Skip to content

Commit 89916de

Browse files
authored
Update offboard.md
1 parent 602c87e commit 89916de

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

articles/sentinel/offboard.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,14 +21,14 @@ If you instead want to offboard Microsoft Sentinel from the Defender portal, see
2121

2222
## Prerequisites
2323

24-
Before you begin, review [Implications of removing Microsoft Sentinel from your workspace](offboard-implications.md).
24+
Before you begin, review [Implications of removing Microsoft Sentinel from your workspace](offboard-implications.md).
25+
26+
For example, you can't manage Microsoft Sentinel tables in Log Analytics after removing Microsoft Sentinel, such as to set extended data retention. Therefore, to avoid extra data retention charges, we recommend that you set per-table retention to 90 days or less for Microsoft Sentinel tables stored in Log Analytics that will be inaccessible after removing Microsoft Sentinel.
2527

2628
## Remove Microsoft Sentinel
2729

2830
Complete the following steps to remove Microsoft Sentinel from your Log Analytics workspace.
2931

30-
1. Before removing Sentinel, note that you will no longer have visibility to manage Sentinel tables, such as setting extended data retention, in the Log Analytics Tables UI. Please consider per-table retention to 90 days or less to avoid data retention charges for the Sentinel data that Log Analytics will store, but which you can no longer access after Sentinel is removed.
31-
3232
1. For Microsoft Sentinel in the [Azure portal](https://portal.microsoft.com), under **Configuration**, select **Settings**.<br>On the **Settings** page, select the **Settings** tab. <br><br> For Microsoft Sentinel in the [Defender portal](https://security.microsoft.com/), select **System** > **Settings** > **Microsoft Sentinel**.
3333

3434
1. Select **Remove Microsoft Sentinel**.

0 commit comments

Comments
 (0)