You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/workspace-manager.md
+35-33Lines changed: 35 additions & 33 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,18 +1,18 @@
1
1
---
2
-
title: Manage multiple Microsoft Sentinel workspaces with Workspace Manager
3
-
description: Learn how to centrally manage multiple Microsoft Sentinel workspaces within one or more Azure tenants with Workspace Manager. This article takes you through provisioning and usage of Workspace Manager to help you gain operational efficiency and operate at scale.
2
+
title: Manage multiple Microsoft Sentinel workspaces with workspace manager
3
+
description: Learn how to centrally manage multiple Microsoft Sentinel workspaces within one or more Azure tenants with workspace manager. This article takes you through provisioning and usage of Workspace Manager to help you gain operational efficiency and operate at scale.
4
4
author: austinmccollum
5
5
ms.author: austinmc
6
6
ms.topic: how-to
7
7
ms.date: 04/24/2023
8
8
ms.custom: template-how-to
9
9
---
10
10
11
-
# Centrally manage multiple Microsoft Sentinel workspaces with Workspace Manager
11
+
# Centrally manage multiple Microsoft Sentinel workspaces with workspace manager
12
12
13
-
Learn how to centrally manage multiple Microsoft Sentinel workspaces within one or more Azure tenants with Workspace Manager. This article takes you through provisioning and usage of Workspace Manager. Whether you're a global enterprise or a Managed Security Services Provider (MSSP), Workspace Manager helps you gain operational efficiency and operate at scale.
13
+
Learn how to centrally manage multiple Microsoft Sentinel workspaces within one or more Azure tenants with workspace manager. This article takes you through provisioning and usage of workspace manager. Whether you're a global enterprise or a Managed Security Services Provider (MSSP), workspace manager helps you operate at scale efficiently.
14
14
15
-
Here are the active content types supported with Workspace Manager:
15
+
Here are the active content types supported with workspace manager:
16
16
- Analytics rules
17
17
- Automation rules (excluding Playbooks)
18
18
- Parsers, Saved Searches and Functions
@@ -21,9 +21,9 @@ Here are the active content types supported with Workspace Manager:
21
21
22
22
## Prerequisites
23
23
24
-
-At least two Microsoft Sentinel workspaces. One to be the manager and at least one member to be managed.
25
-
- The [Microsoft Sentinel Contributor role assignment](/azure/role-based-access-control/built-in-roles#microsoft-sentinel-contributor) is required on the central workspace (where Workspace Manager is enabled on), and on the member workspace(s) the user needs to manage. To learn more about roles in Microsoft Sentinel, see [Roles and permissions in Microsoft Sentinel](roles.md).
26
-
- Enable Azure Lighthouse if you're' managing workspaces across multiple Azure AD tenants. To learn more, see [Manage Microsoft Sentinel workspaces at scale](/azure/lighthouse/how-to/manage-sentinel-workspaces).
24
+
-You need at least two Microsoft Sentinel workspaces. One workspace to manage from and at least one other workspace to be managed.
25
+
- The [Microsoft Sentinel Contributor role assignment](/azure/role-based-access-control/built-in-roles#microsoft-sentinel-contributor) is required on the central workspace (where workspace manager is enabled on), and on the member workspace(s) the contributor needs to manage. To learn more about roles in Microsoft Sentinel, see [Roles and permissions in Microsoft Sentinel](roles.md).
26
+
- Enable Azure Lighthouse if you're managing workspaces across multiple Azure AD tenants. To learn more, see [Manage Microsoft Sentinel workspaces at scale](/azure/lighthouse/how-to/manage-sentinel-workspaces).
27
27
28
28
29
29
## Considerations
@@ -36,51 +36,53 @@ Depending on your scenario, consider these architectures:
36
36
37
37
:::image type="content" source="media/workspace-manager/architectures.png" alt-text="A diagram showing various architecture choices for workspace manager in Microsoft Sentinel.":::
38
38
39
-
## Enable Workspace Manager on the central workspace
40
-
Enable the central workspace once you have decided which Microsoft Sentinel workspace should be the Workspace Manager.
