You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/sentinel-solution.md
+11-11Lines changed: 11 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -28,7 +28,7 @@ While only Microsoft Sentinel is required to get started, the solution is enhanc
28
28
For more information, see [Guiding principles of Zero Trust](/azure/security/integrated/zero-trust-overview#guiding-principles-of-zero-trust).
29
29
30
30
> [!NOTE]
31
-
> Microsoft Sentinel solutions are sets of bundled content, pre-configured for a specific set of data. For more information, see [Microsoft Sentinel solutions documentation](sentinel-solutions).
31
+
> Microsoft Sentinel solutions are sets of bundled content, pre-configured for a specific set of data. For more information, see [Microsoft Sentinel solutions documentation](sentinel-solutions.md).
32
32
>
33
33
34
34
## The Zero Trust solution and the TIC 3.0 framework
@@ -53,7 +53,7 @@ The Microsoft Sentinel solution for **Zero Trust (TIC 3.0)** is useful for any o
53
53
54
54
Before installing the **Zero Trust (TIC 3.0)** solution, make sure you have the following prerequisites:
55
55
56
-
-**Onboard Microsoft services**: Make sure that you have both [Microsoft Sentinel](quickstart-onboard) and [Microsoft Defender for Cloud](/azure/defender-for-cloud/get-started) enabled in your Azure subscription.
56
+
-**Onboard Microsoft services**: Make sure that you have both [Microsoft Sentinel](quickstart-onboard.md) and [Microsoft Defender for Cloud](/azure/defender-for-cloud/get-started) enabled in your Azure subscription.
57
57
58
58
-**Microsoft Defender for Cloud requirements**: In Microsoft Defender for Cloud:
59
59
@@ -73,7 +73,7 @@ Before installing the **Zero Trust (TIC 3.0)** solution, make sure you have the
73
73
74
74
When you're done, select **Review + Create** to install the solution.
75
75
76
-
For more information, see [Deploy out-of-the-box content and solutions](sentinel-solutions-deploy).
76
+
For more information, see [Deploy out-of-the-box content and solutions](sentinel-solutions-deploy.md).
77
77
78
78
## Sample usage scenario
79
79
@@ -99,7 +99,7 @@ After [installing](#install-the-zero-trust-tic-30-solution) the **Zero Trust (TI
99
99
> Use the **Guides** toggle at the top left to view or hide recommendations and guide panes. For example, these may be helpful when you first access the workbook, but unnecessary once you've understood the relevant concepts.
100
100
>
101
101
102
-
1.**Explore queries**. For example, at the top right of the **Adaptive Access Control** card, select the **:***More* button, and then select the :::image type="icon" source="../media/integrate/sentinel-workbook/icon-open-in-logs.png" border="false"::: **Open the last run query in the Logs view.** option.
102
+
1.**Explore queries**. For example, at the top right of the **Adaptive Access Control** card, select the **:***More* button, and then select the :::image type="icon" source="media/sentinel-workbook/icon-open-in-logs.png" border="false"::: **Open the last run query in the Logs view.** option.
103
103
104
104
The query is opened in the Microsoft Sentinel **Logs** page:
105
105
@@ -117,7 +117,7 @@ For example, if your workload's resiliency posture falls below a specified perce
117
117
118
118
:::image type="content" source="media/sentinel-workbook/edit-rule.png" alt-text="Screenshot of the Analytics rule wizard.":::
119
119
120
-
For more information, see [Create custom analytics rules to detect threats](detect-threats-custom).
120
+
For more information, see [Create custom analytics rules to detect threats](detect-threats-custom.md).
121
121
122
122
### Respond with SOAR
123
123
@@ -127,15 +127,15 @@ Use this playbook to automatically monitor CMMC alerts, and notify the governanc
127
127
128
128
:::image type="content" source="media/sentinel-workbook/logic-app-sample.png" alt-text="Screenshot of the Logic app designer showing a sample playbook.":::
129
129
130
-
For more information, see [Use triggers and actions in Microsoft Sentinel playbooks](playbook-triggers-actions).
130
+
For more information, see [Use triggers and actions in Microsoft Sentinel playbooks](playbook-triggers-actions.md).
131
131
132
132
## Frequently asked questions
133
133
134
134
### Are custom views and reports supported?
135
135
136
136
Yes. You can customize your **Zero Trust (TIC 3.0)** workbook to view data by subscription, workspace, time, control family, or maturity level parameters, and you can export and print your workbook.
137
137
138
-
For more information, see [Use Azure Monitor workbooks to visualize and monitor your data](monitor-your-data).
138
+
For more information, see [Use Azure Monitor workbooks to visualize and monitor your data](monitor-your-data.md).
139
139
140
140
### Are additional products required?
141
141
@@ -151,13 +151,13 @@ Panels with no data provide a starting point for addressing Zero Trust and TIC 3
151
151
152
152
Yes. You can use workbook parameters, Azure Lighthouse, and Azure Arc to leverage the **Zero Trust (TIC 3.0)** solution across all of your subscriptions, clouds, and tenants.
153
153
154
-
For more information, see [Use Azure Monitor workbooks to visualize and monitor your data](monitor-your-data) and [Manage multiple tenants in Microsoft Sentinel as an MSSP](multiple-tenants-service-providers).
154
+
For more information, see [Use Azure Monitor workbooks to visualize and monitor your data](monitor-your-data.md) and [Manage multiple tenants in Microsoft Sentinel as an MSSP](multiple-tenants-service-providers.md).
155
155
156
156
### Is partner integration supported?
157
157
158
158
Yes. Both workbooks and analytics rules are customizable for integrations with partner services.
159
159
160
-
For more information, see [Use Azure Monitor workbooks to visualize and monitor your data](monitor-your-data) and [Surface custom event details in alerts](surface-custom-details-in-alerts).
160
+
For more information, see [Use Azure Monitor workbooks to visualize and monitor your data](monitor-your-data.md) and [Surface custom event details in alerts](surface-custom-details-in-alerts.md).
161
161
162
162
### Is this available in government regions?
163
163
@@ -169,14 +169,14 @@ Yes. The **Zero Trust (TIC 3.0)** solution is in Public Preview and deployable t
169
169
170
170
-[Microsoft Sentinel Reader](/azure/role-based-access-control/built-in-roles#microsoft-sentinel-reader) users can view data, incidents, workbooks, and other Microsoft Sentinel resources.
171
171
172
-
For more information, see [Permissions in Microsoft Sentinel](roles).
172
+
For more information, see [Permissions in Microsoft Sentinel](roles.md).
173
173
174
174
## Next steps
175
175
176
176
For more information, see:
177
177
178
178
-[Get Started with Microsoft Sentinel](https://azure.microsoft.com/services/azure-sentinel/)
179
-
-[Visualize and monitor your data with workbooks](monitor-your-data)
179
+
-[Visualize and monitor your data with workbooks](monitor-your-data.md)
180
180
-[Microsoft Zero Trust Model](https://www.microsoft.com/security/business/zero-trust)
0 commit comments