Skip to content

Commit d541fef

Browse files
committed
Cloud feature availability page for Sentinel
1 parent 3985a12 commit d541fef

File tree

3 files changed

+187
-0
lines changed

3 files changed

+187
-0
lines changed

articles/reliability/sovereign-cloud-china.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -61,6 +61,14 @@ This section outlines variations and considerations when using Networking servic
6161
|---------|--------|------------|
6262
| Private Link| <li>For Private Link services availability, see [Azure Private Link availability](../private-link/availability.md).<li>For Private DNS zone names, see [Azure Private Endpoint DNS configuration](../private-link/private-endpoint-dns.md#government). |
6363

64+
### Security
65+
66+
This section outlines variations and considerations when using Security services.
67+
68+
| Product | Unsupported, limited, and/or modified features | Notes |
69+
|---------|--------|------------|
70+
| Microsoft Sentinel| For Microsoft Sentinel availability, see [Microsoft Sentinel availability](../sentinel/feature-availability.md). |
71+
6472
### Azure Container Apps
6573

6674
This section outlines variations and considerations when using Azure Container Apps services.

articles/sentinel/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1146,6 +1146,8 @@
11461146
href: https://azure.microsoft.com/global-infrastructure/services/?products=azure-sentinel
11471147
- name: Pricing
11481148
href: https://azure.microsoft.com/pricing/details/azure-sentinel/
1149+
- name: Feature availability
1150+
href: feature-availability.md
11491151
- name: Feature availability for US Government clouds
11501152
href: ../security/fundamentals/feature-availability.md
11511153
- name: Build your skills for Microsoft Sentinel
Lines changed: 177 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,177 @@
1+
---
2+
title: Cloud feature availability in Microsoft Sentinel
3+
description: This article describes feature availability in Microsoft Sentinel across different Azure environments.
4+
author: limwainstein
5+
ms.author: lwainstein
6+
ms.topic: feature-availability
7+
ms.custom: references_regions
8+
ms.date: 02/02/2023
9+
---
10+
11+
# Cloud feature availability in Microsoft Sentinel
12+
13+
This article describes feature availability in Microsoft Sentinel across different Azure environments.
14+
15+
## Incidents
16+
17+
|Feature |Azure commercial |Azure China 21Vianet |
18+
|---------|---------|---------|
19+
|[Automation rules](automate-incident-handling-with-automation-rules.md) |Public Preview |&#x2705; |
20+
|[Cross-tenant/Cross-workspace incidents view](multiple-workspace-view.md) |GA |&#x2705; |
21+
|[SOC incident audit metrics](manage-soc-with-incident-metrics.md) |GA |&#x2705; |
22+
|[Incident advanced search](investigate-cases.md#search-for-incidents) |GA |&#x2705; |
23+
|[Microsoft 365 Defender incident integration](microsoft-365-defender-sentinel-integration.md#working-with-microsoft-365-defender-incidents-in-microsoft-sentinel-and-bi-directional-sync) |Public Preview |&#10060; |
24+
|[Microsoft Teams integrations](collaborate-in-microsoft-teams.md) |Public Preview |&#10060; |
25+
|[Run playbooks on incidents](automate-responses-with-playbooks.md) |Public Preview |&#x2705; |
26+
|[Run playbooks on entities](respond-threats-during-investigation.md) |Public Preview |&#10060; |
27+
|[Playbook template gallery](use-playbook-templates.md) |Public Preview |&#10060; |
28+
|[Automation rules health](monitor-automation-health.md) |Public Preview |&#10060; |
29+
|[Incident tasks](incident-tasks.md) |Public Preview |&#10060; |
30+
|[Advanced and/or conditions](add-advanced-conditions-to-automation-rules.md) |Public Preview |&#10060; |
31+
|[Create incidents manually](create-incident-manually.md) |Public Preview |&#10060; |
32+
|[Add entities to threat intelligence](add-entity-to-threat-intelligence.md?tabs=incidents) |Public Preview |&#10060; |
33+
34+
## Analytics
35+
36+
|Feature |Azure commercial |Azure China 21Vianet |
37+
|---------|---------|---------|
38+
|[Scheduled](detect-threats-built-in.md) and [Microsoft rules](create-incidents-from-alerts.md) |GA |&#x2705; |
39+
|[NRT rules](near-real-time-rules.md) |Public Preview |&#x2705; |
40+
|[MITRE ATT&CK dashboard](mitre-coverage.md) |Public Preview |&#10060; |
41+
|[Recommendations](detection-tuning.md) |Public Preview |&#10060; |
42+
|[Analytics rules health](monitor-analytics-rule-integrity.md) |Public Preview |&#10060; |
