Skip to content

Commit 89958b0

Browse files
authored
Merge pull request #218161 from limwainstein/gcc-mapping
Adding cloud support page (GCC)
2 parents e9e1b9a + 6991e7c commit 89958b0

File tree

4 files changed

+135
-1
lines changed

4 files changed

+135
-1
lines changed

articles/sentinel/TOC.yml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -73,6 +73,8 @@
7373
href: extend-sentinel-across-workspaces-tenants.md
7474
- name: Security baseline
7575
href: /security/benchmark/azure/baselines/sentinel-security-baseline?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json
76+
- name: Support for data types in different clouds
77+
href: data-type-cloud-support.md
7678
- name: Find solutions and content
7779
items:
7880
- name: About Sentinel content
@@ -102,7 +104,7 @@
102104
- name: KQL quick reference
103105
href: /azure/data-explorer/kql-quick-reference?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json
104106
- name: Other KQL resources
105-
href: kusto-resources.md
107+
href: kusto-resources.md
106108
- name: Normalize data
107109
items:
108110
- name: ASIM overview
@@ -557,6 +559,8 @@
557559
href: windows-security-event-id-reference.md
558560
- name: DNS over AMA reference
559561
href: dns-ama-fields.md
562+
- name: Microsoft 365 Defender connector data type support
563+
href: microsoft-365-defender-cloud-support.md
560564
- name: Detection and analysis references
561565
items:
562566
- name: Top Microsoft Sentinel workbooks
Lines changed: 54 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,54 @@
1+
---
2+
title: Support for Microsoft Sentinel connector data types in different clouds
3+
description: This article describes the types of clouds that affect data streaming from the different connectors that Microsoft Sentinel supports.
4+
author: limwainstein
5+
ms.topic: conceptual
6+
ms.date: 11/14/2022
7+
ms.author: lwainstein
8+
---
9+
10+
# Support for data types in Microsoft Sentinel across different clouds
11+
12+
Microsoft Sentinel data connectors use data stored in various cloud environments, like the Microsoft 365 Commercial cloud or the Government Community Cloud (GCC).
13+
14+
This article describes the types of clouds that affect the supported data types for the different connectors that Microsoft Sentinel supports. Specifically, support varies for different Microsoft 365 Defender connector data types in different GCC environments.
15+
16+
## Microsoft cloud types
17+
18+
|Name |Also named|Description |Learn more |
19+
|---------|---------|---------|
20+
|Azure Commercial |Azure, Azure Public |The standard Microsoft cloud. Most of the enterprises in the private market, academic institutions and home Office 365 tenants reside in a Commercial environment.<br><br>Different tools help meet the Microsoft 365 Commercial compliance and security needs. For example: Intune, Microsoft Purview compliance portal, Microsoft Purview Information Protection, and more. |[Microsoft 365 integration](../security/fundamentals/feature-availability.md#microsoft-365-integration) |
21+
|Government Community Cloud (GCC) |GCC-M, GCC Moderate |A government-focused copy of Microsoft 365 Commercial environment. While GCC contains similar features to the Microsoft 365 Commercial environment, GCC is subject to the FedRAMP Moderate policy. |[Government Community Cloud](/office365/servicedescriptions/office-365-platform-service-description/office-365-us-government/gcc) |
22+
|Department of Defense (DoD) | |Originally created for internal use by the Department of Defense. DoD is the only environment that meets DoD SRG levels 5 and 6. Other clouds described in this article don't support these SRG levels. |[GCC High and DoD](/office365/servicedescriptions/office-365-platform-service-description/office-365-us-government/gcc-high-and-dod) |
23+
|GCC-High |GCC High |Technically, GCC High is a copy of a DoD environment, but GCC High exists in its own sovereign environment.<br><br>GCC High (and above) stores the data in Azure Government, so it is physically segregated from the commercial services. |[GCC High and DoD](/office365/servicedescriptions/office-365-platform-service-description/office-365-us-government/gcc-high-and-dod) |
24+
25+
## Microsoft clouds and Microsoft Sentinel
26+
27+
Microsoft Sentinel is built on Microsoft Azure environments—both commercial and government. Office 365 environments, like GCC, GCC-High and DoD, interface at different levels with Azure environments.
28+
29+
This diagram shows the hierarchy of the Office 365 and Microsoft Azure clouds and how they relate to each other and to Microsoft Sentinel.
30+
31+
:::image type="content" source="./media/data-type-cloud-support/cloud-architecture-microsoft-sentinel.png" alt-text="Diagram showing how the Microsoft cloud architecture relates to Microsoft Sentinel data." border="false" lightbox="./media/data-type-cloud-support/cloud-architecture-microsoft-sentinel.png":::
32+
33+
Because of this complexity, different types of data streaming into Microsoft Sentinel may or may not be fully supported.
34+
35+
## How cloud support affects data from Microsoft 365 Defender connectors
36+
37+
Your environment ingests data from multiple connectors. The type of cloud you use affects Microsoft Sentinel's ability to ingest and display data from these connectors, like logs, alerts, device events, and more.
38+
39+
We have identified support discrepancies between the different clouds for the data streaming from these connectors:
40+
41+
- Microsoft Defender for Endpoint
42+
- Microsoft Defender for Office 365
43+
- Microsoft Defender for Identity
44+
- Microsoft Defender for Cloud Apps
45+
- Azure Active Directory Identity Protection
46+
47+
