Skip to content

Commit face379

Browse files
authored
Merge pull request #235358 from limwainstein/cloud-feature-availability-sentinel
Cloud feature availability page for Sentinel
2 parents ba43100 + 45b7f4c commit face379

File tree

3 files changed

+188
-2
lines changed

3 files changed

+188
-2
lines changed

articles/reliability/sovereign-cloud-china.md

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ This section outlines variations and considerations when using Azure Bot Service
2525

2626
| Product | Unsupported, limited, and/or modified features | Notes |
2727
|---------|--------|------------|
28-
|Azure Machine learning| See [Azure Machine Learning feature availability across Azure in China cloud regions](../machine-learning/reference-machine-learning-cloud-parity.md#azure-china-21vianet). | |
28+
|Azure Machine Learning| See [Azure Machine Learning feature availability across Azure in China cloud regions](../machine-learning/reference-machine-learning-cloud-parity.md#azure-china-21vianet). | |
2929
| Cognitive Services: Speech| See [Cognitive Services: Azure in China - Speech service](../cognitive-services/speech-service/sovereign-clouds.md?tabs=c-sharp.md#azure-china) ||
3030
| Cognitive Services: Speech|For feature variations and limitations, including API endpoints, see [Translator in sovereign clouds](../cognitive-services/translator/sovereign-clouds.md?tabs=china).|
3131

@@ -61,6 +61,14 @@ This section outlines variations and considerations when using Networking servic
6161
|---------|--------|------------|
6262
| Private Link| <li>For Private Link services availability, see [Azure Private Link availability](../private-link/availability.md).<li>For Private DNS zone names, see [Azure Private Endpoint DNS configuration](../private-link/private-endpoint-dns.md#government). |
6363

64+
### Security
65+
66+
This section outlines variations and considerations when using Security services.
67+
68+
| Product | Unsupported, limited, and/or modified features | Notes |
69+
|---------|--------|------------|
70+
| Microsoft Sentinel| For Microsoft Sentinel availability, see [Microsoft Sentinel availability](../sentinel/feature-availability.md). |
71+
6472
### Azure Container Apps
6573

6674
This section outlines variations and considerations when using Azure Container Apps services.
@@ -106,7 +114,7 @@ For IP rangers for Azure in China, download [Azure Datacenter IP Ranges in China
106114
| Azure Bot Services | <\*.botframework.com> | <\*.botframework.azure.cn> |
107115
| Azure Key Vault API | \*.vault.azure.net | \*.vault.azure.cn |
108116
| Sign in with PowerShell: <br>- Azure classic portal <br>- Azure Resource Manager <br>- Azure AD| - Add-AzureAccount<br>- Connect-AzureRmAccount <br> - Connect-msolservice |  - Add-AzureAccount -Environment AzureChinaCloud <br> - Connect-AzureRmAccount -Environment AzureChinaCloud <br>- Connect-msolservice -AzureEnvironment AzureChinaCloud |
109-
| Azure Container Apps Default Domain | \*.azurecontainerapps.io | No default domain is provided for external enviromment. The [custom domain](/azure/container-apps/custom-domains-certificates) is required. |
117+
| Azure Container Apps Default Domain | \*.azurecontainerapps.io | No default domain is provided for external environment. The [custom domain](/azure/container-apps/custom-domains-certificates) is required. |
110118
| Azure Container Apps Event Stream Endpoint | \<region\>.azurecontainerapps.dev | \<region\>.chinanorth3.azurecontainerapps-dev.cn |
111119