43+
44+
## Notebooks
45+
46+
|Feature |Azure commercial |Azure China 21Vianet |
47+
|---------|---------|---------|
48+
|[Notebooks](notebooks.md) |GA |&#x2705; |
49+
|[Notebook integration with Azure Synapse](notebooks-with-synapse.md) |Public Preview |&#x2705; |
50+
51+
## Watchlists
52+
53+
|Feature |Azure commercial |Azure China 21Vianet |
54+
|---------|---------|---------|
55+
|[Watchlists](watchlists.md) |GA |&#x2705; |
56+
|[Large watchlists from Azure Storage](watchlists.md) |Public Preview |&#10060; |
57+
|[Watchlist templates](watchlist-schemas.md) |Public Preview |&#10060; |
58+
59+
## Hunting
60+
61+
|Feature |Azure commercial |Azure China 21Vianet |
62+
|---------|---------|---------|
63+
|[Hunting blade](hunting.md) |GA |&#x2705; |
64+
|[Search large datasets](search-jobs.md) |GA |&#x2705; |
65+
|[Restore historical data](restore.md) |GA |&#x2705; |
66+
67+
## Content and content management
68+
69+
|Feature |Azure commercial |Azure China 21Vianet |
70+
|---------|---------|---------|
71+
|[Content hub](sentinel-solutions.md) and [solutions](sentinel-solutions-catalog.md) |Public preview |&#10060; |
72+
|[Repositories](ci-cd.md?tabs=github) |Public preview |&#10060; |
73+
|[Workbooks](monitor-your-data.md) |GA |&#x2705; |
74+
75+
## SAP
76+
77+
|Feature |Azure commercial |Azure China 21Vianet |
78+
|---------|---------|---------|
79+
|[Threat protection for SAP](sap/deployment-overview.md)<sup>[1](#sap)</sup> |GA |&#x2705; |
80+
|[Threat protection for SAP Business Technology Platform (BTP)](sap/deploy-sap-btp-solution.md) |Public Preview |&#10060; |
81+
82+
<sup><a name="sap"></a>1</sup> Deploy SAP security content [via GitHub](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/SAP).
83+
84+
## Normalization
85+
86+
|Feature |Azure commercial |Azure China 21Vianet |
87+
|---------|---------|---------|
88+
|[Advanced SIEM Information Model (ASIM)](normalization.md) |Public Preview |&#x2705; |
89+
90+
## UEBA
91+
92+
|Feature |Azure commercial |Azure China 21Vianet |
93+
|---------|---------|---------|
94+
|[Entity insights](identify-threats-with-entity-behavior-analytics.md) |GA |&#x2705; |
95+
|[Identity info table data ingestion](investigate-with-ueba.md) |GA |&#x2705; |
96+
|[UEBA enrichments\insights](investigate-with-ueba.md) |GA |&#x2705; |
97+
|[Entity pages](entity-pages.md) |GA |&#x2705; |
98+
|[Azure resource entity pages](entity-pages.md) |Public Preview |&#10060; |
99+
|[IoT device entity page](/azure/defender-for-iot/organizations/iot-advanced-threat-monitoring#investigate-further-with-iot-device-entities) |Public Preview |&#10060; |
100+
|[UEBA anomalies](soc-ml-anomalies.md#ueba-anomalies) |GA |&#10060; |
101+
|[SOC-ML anomalies](soc-ml-anomalies.md#what-are-customizable-anomalies) |GA |&#10060; |
102+
|[Peer/Blast radius enrichments](identify-threats-with-entity-behavior-analytics.md#what-is-user-and-entity-behavior-analytics-ueba) |Public preview |&#10060; |
103+
|[Active Directory sync via MDI](enable-entity-behavior-analytics.md#how-to-enable-user-and-entity-behavior-analytics) |Public preview |&#10060; |
104+
105+
## Threat intelligence support
106+
107+
|Feature |Azure commercial |Azure China 21Vianet |
108+
|---------|---------|---------|
109+
|[Threat Intelligence - TAXII data connector](understand-threat-intelligence.md) |GA |&#x2705; |
110+
|[Threat Intelligence Platform data connector](understand-threat-intelligence.md) |Public Preview |&#x2705; |
111+
|[Threat Intelligence Research blade](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/what-s-new-threat-intelligence-menu-item-in-public-preview/ba-p/1646597) |GA |&#x2705; |
112+
|[URL detonation](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/using-the-new-built-in-url-detonation-in-azure-sentinel/ba-p/996229) |Public Preview |&#10060; |
113+
|[Threat Intelligence workbook](/azure/architecture/example-scenario/data/sentinel-threat-intelligence) |GA |&#x2705; |
114+
|[GeoLocation and WhoIs data enrichment](work-with-threat-indicators.md) |Public Preview |&#10060; |
115+
|[Threat intelligence matching analytics](use-matching-analytics-to-detect-threats.md) |Public Preview |&#10060; |
116+
|[Import TI from flat file](indicators-bulk-file-import.md) |Public Preview |&#x2705; |
117+
118+
## Machine Learning
119+
120+
|Feature |Azure commercial |Azure China 21Vianet |
121+
|---------|---------|---------|
122+
|[Fusion](fusion.md) - advanced multistage attack detections <sup>[1](#partialga)</sup> |GA |&#x2705; |
