Skip to content

Commit c11d7d3

Browse files
authored
Merge pull request #88992 from cabailey/cabailey-azuredocs-aipconnector
Add other Azure AD roles needed for AIP connector & clarify not needed after configuration
2 parents 78d79b6 + f85fb27 commit c11d7d3

File tree

1 file changed

+14
-6
lines changed

1 file changed

+14
-6
lines changed

articles/sentinel/connect-azure-information-protection.md

Lines changed: 14 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -13,12 +13,12 @@ ms.devlang: na
1313
ms.topic: conceptual
1414
ms.tgt_pltfrm: na
1515
ms.workload: na
16-
ms.date: 09/15/2019
16+
ms.date: 09/20/2019
1717
ms.author: cabailey
1818

1919
---
2020

21-
# Connect data from Azure Information Protection - Preview
21+
# Connect data from Azure Information Protection
2222

2323
You can stream logging information from [Azure Information Protection](https://azure.microsoft.com/services/information-protection/) into Azure Sentinel by configuring the Azure Information Protection data connector. Azure Information Protection helps you control and secure your sensitive data, whether it’s stored in the cloud or on-premises.
2424

@@ -34,18 +34,25 @@ However, if logging information from Azure Information Protection is going to a
3434

3535
## Prerequisites
3636

37-
- One of the following Azure AD administrator roles for your tenant: Azure Information Protection administrator, Security administrator, or Global administrator.
37+
- One of the following Azure AD administrator roles for your tenant:
38+
- Azure Information Protection administrator
39+
- Security administrator
40+
- Compliance administrator
41+
- Compliance data administrator
42+
- Global administrator
3843

3944
> [!NOTE]
40-
> You cannot use the Azure Information Protection administrator role if your tenant is on the [unified labeling platform](https://docs.microsoft.com/azure/information-protection/faqs#how-can-i-determine-if-my-tenant-is-on-the-unified-labeling-platform).
45+
> You cannot use the Azure Information Protection administrator role if your tenant is on the [unified labeling platform](/information-protection/faqs#how-can-i-determine-if-my-tenant-is-on-the-unified-labeling-platform).
46+
47+
These administrator roles are required only for configuring the Azure Information Protection connector, and aren't required when Azure Sentinel is connected to Azure Information Protection.
4148

42-
- Permissions to read and write to the Log Analytics workspace you're using for Sentinel and Azure Information Protection.
49+
- Permissions to read and write to the Log Analytics workspace you're using for Azure Sentinel and Azure Information Protection.
4350

4451
- Azure Information Protection has been added to the Azure portal. If you need help with this step, see [Add Azure Information Protection to the Azure portal](https://docs.microsoft.com/azure/information-protection/quickstart-viewpolicy#add-azure-information-protection-to-the-azure-portal).
4552

4653
## Connect to Azure Information Protection
4754

48-
Use the following instructions if you haven't configured a Log Analytics workspace for Azure Information Protection, or you need to change the workspace that stores the Azure Information Protection logging information.
55+
Use the following instructions if you haven't configured a Log Analytics workspace for Azure Information Protection, or you need to change the workspace that stores the Azure Information Protection logging information.
4956

5057
1. In Azure Sentinel, select **Data connectors**, and then **Azure Information Protection**.
5158

@@ -62,6 +69,7 @@ Use the following instructions if you haven't configured a Log Analytics workspa
6269
To use the relevant schema in Azure Monitor for this reporting data, search for **InformationProtectionEvents**. For information about these event functions, see the [Friendly schema reference for event functions](https://docs.microsoft.com/azure/information-protection/reports-aip#friendly-schema-reference-for-event-functions) section from the Azure Information Protection documentation.
6370

6471
## Next steps
72+
6573
In this document, you learned how to connect Azure Information Protection to Azure Sentinel. To learn more about Azure Sentinel, see the following articles:
6674
- Learn how to [get visibility into your data, and potential threats](quickstart-get-visibility.md).
6775
- Get started [detecting threats with Azure Sentinel](tutorial-detect-threats-built-in.md).

0 commit comments

Comments
 (0)