112120
### Application Insights

articles/sentinel/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1148,6 +1148,8 @@
11481148
href: https://azure.microsoft.com/global-infrastructure/services/?products=azure-sentinel
11491149
- name: Pricing
11501150
href: https://azure.microsoft.com/pricing/details/azure-sentinel/
1151+
- name: Feature availability
1152+
href: feature-availability.md
11511153
- name: Feature availability for US Government clouds
11521154
href: ../security/fundamentals/feature-availability.md
11531155
- name: Build your skills for Microsoft Sentinel
Lines changed: 176 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,176 @@
1+
---
2+
title: Cloud feature availability in Microsoft Sentinel
3+
description: This article describes feature availability in Microsoft Sentinel across different Azure environments.
4+
author: limwainstein
5+
ms.author: lwainstein
6+
ms.topic: feature-availability
7+
ms.custom: references_regions
8+
ms.date: 02/02/2023
9+
---
10+
11+
# Cloud feature availability in Microsoft Sentinel
12+
13+
This article describes feature availability in Microsoft Sentinel across different Azure environments.
14+
15+
## Analytics
16+
17+
|Feature |Azure commercial |Azure China 21Vianet |
18+
|---------|---------|---------|
19+
|[Analytics rules health](monitor-analytics-rule-integrity.md) |Public Preview |&#10060; |
20+
|[MITRE ATT&CK dashboard](mitre-coverage.md) |Public Preview |&#10060; |
21+
|[NRT rules](near-real-time-rules.md) |Public Preview |&#x2705; |
22+
|[Recommendations](detection-tuning.md) |Public Preview |&#10060; |
23+
|[Scheduled](detect-threats-built-in.md) and [Microsoft rules](create-incidents-from-alerts.md) |GA |&#x2705; |
24+
25+
## Content and content management
26+
27+
|Feature |Azure commercial |Azure China 21Vianet |
28+
|---------|---------|---------|
29+
|[Content hub](sentinel-solutions.md) and [solutions](sentinel-solutions-catalog.md) |Public preview |&#10060; |
30+
|[Repositories](ci-cd.md?tabs=github) |Public preview |&#10060; |
31+
|[Workbooks](monitor-your-data.md) |GA |&#x2705; |
32+
33+
## Data collection
34+
35+
|Feature |Azure commercial |Azure China 21Vianet |
36+
|---------|---------|---------|
37+
|[Amazon Web Services](connect-aws.md?tabs=ct) |GA |&#10060; |
38+
|[Amazon Web Services S3 (Preview)](connect-aws.md?tabs=s3) |Public Preview |&#10060; |
39+
|[Azure Active Directory](connect-azure-active-directory.md) |GA |&#x2705; <sup>[1](#logsavailable)</sup> |
40+
|[Azure Active Directory Identity Protection](connect-services-api-based.md) |GA |&#10060; |
41+
|[Azure Activity](data-connectors/azure-activity.md) |GA |&#x2705; |
42+
|[Azure DDoS Protection](connect-services-diagnostic-setting-based.md) |GA |&#10060; |
43+
|[Azure Firewall](data-connectors/azure-firewall.md) |GA |&#x2705; |
44+
|[Azure Information Protection (Preview)](data-connectors/azure-information-protection.md) |Deprecated |&#10060; |
45+
|[Azure Key Vault](data-connectors/azure-key-vault.md) |Public Preview |&#x2705; |
46+
|[Azure Kubernetes Service (AKS)](data-connectors/azure-kubernetes-service-aks.md) |Public Preview |&#x2705; |
47+
|[Azure SQL Databases](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/azure-sentinel-sql-solution-query-deep-dive/ba-p/2597961) |GA |&#x2705; |
48+
|[Azure Web Application Firewall (WAF)](data-connectors/azure-web-application-firewall-waf.md) |GA |&#x2705; |
49+
|[Cisco ASA](data-connectors/cisco-asa.md) |GA |&#x2705; |
50+
|[Codeless Connectors Platform](create-codeless-connector.md?tabs=deploy-via-arm-template%2Cconnect-via-the-azure-portal) |Public Preview |&#10060; |
51+
|[Common Event Format (CEF)](connect-common-event-format.md) |GA |&#x2705; |
52+
|[Common Event Format (CEF) via AMA (Preview)](connect-cef-ama.md) |Public Preview |&#x2705; |
53+
|[Data Connectors health](monitor-data-connector-health.md#use-the-sentinelhealth-data-table-public-preview) |Public Preview |&#10060; |
54+
|[DNS](data-connectors/dns.md) |Public Preview |&#x2705; |
55+
|[GCP Pub/Sub Audit Logs](connect-google-cloud-platform.md) |Public Preview |&#10060; |
