|
| 1 | +--- |
| 2 | +title: Support for Microsoft 365 Defender connector data types in Microsoft Sentinel for different clouds (GCC environments) |
| 3 | +description: This article describes support for different Microsoft 365 Defender connector data types in Microsoft Sentinel across different clouds, including Commercial, GCC, GCC-High, and DoD. |
| 4 | +author: limwainstein |
| 5 | +ms.topic: reference |
| 6 | +ms.date: 11/14/2022 |
| 7 | +ms.author: lwainstein |
| 8 | +--- |
| 9 | + |
| 10 | +# Support for Microsoft 365 Defender connector data types in different clouds |
| 11 | + |
| 12 | +The type of cloud your environment uses affects Microsoft Sentinel's ability to ingest and display data from these connectors, like logs, alerts, device events, and more. This article describes support for different Microsoft 365 Defender connector data types in Microsoft Sentinel across different clouds, including Commercial, GCC, GCC-High, and DoD. |
| 13 | + |
| 14 | +Read more about [data type support for different clouds in Microsoft Sentinel](data-type-cloud-support.md). |
| 15 | + |
| 16 | +## Microsoft Defender for Endpoint |
| 17 | + |
| 18 | +|Data type |Commercial |GCC |GCC-High |DoD | |
| 19 | +|---------|---------|---------|---------|---------| |
| 20 | +|DeviceInfo |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> | |
| 21 | +|DeviceNetworkInfo |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> | |
| 22 | +|DeviceProcessEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</ul></li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> | |
| 23 | +|DeviceNetworkEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> | |
| 24 | +|DeviceFileEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> | |
| 25 | +|DeviceRegistryEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> | |
| 26 | +|DeviceLogonEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> | |
| 27 | +|DeviceImageLoadEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> | |
| 28 | +|DeviceEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> | |
| 29 | +|DeviceFileCertificateInfo |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> | |
| 30 | + |
| 31 | +## Microsoft Defender for Identity |
| 32 | + |
| 33 | +|Data type |Commercial |GCC |GCC-High |DoD | |
| 34 | +|---------|---------|---------|---------|---------| |
| 35 | +|IdentityDirectoryEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |Unsupported |Unsupported |Unsupported | |
| 36 | +IdentityLogonEvents|<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |Unsupported |Unsupported |Unsupported | |
| 37 | +IdentityQueryEvents|<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |Unsupported |Unsupported |Unsupported | |
| 38 | + |
| 39 | +## Microsoft Defender for Cloud Apps |
| 40 | + |
| 41 | +|Data type |Commercial |GCC |GCC-High |DoD | |
| 42 | +|---------|---------|---------|---------|---------| |
| 43 | +|CloudAppEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |Unsupported |Unsupported |Unsupported | |
| 44 | + |
| 45 | +## Microsoft 365 Defender incidents |
| 46 | + |
| 47 | +|Data type |Commercial |GCC |GCC-High |DoD | |
| 48 | +|---------|---------|---------|---------|---------| |
| 49 | +|SecurityIncident |Microsoft Sentinel: Public Preview |Microsoft Sentinel: Public Preview |Microsoft Sentinel: Public Preview |Microsoft Sentinel: Public Preview | |
| 50 | + |
| 51 | +## Alerts |
| 52 | + |
| 53 | +|Connector/Data type |Commercial |GCC |GCC-High |DoD | |
| 54 | +|---------|---------|---------|---------|---------| |
| 55 | +|Microsoft 365 Defender Alerts: SecurityAlert |Public Preview |Public Preview |Public Preview |Public Preview | |
| 56 | +|Microsoft Defender for Endpoint Alerts (standalone connector): SecurityAlert (MDATP) |Public Preview |Public Preview |Public Preview |Public Preview | |
| 57 | +| Microsoft Defender for Office 365 Alerts (standalone connector): SecurityAlert (OATP) |Public Preview |Public Preview |Public Preview |Public Preview | |
| 58 | +Microsoft Defender for Identity Alerts (standalone connector): SecurityAlert (AATP) |Public Preview |Unsupported |Unsupported |Unsupported | |
| 59 | +Microsoft Defender for Cloud Apps Alerts (standalone connector): SecurityAlert (MCAS), |Public Preview |Unsupported |Unsupported |Unsupported | |
| 60 | +|Microsoft Defender for Cloud Apps Alerts (standalone connector): McasShadowItReporting |Public Preview |Unsupported |Unsupported |Unsupported | |
| 61 | + |
| 62 | +## Azure Active Directory Identity Protection |
| 63 | + |
| 64 | +|Data type |Commercial |GCC |GCC-High |DoD | |
| 65 | +|---------|---------|---------|---------|---------| |
| 66 | +|SecurityAlert (IPC) |Public Preview/GA |Supported |Supported |Supported | |
| 67 | +|AlertEvidence |Public Preview |Unsupported |Unsupported |Unsupported | |
| 68 | + |
| 69 | +## Next steps |
| 70 | + |
| 71 | +In this article, you learned which Microsoft 365 Defender connector data types are supported in Microsoft Sentinel for different cloud environments. |
| 72 | + |
| 73 | +- Read more about [GCC environments in Microsoft Sentinel](data-type-cloud-support.md). |
| 74 | +- Learn how to [get visibility into your data, and potential threats](get-visibility.md). |
| 75 | +- Get started [detecting threats with Microsoft Sentinel](detect-threats-built-in.md). |
| 76 | +- [Use workbooks](monitor-your-data.md) to monitor your data. |
0 commit comments