large datasets](search-jobs.md) |GA |&#x2705; |
6681

67-
## Content and content management
82+
## Incidents
6883

6984
|Feature |Azure commercial |Azure China 21Vianet |
7085
|---------|---------|---------|
71-
|[Content hub](sentinel-solutions.md) and [solutions](sentinel-solutions-catalog.md) |Public preview |&#10060; |
72-
|[Repositories](ci-cd.md?tabs=github) |Public preview |&#10060; |
73-
|[Workbooks](monitor-your-data.md) |GA |&#x2705; |
86+
|[Add entities to threat intelligence](add-entity-to-threat-intelligence.md?tabs=incidents) |Public Preview |&#10060; |
87+
|[Advanced and/or conditions](add-advanced-conditions-to-automation-rules.md) |Public Preview |&#x2705; |
88+
|[Automation rules](automate-incident-handling-with-automation-rules.md) |Public Preview |&#x2705; |
89+
|[Automation rules health](monitor-automation-health.md) |Public Preview |&#10060; |
90+
|[Create incidents manually](create-incident-manually.md) |Public Preview |&#x2705; |
91+
|[Cross-tenant/Cross-workspace incidents view](multiple-workspace-view.md) |GA |&#x2705; |
92+
|[Incident advanced search](investigate-cases.md#search-for-incidents) |GA |&#x2705; |
93+
|[Incident tasks](incident-tasks.md) |Public Preview |&#x2705; |
94+
|[Microsoft 365 Defender incident integration](microsoft-365-defender-sentinel-integration.md#working-with-microsoft-365-defender-incidents-in-microsoft-sentinel-and-bi-directional-sync) |Public Preview |&#10060; |
95+
|[Microsoft Teams integrations](collaborate-in-microsoft-teams.md) |Public Preview |&#10060; |
96+
|[Playbook template gallery](use-playbook-templates.md) |Public Preview |&#10060; |
97+
|[Run playbooks on entities](respond-threats-during-investigation.md) |Public Preview |&#10060; |
98+
|[Run playbooks on incidents](automate-responses-with-playbooks.md) |Public Preview |&#x2705; |
99+
|[SOC incident audit metrics](manage-soc-with-incident-metrics.md) |GA |&#x2705; |
74100

75-
## SAP
101+
## Machine Learning
76102

77103
|Feature |Azure commercial |Azure China 21Vianet |
78104
|---------|---------|---------|
79-
|[Threat protection for SAP](sap/deployment-overview.md)<sup>[1](#sap)</sup> |GA |&#x2705; |
80-
|[Threat protection for SAP Business Technology Platform (BTP)](sap/deploy-sap-btp-solution.md) |Public Preview |&#10060; |
105+
|[Anomalous RDP login detection - built-in ML detection](configure-connector-login-detection.md) |Public Preview |&#x2705; |
106+
|[Anomalous SSH login detection - built-in ML detection](connect-syslog.md#configure-the-syslog-connector-for-anomalous-ssh-login-detection) |Public Preview |&#x2705; |
107+
|[Bring Your Own ML (BYO-ML)](bring-your-own-ml.md) |Public Preview |&#10060; |
108+
|[Fusion](fusion.md) - advanced multistage attack detections <sup>[1](#partialga)</sup> |GA |&#x2705; |
109+
|[Fusion detection for ransomware](fusion.md#fusion-for-ransomware) |Public Preview |&#x2705; |
110+
|[Fusion for emerging threats](fusion.md#fusion-for-emerging-threats) |Public Preview |&#x2705; |
81111

82-
<sup><a name="sap"></a>1</sup> Deploy SAP security content [via GitHub](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/SAP).
112+
<sup><a name="partialga"></a>1</sup> Partially GA: The ability to disable specific findings from vulnerability scans is in public preview.
83113

84114
## Normalization
85115

86116
|Feature |Azure commercial |Azure China 21Vianet |
87117
|---------|---------|---------|
88-
|[Advanced SIEM Information Model (ASIM)](normalization.md) |Public Preview |&#x2705; |
118+
|[Advanced Security Information Model (ASIM)](normalization.md) |Public Preview |&#x2705; |
89119