56+
|[Microsoft 365 Defender](connect-microsoft-365-defender.md?tabs=MDE) |GA |&#10060; |
57+
|[Microsoft Purview Insider Risk Management (Preview)](sentinel-solutions-catalog.md#domain-solutions) |Public Preview |&#10060; |
58+
|[Microsoft Defender for Cloud](connect-defender-for-cloud.md) |GA |&#x2705; |
59+
|[Microsoft Defender for IoT](connect-services-api-based.md) |GA |&#10060; |
60+
|[Microsoft Power BI (Preview)](data-connectors/microsoft-powerbi.md) |Public Preview |&#10060; |
61+
|[Microsoft Project (Preview)](data-connectors/microsoft-project.md) |Public Preview |&#10060; |
62+
|[Microsoft Purview (Preview)](connect-services-diagnostic-setting-based.md) |Public Preview |&#10060; |
63+
|[Microsoft Purview Information Protection](connect-microsoft-purview.md) |Public Preview |&#10060; |
64+
|[Office 365](connect-services-api-based.md) |GA |&#x2705; |
65+
|[Security Events via Legacy Agent](connect-services-windows-based.md#log-analytics-agent-legacy) |GA |&#x2705; |
66+
|[Syslog](connect-syslog.md) |GA |&#x2705; |
67+
|[Windows DNS Events via AMA (Preview)](connect-dns-ama.md) |Public Preview |&#10060; |
68+
|[Windows Firewall](data-connectors/windows-firewall.md) |GA |&#x2705; |
69+
|[Windows Forwarded Events (Preview)](connect-services-windows-based.md) |Public Preview |&#x2705; |
70+
|[Windows Security Events via AMA](connect-services-windows-based.md) |GA |&#x2705; |
71+
72+
<sup><a name="logsavailable"></a>1</sup> Supports only sign-in logs and audit logs.
73+
74+
## Hunting
75+
76+
|Feature |Azure commercial |Azure China 21Vianet |
77+
|---------|---------|---------|
78+
|[Hunting blade](hunting.md) |GA |&#x2705; |
79+
|[Restore historical data](restore.md) |GA |&#x2705; |
80+
|[Search large datasets](search-jobs.md) |GA |&#x2705; |
81+
82+
## Incidents
83+
84+
|Feature |Azure commercial |Azure China 21Vianet |
85+
|---------|---------|---------|
86+
|[Add entities to threat intelligence](add-entity-to-threat-intelligence.md?tabs=incidents) |Public Preview |&#10060; |
87+
|[Advanced and/or conditions](add-advanced-conditions-to-automation-rules.md) |Public Preview |&#x2705; |
88+
|[Automation rules](automate-incident-handling-with-automation-rules.md) |Public Preview |&#x2705; |
89+
|[Automation rules health](monitor-automation-health.md) |Public Preview |&#10060; |
90+
|[Create incidents manually](create-incident-manually.md) |Public Preview |&#x2705; |
91+
|[Cross-tenant/Cross-workspace incidents view](multiple-workspace-view.md) |GA |&#x2705; |
92+
|[Incident advanced search](investigate-cases.md#search-for-incidents) |GA |&#x2705; |
93+
|[Incident tasks](incident-tasks.md) |Public Preview |&#x2705; |
94+
|[Microsoft 365 Defender incident integration](microsoft-365-defender-sentinel-integration.md#working-with-microsoft-365-defender-incidents-in-microsoft-sentinel-and-bi-directional-sync) |Public Preview |&#10060; |
95+
|[Microsoft Teams integrations](collaborate-in-microsoft-teams.md) |Public Preview |&#10060; |
96+
|[Playbook template gallery](use-playbook-templates.md) |Public Preview |&#10060; |
97+
|[Run playbooks on entities](respond-threats-during-investigation.md) |Public Preview |&#10060; |
98+
|[Run playbooks on incidents](automate-responses-with-playbooks.md) |Public Preview |&#x2705; |
99+
|[SOC incident audit metrics](manage-soc-with-incident-metrics.md) |GA |&#x2705; |
100+
101+
## Machine Learning
102+
103+
|Feature |Azure commercial |Azure China 21Vianet |
104+
|---------|---------|---------|
105+
|[Anomalous RDP login detection - built-in ML detection](configure-connector-login-detection.md) |Public Preview |&#x2705; |
106+
|[Anomalous SSH login detection - built-in ML detection](connect-syslog.md#configure-the-syslog-connector-for-anomalous-ssh-login-detection) |Public Preview |&#x2705; |
107+
|[Bring Your Own ML (BYO-ML)](bring-your-own-ml.md) |Public Preview |&#10060; |
108+
|[Fusion](fusion.md) - advanced multistage attack detections <sup>[1](#partialga)</sup> |GA |&#x2705; |
109+
|[Fusion detection for ransomware](fusion.md#fusion-for-ransomware) |Public Preview |&#x2705; |
