Skip to content

Commit e02bb38

Browse files
committed
added note on subscription and and resource group
1 parent 842ffd4 commit e02bb38

File tree

1 file changed

+5
-2
lines changed

1 file changed

+5
-2
lines changed

articles/sentinel/datalake/sentinel-lake-onboarding.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ ms.subservice: sentinel-graph
1515
# Onboarding to Microsoft Sentinel data lake (preview)
1616

1717

18-
The Microsoft Sentinel data lake, available in the Microsoft Defender portal, is a tenant-wide, repository for collecting, storing, and managing large volumes of security-related data from various sources. It enables comprehensive, unified analysis and visibility across your security landscape. By leveraging advanced analytics, machine learning, and artificial intelligence, the data lake helps in detecting threats, investigating and responding to incidents, and improving overall security posture.
18+
The Microsoft Sentinel data lake, available in the Microsoft Defender portal, is a tenant-wide, repository for collecting, storing, and managing large volumes of security-related data from various sources. It enables comprehensive, unified analysis and visibility across your security landscape. By using advanced analytics, machine learning, and artificial intelligence, the data lake helps in detecting threats, investigating, and responding to incidents, and improving overall security posture.
1919

2020
For more information, see [What is Microsoft Sentinel data lake (preview)](sentinel-lake-overview.md).
2121

@@ -58,7 +58,7 @@ This article describes how to onboard to the Microsoft Sentinel data lake for cu
5858

5959
To onboard to the Microsoft Sentinel data lake Public Preview, you must be an existing Microsoft Defender and Microsoft Sentinel customer with the following prerequisites:
6060

61-
+ You must have Microsoft Defender (security.microsoft.com) and Microsoft Sentinel to onboard the data lake. A Microsoft Defender XDR license is not required to use Microsoft Sentinel data lake with Microsoft Sentinel in the Microsoft Defender portal.
61+
+ You must have Microsoft Defender (security.microsoft.com) and Microsoft Sentinel to onboard the data lake. A Microsoft Defender XDR license isn't required to use Microsoft Sentinel data lake with Microsoft Sentinel in the Microsoft Defender portal.
6262

6363
+ You must have existing Azure subscription and resource group to set up billing for the data lake. You must be the subscription owner. You can use your existing Microsoft Sentinel SIEM Azure subscription and resource group or create a new one.
6464
+ You must have a Microsoft Sentinel primary workspace connected to Microsoft Defender portal.
@@ -109,6 +109,9 @@ Use the following steps to onboard to the Microsoft Sentinel data lake from the
109109

110110
1. If you have the required permissions, a setup side panel appears. Select the **Subscription** and **Resource group** to enable billing for the Microsoft Sentinel data lake.
111111

112+
> [!NOTE]
113+
> After the data lake is provisioned for a specific Azure subscription and resource group, it can't be migrated to a different subscription or resource group.
114+
112115
1. Select **Set up data lake**.
113116

114117
:::image type="content" source="./media/sentinel-lake-onboarding/set-up-data-lake.png" lightbox="./media/sentinel-lake-onboarding/set-up-data-lake.png" alt-text="A screenshot showing the setup page for the Microsoft Sentinel data lake.":::

0 commit comments

Comments
 (0)