Skip to content

Commit ce90268

Browse files
updates from peer review
1 parent 51019ae commit ce90268

File tree

6 files changed

+35
-33
lines changed

6 files changed

+35
-33
lines changed
Binary file not shown.
Binary file not shown.
124 KB
Loading
63.6 KB
Loading
61 KB
Loading

articles/sentinel/workspace-manager.md

Lines changed: 35 additions & 33 deletions
Original file line numberDiff line numberDiff line change
@@ -1,18 +1,18 @@
11
---
2-
title: Manage multiple Microsoft Sentinel workspaces with Workspace Manager
3-
description: Learn how to centrally manage multiple Microsoft Sentinel workspaces within one or more Azure tenants with Workspace Manager. This article takes you through provisioning and usage of Workspace Manager to help you gain operational efficiency and operate at scale.
2+
title: Manage multiple Microsoft Sentinel workspaces with workspace manager
3+
description: Learn how to centrally manage multiple Microsoft Sentinel workspaces within one or more Azure tenants with workspace manager. This article takes you through provisioning and usage of Workspace Manager to help you gain operational efficiency and operate at scale.
44
author: austinmccollum
55
ms.author: austinmc
66
ms.topic: how-to
77
ms.date: 04/24/2023
88
ms.custom: template-how-to
99
---
1010

11-
# Centrally manage multiple Microsoft Sentinel workspaces with Workspace Manager
11+
# Centrally manage multiple Microsoft Sentinel workspaces with workspace manager
1212

13-
Learn how to centrally manage multiple Microsoft Sentinel workspaces within one or more Azure tenants with Workspace Manager. This article takes you through provisioning and usage of Workspace Manager. Whether you're a global enterprise or a Managed Security Services Provider (MSSP), Workspace Manager helps you gain operational efficiency and operate at scale.
13+
Learn how to centrally manage multiple Microsoft Sentinel workspaces within one or more Azure tenants with workspace manager. This article takes you through provisioning and usage of workspace manager. Whether you're a global enterprise or a Managed Security Services Provider (MSSP), workspace manager helps you operate at scale efficiently.
1414

15-
Here are the active content types supported with Workspace Manager:
15+
Here are the active content types supported with workspace manager:
1616
- Analytics rules
1717
- Automation rules (excluding Playbooks)
1818
- Parsers, Saved Searches and Functions
@@ -21,9 +21,9 @@ Here are the active content types supported with Workspace Manager:
2121

2222
## Prerequisites
2323

24-
- At least two Microsoft Sentinel workspaces. One to be the manager and at least one member to be managed.
25-
- The [Microsoft Sentinel Contributor role assignment](/azure/role-based-access-control/built-in-roles#microsoft-sentinel-contributor) is required on the central workspace (where Workspace Manager is enabled on), and on the member workspace(s) the user needs to manage. To learn more about roles in Microsoft Sentinel, see [Roles and permissions in Microsoft Sentinel](roles.md).
26-
- Enable Azure Lighthouse if you're' managing workspaces across multiple Azure AD tenants. To learn more, see [Manage Microsoft Sentinel workspaces at scale](/azure/lighthouse/how-to/manage-sentinel-workspaces).
24+
- You need at least two Microsoft Sentinel workspaces. One workspace to manage from and at least one other workspace to be managed.
25+
- The [Microsoft Sentinel Contributor role assignment](/azure/role-based-access-control/built-in-roles#microsoft-sentinel-contributor) is required on the central workspace (where workspace manager is enabled on), and on the member workspace(s) the contributor needs to manage. To learn more about roles in Microsoft Sentinel, see [Roles and permissions in Microsoft Sentinel](roles.md).
26+
- Enable Azure Lighthouse if you're managing workspaces across multiple Azure AD tenants. To learn more, see [Manage Microsoft Sentinel workspaces at scale](/azure/lighthouse/how-to/manage-sentinel-workspaces).
2727

2828

2929
## Considerations
@@ -36,51 +36,53 @@ Depending on your scenario, consider these architectures:
3636