Read more about [support for Microsoft Defender 365 connector data types in different clouds](microsoft-365-defender-cloud-support.md).
48+
49+
## Next steps
50+
51+
In this article, you learned about the types of clouds that affect the supported data types for the different connectors that Microsoft Sentinel supports.
52+
53+
- To get started with Microsoft Sentinel, you need a subscription to Microsoft Azure. If you don't have a subscription, you can sign up for a [free trial](https://azure.microsoft.com/free/).
54+
- Learn how to [onboard your data to Microsoft Sentinel](quickstart-onboard.md) and [get visibility into your data and potential threats](get-visibility.md).
142 KB
Loading
Lines changed: 76 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,76 @@
1+
---
2+
title: Support for Microsoft 365 Defender connector data types in Microsoft Sentinel for different clouds (GCC environments)
3+
description: This article describes support for different Microsoft 365 Defender connector data types in Microsoft Sentinel across different clouds, including Commercial, GCC, GCC-High, and DoD.
4+
author: limwainstein
5+
ms.topic: reference
6+
ms.date: 11/14/2022
7+
ms.author: lwainstein
8+
---
9+
10+
# Support for Microsoft 365 Defender connector data types in different clouds
11+
12+
The type of cloud your environment uses affects Microsoft Sentinel's ability to ingest and display data from these connectors, like logs, alerts, device events, and more. This article describes support for different Microsoft 365 Defender connector data types in Microsoft Sentinel across different clouds, including Commercial, GCC, GCC-High, and DoD.
13+
14+
Read more about [data type support for different clouds in Microsoft Sentinel](data-type-cloud-support.md).
15+
16+
## Microsoft Defender for Endpoint
17+
18+
|Data type |Commercial |GCC |GCC-High |DoD |
19+
|---------|---------|---------|---------|---------|
20+
|DeviceInfo |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
21+
|DeviceNetworkInfo |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
22+
|DeviceProcessEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</ul></li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
23+
|DeviceNetworkEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |
24+
|DeviceFileEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
25+
|DeviceRegistryEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
26+
|DeviceLogonEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
27+
|DeviceImageLoadEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
28+
|DeviceEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
29+
|DeviceFileCertificateInfo |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
30+
31+
## Microsoft Defender for Identity
32+
33+
|Data type |Commercial |GCC |GCC-High |DoD |
34+
|---------|---------|---------|---------|---------|
35+
|IdentityDirectoryEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |Unsupported |Unsupported |Unsupported |
36+
IdentityLogonEvents|<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |Unsupported |Unsupported |Unsupported |
37+
IdentityQueryEvents|<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |Unsupported |Unsupported |Unsupported |
38+
39+
## Microsoft Defender for Cloud Apps
40+
41+
|Data type |Commercial |GCC |GCC-High |DoD |
42+
|---------|---------|---------|---------|---------|
43+
|CloudAppEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |Unsupported |Unsupported |Unsupported |
44+
45+
## Microsoft 365 Defender incidents
46+
47+
|Data type |Commercial |GCC |GCC-High |DoD |
48+
|---------|---------|---------|---------|---------|
49+
|SecurityIncident |Microsoft Sentinel: Public Preview |Microsoft Sentinel: Public Preview |Microsoft Sentinel: Public Preview |Microsoft Sentinel: Public Preview |
50+
51+
## Alerts
52+
53+
|Connector/Data type |Commercial |GCC |GCC-High |DoD |
54+
|---------|---------|---------|---------|---------|
55+
|Microsoft 365 Defender Alerts: SecurityAlert |Public Preview |Public Preview |Public Preview |Public Preview |
56+
|Microsoft Defender for Endpoint Alerts (standalone connector): SecurityAlert (MDATP) |Public Preview |Public Preview |Public Preview |Public Preview |
57+
| Microsoft Defender for Office 365 Alerts (standalone connector): SecurityAlert (OATP) |Public Preview |Public Preview |Public Preview |Public Preview |
58+
Microsoft Defender for Identity Alerts (standalone connector): SecurityAlert (AATP) |Public Preview |Unsupported |Unsupported |Unsupported |
59+
Microsoft Defender for Cloud Apps Alerts (standalone connector): SecurityAlert (MCAS), |Public Preview |Unsupported |Unsupported |Unsupported |
60+
|Microsoft Defender for Cloud Apps Alerts (standalone connector): McasShadowItReporting |Public Preview |Unsupported |Unsupported |Unsupported |
61+
62+
## Azure Active Directory Identity Protection
63+
64+
|Data type |Commercial |GCC |GCC-High |DoD |
65+
|---------|---------|---------|---------|---------|
66+
|SecurityAlert (IPC) |Public Preview/GA |Supported |Supported |Supported |
67+
|AlertEvidence |Public Preview |Unsupported |Unsupported |Unsupported |
68+
69+
## Next steps
70+
71+
In this article, you learned which Microsoft 365 Defender connector data types are supported in Microsoft Sentinel for different cloud environments.
72+
73+
- Read more about [GCC environments in Microsoft Sentinel](data-type-cloud-support.md).
74+
- Learn how to [get visibility into your data, and potential threats](get-visibility.md).
75+
- Get started [detecting threats with Microsoft Sentinel](detect-threats-built-in.md).
76+
- [Use workbooks](monitor-your-data.md) to monitor your data.

0 commit comments

Comments
 (0)