90-
## UEBA
120+
## Notebooks
91121

92122
|Feature |Azure commercial |Azure China 21Vianet |
93123
|---------|---------|---------|
94-
|[Entity insights](identify-threats-with-entity-behavior-analytics.md) |GA |&#x2705; |
95-
|[Identity info table data ingestion](investigate-with-ueba.md) |GA |&#x2705; |
96-
|[UEBA enrichments\insights](investigate-with-ueba.md) |GA |&#x2705; |
97-
|[Entity pages](entity-pages.md) |GA |&#x2705; |
98-
|[Azure resource entity pages](entity-pages.md) |Public Preview |&#10060; |
99-
|[IoT device entity page](/azure/defender-for-iot/organizations/iot-advanced-threat-monitoring#investigate-further-with-iot-device-entities) |Public Preview |&#10060; |
100-
|[UEBA anomalies](soc-ml-anomalies.md#ueba-anomalies) |GA |&#10060; |
101-
|[SOC-ML anomalies](soc-ml-anomalies.md#what-are-customizable-anomalies) |GA |&#10060; |
102-
|[Peer/Blast radius enrichments](identify-threats-with-entity-behavior-analytics.md#what-is-user-and-entity-behavior-analytics-ueba) |Public preview |&#10060; |
103-
|[Active Directory sync via MDI](enable-entity-behavior-analytics.md#how-to-enable-user-and-entity-behavior-analytics) |Public preview |&#10060; |
124+
|[Notebooks](notebooks.md) |GA |&#x2705; |
125+
|[Notebook integration with Azure Synapse](notebooks-with-synapse.md) |Public Preview |&#x2705; |
126+
127+
## SAP
128+
129+
|Feature |Azure commercial |Azure China 21Vianet |
130+
|---------|---------|---------|
131+
|[Threat protection for SAP](sap/deployment-overview.md)<sup>[1](#sap)</sup> |GA |&#x2705; |
132+
133+
<sup><a name="sap"></a>1</sup> Deploy SAP security content [via GitHub](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/SAP).
104134

105135
## Threat intelligence support
106136

107137
|Feature |Azure commercial |Azure China 21Vianet |
108138
|---------|---------|---------|
109-
|[Threat Intelligence - TAXII data connector](understand-threat-intelligence.md) |GA |&#x2705; |
139+
|[GeoLocation and WhoIs data enrichment](work-with-threat-indicators.md) |Public Preview |&#10060; |
140+
|[Import TI from flat file](indicators-bulk-file-import.md) |Public Preview |&#x2705; |
141+
|[Threat intelligence matching analytics](use-matching-analytics-to-detect-threats.md) |Public Preview |&#10060; |
110142
|[Threat Intelligence Platform data connector](understand-threat-intelligence.md) |Public Preview |&#x2705; |
111143
|[Threat Intelligence Research blade](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/what-s-new-threat-intelligence-menu-item-in-public-preview/ba-p/1646597) |GA |&#x2705; |
112-
|[URL detonation](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/using-the-new-built-in-url-detonation-in-azure-sentinel/ba-p/996229) |Public Preview |&#10060; |
144+
|[Threat Intelligence - TAXII data connector](understand-threat-intelligence.md) |GA |&#x2705; |
113145
|[Threat Intelligence workbook](/azure/architecture/example-scenario/data/sentinel-threat-intelligence) |GA |&#x2705; |
114-
|[GeoLocation and WhoIs data enrichment](work-with-threat-indicators.md) |Public Preview |&#10060; |
115-
|[Threat intelligence matching analytics](use-matching-analytics-to-detect-threats.md) |Public Preview |&#10060; |
116-
|[Import TI from flat file](indicators-bulk-file-import.md) |Public Preview |&#x2705; |
146+
|[URL detonation](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/using-the-new-built-in-url-detonation-in-azure-sentinel/ba-p/996229) |Public Preview |&#10060; |
117147

118-
## Machine Learning
148+
## UEBA
119149

120150
|Feature |Azure commercial |Azure China 21Vianet |
121151
|---------|---------|---------|
122-
|[Fusion](fusion.md) - advanced multistage attack detections <sup>[1](#partialga)</sup> |GA |&#x2705; |
123-
|[Fusion detection for ransomware](fusion.md#fusion-for-ransomware) |Public Preview |&#x2705; |
124-
|[Fusion for emerging threats](fusion.md#fusion-for-emerging-threats) |Public Preview |&#x2705; |
125-
|[Anomalous RDP login detection - built-in ML detection](configure-connector-login-detection.md) |Public Preview |&#10060; |
126-
|[Anomalous SSH login detection - built-in ML detection](connect-syslog.md#configure-the-syslog-connector-for-anomalous-ssh-login-detection) |Public Preview |&#10060; |
127-
|[Bring Your Own ML (BYO-ML)](bring-your-own-ml.md) |Public Preview |&#10060; |
128-
129-
<sup><a name="partialga"></a>1</sup> Partially GA: The ability to disable specific findings from vulnerability scans is in public preview.
152+
|[Active Directory sync via MDI](enable-entity-behavior-analytics.md#how-to-enable-user-and-entity-behavior-analytics) |Public preview |&#10060; |
153+
|[Azure resource entity pages](entity-pages.md) |Public Preview |&#10060; |
154+
|[Entity insights](identify-threats-with-entity-behavior-analytics.md) |GA |&#x2705; |
155+
|[Entity pages](entity-pages.md) |GA |&#x2705; |
156+
|[Identity info table data ingestion](investigate-with-ueba.md) |GA |&#x2705; |
157+
|[IoT device entity page](/azure/defender-for-iot/organizations/iot-advanced-threat-monitoring#investigate-further-with-iot-device-entities) |Public Preview |&#10060; |
158+
|[Peer/Blast radius enrichments](identify-threats-with-entity-behavior-analytics.md#what-is-user-and-entity-behavior-analytics-ueba) |Public preview |&#10060; |
159+
|[SOC-ML anomalies](soc-ml-anomalies.md#what-are-customizable-anomalies) |GA |&#10060; |
160+
|[UEBA anomalies](soc-ml-anomalies.md#ueba-anomalies) |GA |&#10060; |
161+
|[UEBA enrichments\insights](investigate-with-ueba.md) |GA |&#x2705; |
130162