3737
:::image type="content" source="media/workspace-manager/architectures.png" alt-text="A diagram showing various architecture choices for workspace manager in Microsoft Sentinel.":::
3838

39-
## Enable Workspace Manager on the central workspace
40-
Enable the central workspace once you have decided which Microsoft Sentinel workspace should be the Workspace Manager.
41-
42-
1. Navigate to the **Settings** blade in the Parent workspace, and toggle "On" the Workspace Manager configuration setting.
43-
:::image type="content" source="media/workspace-manager/enable-workspace-manager.png" alt-text="A screenshot showing the Workspace manager configuration settings with the workspace parent toggle button highlighted.":::
39+
## Enable workspace manager on the central workspace
40+
Enable the central workspace once you have decided which Microsoft Sentinel workspace should be the workspace manager.
4441

42+
1. Navigate to the **Settings** blade in the parent workspace, and toggle "On" the workspace manager configuration setting.
4543
1. Once enabled, a new blade **Workspace manager (preview)** appears on the left menu under **Configuration**.
46-
:::image type="content" source="media/workspace-manager/enable-workspace-manager-enabled.png" alt-text="A screenshot showing the Workspace manager configuration settings with the new workspace manager menu section highlighted.":::
44+
45+
Here's a comparison of the feature off and enabled side by side.
46+
:::image type="content" source="media/workspace-manager/workspace-manager-before-after.png" alt-text="A screenshot showing the Workspace manager configuration settings with the workspace parent toggle button off next to the same screen with the menu item added for workspace manager and the toggle button on.":::
4747

4848
## Onboard member workspaces
49-
Member workspaces are the set of workspaces that will be managed by Workspace Manager. You can onboard some or all of the workspaces in the tenant, and across multiple tenants as well (if Azure Lighthouse is enabled).
50-
1. Navigate to Workspace Manager and select "Add workspaces"
49+
Member workspaces are the set of workspaces that will be managed by workspace manager. You can onboard some or all of the workspaces in the tenant, and across multiple tenants as well (if Azure Lighthouse is enabled).
50+
1. Navigate to workspace manager and select "Add workspaces"
5151
:::image type="content" source="media/workspace-manager/add-workspace.png" alt-text="Screenshot shows the add workspace menu." lightbox="media/workspace-manager/add-workspace.png":::
52-
1. Select the member workspace(s) you would like to onboard to Workspace Manager.
52+
1. Select the member workspace(s) you would like to onboard to workspace manager.
5353
:::image type="content" source="media/workspace-manager/add-workspace-select.png" alt-text="Screenshot shows the add workspace selection menu.":::
5454
1. Once successfully onboarded, the **Members** count increases and your member workspaces are reflected in the **Workspaces** tab.
5555
:::image type="content" source="media/workspace-manager/add-workspace-selected.png" alt-text="Screenshot shows the added workspaces and the Members count incremented to 2.":::
5656

57-
## Create a Group
58-
Groups allow you to organize workspaces together based on business groups, verticals, geography, etc. Use Groups to pair content items relevant to the workspaces in a group.
57+
## Create a group
58+
59+
Workspace manager groups allow you to organize workspaces together based on business groups, verticals, geography, etc. Use groups to pair content items relevant to the workspaces.
5960

6061
> [!TIP]
61-
> Before proceeding further, make sure that you have at least one active content item deployed in the central workspace. This will enable you to select content items from central to member workspace(s) in the subsequent steps.
62+
> Make sure you have at least one active content item deployed in the central workspace. This allows you to select content items from the central workspace to be published in the member workspace(s) in the subsequent steps.
6263
>
6364
64-
1. To create a Group:
65+
1. To create a group:
6566
- To add one workspace, select **Add** > **Group**.
6667
- To add multiple workspaces, select the workspaces and **Add** > **Group from selected**.
6768
:::image type="content" source="media/workspace-manager/add-group.png" alt-text="Screenshot shows the add group menu.":::
6869