41
-
42
-
1. Navigate to the **Settings** blade in the Parent workspace, and toggle "On" the Workspace Manager configuration setting.
43
-
:::image type="content" source="media/workspace-manager/enable-workspace-manager.png" alt-text="A screenshot showing the Workspace manager configuration settings with the workspace parent toggle button highlighted.":::
39
+
## Enable workspace manager on the central workspace
40
+
Enable the central workspace once you have decided which Microsoft Sentinel workspace should be the workspace manager.
44
41
42
+
1. Navigate to the **Settings** blade in the parent workspace, and toggle "On" the workspace manager configuration setting.
45
43
1. Once enabled, a new blade **Workspace manager (preview)** appears on the left menu under **Configuration**.
46
-
:::image type="content" source="media/workspace-manager/enable-workspace-manager-enabled.png" alt-text="A screenshot showing the Workspace manager configuration settings with the new workspace manager menu section highlighted.":::
44
+
45
+
Here's a comparison of the feature off and enabled side by side.
46
+
:::image type="content" source="media/workspace-manager/workspace-manager-before-after.png" alt-text="A screenshot showing the Workspace manager configuration settings with the workspace parent toggle button off next to the same screen with the menu item added for workspace manager and the toggle button on.":::
47
47
48
48
## Onboard member workspaces
49
-
Member workspaces are the set of workspaces that will be managed by Workspace Manager. You can onboard some or all of the workspaces in the tenant, and across multiple tenants as well (if Azure Lighthouse is enabled).
50
-
1. Navigate to Workspace Manager and select "Add workspaces"
49
+
Member workspaces are the set of workspaces that will be managed by workspace manager. You can onboard some or all of the workspaces in the tenant, and across multiple tenants as well (if Azure Lighthouse is enabled).
50
+
1. Navigate to workspace manager and select "Add workspaces"
51
51
:::image type="content" source="media/workspace-manager/add-workspace.png" alt-text="Screenshot shows the add workspace menu." lightbox="media/workspace-manager/add-workspace.png":::
52
-
1. Select the member workspace(s) you would like to onboard to Workspace Manager.
52
+
1. Select the member workspace(s) you would like to onboard to workspace manager.
53
53
:::image type="content" source="media/workspace-manager/add-workspace-select.png" alt-text="Screenshot shows the add workspace selection menu.":::
54
54
1. Once successfully onboarded, the **Members** count increases and your member workspaces are reflected in the **Workspaces** tab.
55
55
:::image type="content" source="media/workspace-manager/add-workspace-selected.png" alt-text="Screenshot shows the added workspaces and the Members count incremented to 2.":::
56
56
57
-
## Create a Group
58
-
Groups allow you to organize workspaces together based on business groups, verticals, geography, etc. Use Groups to pair content items relevant to the workspaces in a group.
57
+
## Create a group
58
+
59
+
Workspace manager groups allow you to organize workspaces together based on business groups, verticals, geography, etc. Use groups to pair content items relevant to the workspaces.
59
60
60
61
> [!TIP]
61
-
> Before proceeding further, make sure that you have at least one active content item deployed in the central workspace. This will enable you to select content items from central to member workspace(s) in the subsequent steps.
62
+
> Make sure you have at least one active content item deployed in the central workspace. This allows you to select content items from the central workspace to be published in the member workspace(s) in the subsequent steps.
62
63
>
63
64
64
-
1. To create a Group:
65
+
1. To create a group:
65
66
- To add one workspace, select **Add** > **Group**.
66
67
- To add multiple workspaces, select the workspaces and **Add** > **Group from selected**.
