Skip to content

Commit 63b6e57

Browse files
authored
Merge pull request #303573 from EdB-MSFT/customer-managed-keys-limitation
limitation for customer managed keys
2 parents ab52552 + ec17fb8 commit 63b6e57

File tree

4 files changed

+14
-2
lines changed

4 files changed

+14
-2
lines changed

articles/sentinel/datalake/sentinel-lake-onboarding.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -65,6 +65,8 @@ To onboard to the Microsoft Sentinel data lake Public Preview, you must be an ex
6565
+ You must have a Microsoft Sentinel primary workspace and other workspaces in the same region as your tenant’s home region.
6666
+ You must have read privileges to the primary and other workspaces so they can be attached to the data lake. For public preview, attaching a primary and all workspaces to the data lake is only supported if they're in the same region as your tenant home region.
6767

68+
[!INCLUDE [Customer-managed keys limitation](../includes/customer-managed-keys-limitation.md)]
69+
6870
The following roles that are required to set up billing and authorize ingestion of asset data into the data lake:
6971

7072
+ Azure Subscription owner for billing setup.

articles/sentinel/datalake/sentinel-lake-service-limits.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,10 +17,10 @@ ms.author: edbaynash
1717

1818
The following service parameters and limits apply to the Microsoft Sentinel data lake service.
1919

20-
[!INCLUDE [Service limits for VS Code notebooks](../includes/service-limits-notebooks.md)]
21-
2220
[!INCLUDE [Service limits for tables, data management and ingestion](../includes/service-limits-table-manaement-ingestion.md)]
2321

22+
[!INCLUDE [Service limits for VS Code notebooks](../includes/service-limits-notebooks.md)]
23+
2424
[!INCLUDE [Service limits for KQL queries against the data lake](../includes/service-limits-kql-queries.md)]
2525

2626
[!INCLUDE [Service limits for KQL jobs](../includes/service-limits-kql-jobs.md)]
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
---
2+
author: EdB-MSFT
3+
ms.author: edbayansh
4+
ms.topic: include
5+
ms.date: 07/30/2025
6+
---
7+
> [!IMPORTANT]
8+
> For Microsoft Sentinel customers using Customer-Managed Keys (CMK) for data encryption, we advise against onboarding to the Microsoft Sentinel data lake during the preview. Due to current preview limitations, certain data lake components don't support encryption using CMK. As a result, onboarding to the Microsoft Sentinel data lake at this stage may lead to noncompliance with your organization's encryption policies or data protection requirements. We recommend waiting until full CMK support is available across all Microsoft Sentinel data lake layers before proceeding.

articles/sentinel/includes/service-limits-table-manaement-ingestion.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,8 @@ ms.date: 07/15/2025
1010
> [!NOTE]
1111
> During preview Microsoft Sentinel data lake uses a single region. Your primary and other workspaces must be in the same region as your tenant’s home region. Only workspaces in the same region as your tenant’s home region can be attached to the data lake.
1212
13+
[!INCLUDE [Customer-managed keys limitation](../includes/customer-managed-keys-limitation.md)]
14+
1315
The following table lists the service parameters and limits for the Microsoft Sentinel data lake (preview) service related to table management, data ingestion, and retention. These limits include, but aren't limited to, Azure Resource Graph data, Microsoft 365 data, and data mirroring.
1416

1517
| Category | Parameter/limit |

0 commit comments

Comments
 (0)