123+
|[Fusion detection for ransomware](fusion.md#fusion-for-ransomware) |Public Preview |&#x2705; |
124+
|[Fusion for emerging threats](fusion.md#fusion-for-emerging-threats) |Public Preview |&#x2705; |
125+
|[Anomalous RDP login detection - built-in ML detection](configure-connector-login-detection.md) |Public Preview |&#10060; |
126+
|[Anomalous SSH login detection - built-in ML detection](connect-syslog.md#configure-the-syslog-connector-for-anomalous-ssh-login-detection) |Public Preview |&#10060; |
127+
|[Bring Your Own ML (BYO-ML)](bring-your-own-ml.md) |Public Preview |&#10060; |
128+
129+
<sup><a name="partialga"></a>1</sup> Partially GA: The ability to disable specific findings from vulnerability scans is in public preview.
130+
131+
## Data collection
132+
133+
|Feature |Azure commercial |Azure China 21Vianet |
134+
|---------|---------|---------|
135+
|[Azure Activity](data-connectors/azure-activity.md) |GA |&#x2705; |
136+
|[Azure Active Directory](connect-azure-active-directory.md) |GA |&#x2705; <sup>[1](#logsavailable)</sup> |
137+
|[Azure Active Directory Identity Protection](connect-services-api-based.md) |GA |&#10060; |
138+
|[Azure DDoS Protection](connect-services-diagnostic-setting-based.md) |GA |&#10060; |
139+
|[Microsoft 365 Defender](connect-microsoft-365-defender.md?tabs=MDE) |GA |&#10060; |
140+
|[Microsoft Purview (Preview)](connect-services-diagnostic-setting-based.md) |Public Preview |&#10060; |
141+
|[Microsoft Defender for Cloud](connect-defender-for-cloud.md) |GA |&#x2705; |
142+
|[Microsoft Defender for IoT](connect-services-api-based.md) |GA |&#10060; |
143+
|[Microsoft 365 Insider Risk Management (Preview)](sentinel-solutions-catalog.md#domain-solutions) |Public Preview |&#10060; |
144+
|[Azure Firewall](data-connectors/azure-firewall.md) |GA |&#x2705; |
145+
|[Azure Information Protection (Preview)](data-connectors/azure-information-protection.md) |Deprecated |&#10060; |
146+
|[Microsoft Purview Information Protection](connect-microsoft-purview.md) |Public Preview |&#10060; |
147+
|[Azure Key Vault](data-connectors/azure-key-vault.md) |Public Preview |&#x2705; |
148+
|[Azure Kubernetes Service (AKS)](data-connectors/azure-kubernetes-service-aks.md) |Public Preview |&#x2705; |
149+
|Azure SQL Databases |GA |&#x2705; |
150+
|[Azure Web Application Firewall (WAF)](data-connectors/azure-web-application-firewall-waf.md) |GA |&#x2705; |
151+
|[Windows Firewall](data-connectors/windows-firewall.md) |GA |&#x2705; |
152+
|[Security Events via Legacy Agent](connect-services-windows-based.md#log-analytics-agent-legacy) |GA |&#x2705; |
153+
|[Windows Security Events via AMA](connect-services-windows-based.md) |GA |&#x2705; |
154+
|[Windows Forwarded Events (Preview)](connect-services-windows-based.md) |Public Preview |&#x2705; |
155+
|[Common Event Format (CEF) via AMA (Preview)](connect-cef-ama.md) |Public Preview |&#x2705; |
156+
|[Windows DNS Events via AMA (Preview)](connect-dns-ama.md) |Public Preview |&#10060; |
157+
|[DNS](data-connectors/dns.md) |Public Preview |&#x2705; |
158+
|[Office 365](connect-services-api-based.md) |GA |&#x2705; |
159+
|[Microsoft Project (Preview)](data-connectors/microsoft-project.md) |Public Preview |&#10060; |
160+
|[Microsoft PowerBI (Preview)](data-connectors/microsoft-powerbi.md) |Public Preview |&#10060; |
161+
|[Common Event Format (CEF)](connect-common-event-format.md) |GA |&#x2705; |
162+
|[Cisco ASA](data-connectors/cisco-asa.md) |GA |&#x2705; |
163+
|[Syslog](connect-syslog.md) |GA |&#x2705; |
164+
|[Amazon Web Services](connect-aws.md?tabs=ct) |GA |&#10060; |
165+
|[Amazon Web Services S3 (Preview)](connect-aws.md?tabs=s3) |Public Preview |&#10060; |
166+
|[GCP Pub/Sub Audit Logs](connect-google-cloud-platform.md) |Public Preview |&#10060; |
167+
|[Codeless Connectors Platform](create-codeless-connector.md?tabs=deploy-via-arm-template%2Cconnect-via-the-azure-portal) |Public Preview |&#10060; |
168+
|[Data Connectors health](monitor-data-connector-health.md#use-the-sentinelhealth-data-table-public-preview) |Public Preview |&#10060; |
169+
170+
<sup><a name="logsavailable"></a>1</sup> Supports only sign-in logs and audit logs.
171+
172+
## Next steps
173+
174+
In this article, you learned about available features in Microsoft Sentinel.
175+
176+
- [Learn about Microsoft Sentinel](overview.md)
177+
- [Plan your Microsoft Sentinel architecture](design-your-workspace-architecture.md)

0 commit comments

Comments
 (0)