67
68
:::image type="content" source="media/workspace-manager/add-group.png" alt-text="Screenshot shows the add group menu.":::
68
69
69
-
1. On the **Create or update group** page, enter a **Name** and **Description** for the Group.
70
+
1. On the **Create or update group** page, enter a **Name** and **Description** for the group.
70
71
:::image type="content" source="media/workspace-manager/add-group-name.png" alt-text="Screenshot shows the group create or update configuration page.":::
71
72
72
-
1. In the **Select workspaces** tab, click **Add** and select the member workspaces that you would like to add to the Group.
73
+
1. In the **Select workspaces** tab, click **Add** and select the member workspaces that you would like to add to the group.
73
74
1. In the **Select content** tab, you will have 2 ways to add content items.
74
-
- Method 1: **Snapshot of all content**currently deployed in the central workspace. This point-in-time snapshot selects only active content, not templates.
75
-
- Method 2: **Custom select** which content items should be added.
75
+
- Method 1: Select the **Add** menu and choose **All content**. This will pull all active content currently deployed in the central workspace. This is a point-in-time snapshot that selects only active content, not templates.
76
+
- Method 2: Select the **Add** menu and choose **Content**. This opens a **Select content** pane where you can custom select the content to be added.
76
77
:::image type="content" source="media/workspace-manager/add-group-content.png" alt-text="Screenshot shows the group content selection.":::
77
78
78
-
1. Once successfully created, the **Group count** increases and your Groups are reflected in the **Groups tab**.
79
+
1. After either method, you can further filter the content before you **Review + create**.
80
+
1. Once successfully created, the **Group count** increases and your groups are reflected in the **Groups tab**.
79
81
80
82
## Publish the Group definition
81
83
At this point, the content items selected haven't been published to the member workspace(s) yet.
82
84
83
-
1. Click **Publish content**in the right flyout.
85
+
1.Select the group > Click the **Publish content**button.
84
86
85
87
:::image type="content" source="media/workspace-manager/publish-group.png" alt-text="Screenshot shows the group publish window.":::
86
88
@@ -97,19 +99,19 @@ At this point, the content items selected haven't been published to the member w
97
99
98
100
99
101
### Troubleshooting
100
-
To facilitate troubleshooting, click the **Failed** hyperlink, to open the Job failure details window. A status for each content item and target workspace pair is displayed.
102
+
Each publish attempt has a link to help with troubleshooting if something goes wrong. Click the **Failed** hyperlink, to open the job failure details window. A status for each content item and target workspace pair is displayed.
101
103
:::image type="content" source="media/workspace-manager/publish-groups-job-details.png" alt-text="Screenshot shows the job details of a group publishing failure event." lightbox="media/workspace-manager/publish-groups-job-details.png":::
102
104
103
105
Common reasons for failure include:
104
-
- Content items referenced in the Group definition no longer exist at the time of Publish (have been deleted).
105
-
- Permissions have changed at the time of Publish. For example, the user is no longer a Microsoft Sentinel Contributor or doesn't have sufficient permissions on the member workspace anymore.
106
+
- Content items referenced in the group definition no longer exist at the time of publish (have been deleted).
107
+
- Permissions have changed at the time of publish. For example, the user is no longer a Microsoft Sentinel Contributor or doesn't have sufficient permissions on the member workspace anymore.
106
108
- A member workspace has been deleted.
107
109
108
110
### Known limitations
109
-
- Playbooks attributed or attached to Analytics and Automation rules are not currently supported.
111
+
- Playbooks attributed or attached to analytics and automation rules aren't currently supported.
110
112
- Workbooks stored in bring-your-own-storage aren't currently supported.
111
-
- Workspace Manager only manages content items published from the central workspace. It doesn't manage content created locally from member workspace(s).
112
-
- Currently, deleting content residing in member workspace(s) centrally via Workspace Manager isn't supported.
113
+
- Workspace manager only manages content items published from the central workspace. It doesn't manage content created locally from member workspace(s).
114
+
- Currently, deleting content residing in member workspace(s) centrally via workspace manager isn't supported.
0 commit comments