131-
## Data collection
163+
## Watchlists
132164

133165
|Feature |Azure commercial |Azure China 21Vianet |
134166
|---------|---------|---------|
135-
|[Azure Activity](data-connectors/azure-activity.md) |GA |&#x2705; |
136-
|[Azure Active Directory](connect-azure-active-directory.md) |GA |&#x2705; <sup>[1](#logsavailable)</sup> |
137-
|[Azure Active Directory Identity Protection](connect-services-api-based.md) |GA |&#10060; |
138-
|[Azure DDoS Protection](connect-services-diagnostic-setting-based.md) |GA |&#10060; |
139-
|[Microsoft 365 Defender](connect-microsoft-365-defender.md?tabs=MDE) |GA |&#10060; |
140-
|[Microsoft Purview (Preview)](connect-services-diagnostic-setting-based.md) |Public Preview |&#10060; |
141-
|[Microsoft Defender for Cloud](connect-defender-for-cloud.md) |GA |&#x2705; |
142-
|[Microsoft Defender for IoT](connect-services-api-based.md) |GA |&#10060; |
143-
|[Microsoft 365 Insider Risk Management (Preview)](sentinel-solutions-catalog.md#domain-solutions) |Public Preview |&#10060; |
144-
|[Azure Firewall](data-connectors/azure-firewall.md) |GA |&#x2705; |
145-
|[Azure Information Protection (Preview)](data-connectors/azure-information-protection.md) |Deprecated |&#10060; |
146-
|[Microsoft Purview Information Protection](connect-microsoft-purview.md) |Public Preview |&#10060; |
147-
|[Azure Key Vault](data-connectors/azure-key-vault.md) |Public Preview |&#x2705; |
148-
|[Azure Kubernetes Service (AKS)](data-connectors/azure-kubernetes-service-aks.md) |Public Preview |&#x2705; |
149-
|Azure SQL Databases |GA |&#x2705; |
150-
|[Azure Web Application Firewall (WAF)](data-connectors/azure-web-application-firewall-waf.md) |GA |&#x2705; |
151-
|[Windows Firewall](data-connectors/windows-firewall.md) |GA |&#x2705; |
152-
|[Security Events via Legacy Agent](connect-services-windows-based.md#log-analytics-agent-legacy) |GA |&#x2705; |
153-
|[Windows Security Events via AMA](connect-services-windows-based.md) |GA |&#x2705; |
154-
|[Windows Forwarded Events (Preview)](connect-services-windows-based.md) |Public Preview |&#x2705; |
155-
|[Common Event Format (CEF) via AMA (Preview)](connect-cef-ama.md) |Public Preview |&#x2705; |
156-
|[Windows DNS Events via AMA (Preview)](connect-dns-ama.md) |Public Preview |&#10060; |
157-
|[DNS](data-connectors/dns.md) |Public Preview |&#x2705; |
158-
|[Office 365](connect-services-api-based.md) |GA |&#x2705; |
159-
|[Microsoft Project (Preview)](data-connectors/microsoft-project.md) |Public Preview |&#10060; |
160-
|[Microsoft PowerBI (Preview)](data-connectors/microsoft-powerbi.md) |Public Preview |&#10060; |
161-
|[Common Event Format (CEF)](connect-common-event-format.md) |GA |&#x2705; |
162-
|[Cisco ASA](data-connectors/cisco-asa.md) |GA |&#x2705; |
163-
|[Syslog](connect-syslog.md) |GA |&#x2705; |
164-
|[Amazon Web Services](connect-aws.md?tabs=ct) |GA |&#10060; |
165-
|[Amazon Web Services S3 (Preview)](connect-aws.md?tabs=s3) |Public Preview |&#10060; |
166-
|[GCP Pub/Sub Audit Logs](connect-google-cloud-platform.md) |Public Preview |&#10060; |
167-
|[Codeless Connectors Platform](create-codeless-connector.md?tabs=deploy-via-arm-template%2Cconnect-via-the-azure-portal) |Public Preview |&#10060; |
168-
|[Data Connectors health](monitor-data-connector-health.md#use-the-sentinelhealth-data-table-public-preview) |Public Preview |&#10060; |
169-
170-
<sup><a name="logsavailable"></a>1</sup> Supports only sign-in logs and audit logs.
167+
|[Large watchlists from Azure Storage](watchlists.md) |Public Preview |&#10060; |
168+
|[Watchlists](watchlists.md) |GA |&#x2705; |
169+
|[Watchlist templates](watchlist-schemas.md) |Public Preview |&#10060; |
171170

172171
## Next steps
173172

0 commit comments

Comments
 (0)