110+
|[Fusion for emerging threats](fusion.md#fusion-for-emerging-threats) |Public Preview |&#x2705; |
111+
112+
<sup><a name="partialga"></a>1</sup> Partially GA: The ability to disable specific findings from vulnerability scans is in public preview.
113+
114+
## Normalization
115+
116+
|Feature |Azure commercial |Azure China 21Vianet |
117+
|---------|---------|---------|
118+
|[Advanced Security Information Model (ASIM)](normalization.md) |Public Preview |&#x2705; |
119+
120+
## Notebooks
121+
122+
|Feature |Azure commercial |Azure China 21Vianet |
123+
|---------|---------|---------|
124+
|[Notebooks](notebooks.md) |GA |&#x2705; |
125+
|[Notebook integration with Azure Synapse](notebooks-with-synapse.md) |Public Preview |&#x2705; |
126+
127+
## SAP
128+
129+
|Feature |Azure commercial |Azure China 21Vianet |
130+
|---------|---------|---------|
131+
|[Threat protection for SAP](sap/deployment-overview.md)<sup>[1](#sap)</sup> |GA |&#x2705; |
132+
133+
<sup><a name="sap"></a>1</sup> Deploy SAP security content [via GitHub](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/SAP).
134+
135+
## Threat intelligence support
136+
137+
|Feature |Azure commercial |Azure China 21Vianet |
138+
|---------|---------|---------|
139+
|[GeoLocation and WhoIs data enrichment](work-with-threat-indicators.md) |Public Preview |&#10060; |
140+
|[Import TI from flat file](indicators-bulk-file-import.md) |Public Preview |&#x2705; |
141+
|[Threat intelligence matching analytics](use-matching-analytics-to-detect-threats.md) |Public Preview |&#10060; |
142+
|[Threat Intelligence Platform data connector](understand-threat-intelligence.md) |Public Preview |&#x2705; |
143+
|[Threat Intelligence Research blade](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/what-s-new-threat-intelligence-menu-item-in-public-preview/ba-p/1646597) |GA |&#x2705; |
144+
|[Threat Intelligence - TAXII data connector](understand-threat-intelligence.md) |GA |&#x2705; |
145+
|[Threat Intelligence workbook](/azure/architecture/example-scenario/data/sentinel-threat-intelligence) |GA |&#x2705; |
146+
|[URL detonation](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/using-the-new-built-in-url-detonation-in-azure-sentinel/ba-p/996229) |Public Preview |&#10060; |
147+
148+
## UEBA
149+
150+
|Feature |Azure commercial |Azure China 21Vianet |
151+
|---------|---------|---------|
152+
|[Active Directory sync via MDI](enable-entity-behavior-analytics.md#how-to-enable-user-and-entity-behavior-analytics) |Public preview |&#10060; |
153+
|[Azure resource entity pages](entity-pages.md) |Public Preview |&#10060; |
154+
|[Entity insights](identify-threats-with-entity-behavior-analytics.md) |GA |&#x2705; |
155+
|[Entity pages](entity-pages.md) |GA |&#x2705; |
156+
|[Identity info table data ingestion](investigate-with-ueba.md) |GA |&#x2705; |
157+
|[IoT device entity page](/azure/defender-for-iot/organizations/iot-advanced-threat-monitoring#investigate-further-with-iot-device-entities) |Public Preview |&#10060; |
158+
|[Peer/Blast radius enrichments](identify-threats-with-entity-behavior-analytics.md#what-is-user-and-entity-behavior-analytics-ueba) |Public preview |&#10060; |
159+
|[SOC-ML anomalies](soc-ml-anomalies.md#what-are-customizable-anomalies) |GA |&#10060; |
160+
|[UEBA anomalies](soc-ml-anomalies.md#ueba-anomalies) |GA |&#10060; |
161+
|[UEBA enrichments\insights](investigate-with-ueba.md) |GA |&#x2705; |
162+
163+
## Watchlists
164+
165+
|Feature |Azure commercial |Azure China 21Vianet |
166+
|---------|---------|---------|
167+
|[Large watchlists from Azure Storage](watchlists.md) |Public Preview |&#10060; |
168+
|[Watchlists](watchlists.md) |GA |&#x2705; |
169+
|[Watchlist templates](watchlist-schemas.md) |Public Preview |&#10060; |
170+
171+
## Next steps
172+
173+
In this article, you learned about available features in Microsoft Sentinel.
174+
175+
- [Learn about Microsoft Sentinel](overview.md)
176+
- [Plan your Microsoft Sentinel architecture](design-your-workspace-architecture.md)

0 commit comments

Comments
 (0)