You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/connect-azure-information-protection.md
+14-6Lines changed: 14 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,12 +13,12 @@ ms.devlang: na
13
13
ms.topic: conceptual
14
14
ms.tgt_pltfrm: na
15
15
ms.workload: na
16
-
ms.date: 09/15/2019
16
+
ms.date: 09/20/2019
17
17
ms.author: cabailey
18
18
19
19
---
20
20
21
-
# Connect data from Azure Information Protection - Preview
21
+
# Connect data from Azure Information Protection
22
22
23
23
You can stream logging information from [Azure Information Protection](https://azure.microsoft.com/services/information-protection/) into Azure Sentinel by configuring the Azure Information Protection data connector. Azure Information Protection helps you control and secure your sensitive data, whether it’s stored in the cloud or on-premises.
24
24
@@ -34,18 +34,25 @@ However, if logging information from Azure Information Protection is going to a
34
34
35
35
## Prerequisites
36
36
37
-
- One of the following Azure AD administrator roles for your tenant: Azure Information Protection administrator, Security administrator, or Global administrator.
37
+
- One of the following Azure AD administrator roles for your tenant:
38
+
- Azure Information Protection administrator
39
+
- Security administrator
40
+
- Compliance administrator
41
+
- Compliance data administrator
42
+
- Global administrator
38
43
39
44
> [!NOTE]
40
-
> You cannot use the Azure Information Protection administrator role if your tenant is on the [unified labeling platform](https://docs.microsoft.com/azure/information-protection/faqs#how-can-i-determine-if-my-tenant-is-on-the-unified-labeling-platform).
45
+
> You cannot use the Azure Information Protection administrator role if your tenant is on the [unified labeling platform](/information-protection/faqs#how-can-i-determine-if-my-tenant-is-on-the-unified-labeling-platform).
46
+
47
+
These administrator roles are required only for configuring the Azure Information Protection connector, and aren't required when Azure Sentinel is connected to Azure Information Protection.
41
48
42
-
- Permissions to read and write to the Log Analytics workspace you're using for Sentinel and Azure Information Protection.
49
+
- Permissions to read and write to the Log Analytics workspace you're using for Azure Sentinel and Azure Information Protection.
43
50
44
51
- Azure Information Protection has been added to the Azure portal. If you need help with this step, see [Add Azure Information Protection to the Azure portal](https://docs.microsoft.com/azure/information-protection/quickstart-viewpolicy#add-azure-information-protection-to-the-azure-portal).
45
52
46
53
## Connect to Azure Information Protection
47
54
48
-
Use the following instructions if you haven't configured a Log Analytics workspace for Azure Information Protection, or you need to change the workspace that stores the Azure Information Protection logging information.
55
+
Use the following instructions if you haven't configured a Log Analytics workspace for Azure Information Protection, or you need to change the workspace that stores the Azure Information Protection logging information.
49
56
50
57
1. In Azure Sentinel, select **Data connectors**, and then **Azure Information Protection**.
51
58
@@ -62,6 +69,7 @@ Use the following instructions if you haven't configured a Log Analytics workspa
62
69
To use the relevant schema in Azure Monitor for this reporting data, search for **InformationProtectionEvents**. For information about these event functions, see the [Friendly schema reference for event functions](https://docs.microsoft.com/azure/information-protection/reports-aip#friendly-schema-reference-for-event-functions) section from the Azure Information Protection documentation.
63
70
64
71
## Next steps
72
+
65
73
In this document, you learned how to connect Azure Information Protection to Azure Sentinel. To learn more about Azure Sentinel, see the following articles:
66
74
- Learn how to [get visibility into your data, and potential threats](quickstart-get-visibility.md).
67
75
- Get started [detecting threats with Azure Sentinel](tutorial-detect-threats-built-in.md).
0 commit comments