69-
1. On the **Create or update group** page, enter a **Name** and **Description** for the Group.
70+
1. On the **Create or update group** page, enter a **Name** and **Description** for the group.
7071
:::image type="content" source="media/workspace-manager/add-group-name.png" alt-text="Screenshot shows the group create or update configuration page.":::
7172

72-
1. In the **Select workspaces** tab, click **Add** and select the member workspaces that you would like to add to the Group.
73+
1. In the **Select workspaces** tab, click **Add** and select the member workspaces that you would like to add to the group.
7374
1. In the **Select content** tab, you will have 2 ways to add content items.
74-
- Method 1: **Snapshot of all content** currently deployed in the central workspace. This point-in-time snapshot selects only active content, not templates.
75-
- Method 2: **Custom select** which content items should be added.
75+
- Method 1: Select the **Add** menu and choose **All content**. This will pull all active content currently deployed in the central workspace. This is a point-in-time snapshot that selects only active content, not templates.
76+
- Method 2: Select the **Add** menu and choose **Content**. This opens a **Select content** pane where you can custom select the content to be added.
7677
:::image type="content" source="media/workspace-manager/add-group-content.png" alt-text="Screenshot shows the group content selection.":::
7778

78-
1. Once successfully created, the **Group count** increases and your Groups are reflected in the **Groups tab**.
79+
1. After either method, you can further filter the content before you **Review + create**.
80+
1. Once successfully created, the **Group count** increases and your groups are reflected in the **Groups tab**.
7981

8082
## Publish the Group definition
8183
At this point, the content items selected haven't been published to the member workspace(s) yet.
8284

83-
1. Click **Publish content** in the right flyout.
85+
1. Select the group > Click the **Publish content** button.
8486

8587
:::image type="content" source="media/workspace-manager/publish-group.png" alt-text="Screenshot shows the group publish window.":::
8688

@@ -97,19 +99,19 @@ At this point, the content items selected haven't been published to the member w
9799

98100

99101
### Troubleshooting
100-
To facilitate troubleshooting, click the **Failed** hyperlink, to open the Job failure details window. A status for each content item and target workspace pair is displayed.
102+
Each publish attempt has a link to help with troubleshooting if something goes wrong. Click the **Failed** hyperlink, to open the job failure details window. A status for each content item and target workspace pair is displayed.
101103
:::image type="content" source="media/workspace-manager/publish-groups-job-details.png" alt-text="Screenshot shows the job details of a group publishing failure event." lightbox="media/workspace-manager/publish-groups-job-details.png":::
102104

103105
Common reasons for failure include:
104-
- Content items referenced in the Group definition no longer exist at the time of Publish (have been deleted).
105-
- Permissions have changed at the time of Publish. For example, the user is no longer a Microsoft Sentinel Contributor or doesn't have sufficient permissions on the member workspace anymore.
106+
- Content items referenced in the group definition no longer exist at the time of publish (have been deleted).
107+
- Permissions have changed at the time of publish. For example, the user is no longer a Microsoft Sentinel Contributor or doesn't have sufficient permissions on the member workspace anymore.
106108
- A member workspace has been deleted.
107109

108110
### Known limitations
109-
- Playbooks attributed or attached to Analytics and Automation rules are not currently supported.
111+
- Playbooks attributed or attached to analytics and automation rules aren't currently supported.
110112
- Workbooks stored in bring-your-own-storage aren't currently supported.
111-
- Workspace Manager only manages content items published from the central workspace. It doesn't manage content created locally from member workspace(s).
112-
- Currently, deleting content residing in member workspace(s) centrally via Workspace Manager isn't supported.
113+
- Workspace manager only manages content items published from the central workspace. It doesn't manage content created locally from member workspace(s).
114+
- Currently, deleting content residing in member workspace(s) centrally via workspace manager isn't supported.
113115

114116
### API references
115117
- [Workspace Manager Assignment Jobs](/rest/api/securityinsights/preview/workspace-manager-assignment-jobs)

0 commit comments

Comments
 (0)