Skip to content

Commit 24d4ef2

Browse files
committed
workspaces to ga
1 parent ee49073 commit 24d4ef2

File tree

6 files changed

+20
-10
lines changed

6 files changed

+20
-10
lines changed

unified-secops-platform/microsoft-sentinel-onboard.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ Before you begin, review the feature documentation to understand the product cha
4646
- [Alerts, incidents, and correlation in Microsoft Defender XDR](/defender-xdr/alerts-incidents-correlation)
4747
- [Automation with the unified security operations platform](/azure/sentinel/automation#automation-with-the-unified-security-operations-platform)
4848

49-
The Microsoft Defender portal supports a single Microsoft Entra tenant and the connection to a primary workspace and multiple secondary workspaces (preview). If you have only one workspace when you onboard Microsoft Sentinel, that workspace is designated as the primary workspace. For more information, see [Multiple Microsoft Sentinel workspaces in the Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2310579). In the context of this article, a workspace is a Log Analytics workspace with Microsoft Sentinel enabled.
49+
The Microsoft Defender portal supports a single Microsoft Entra tenant and the connection to a primary workspace and multiple secondary workspaces. If you have only one workspace when you onboard Microsoft Sentinel, that workspace is designated as the primary workspace. For more information, see [Multiple Microsoft Sentinel workspaces in the Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2310579). In the context of this article, a workspace is a Log Analytics workspace with Microsoft Sentinel enabled.
5050

5151
### Microsoft Sentinel prerequisites
5252

@@ -110,7 +110,7 @@ After your workspace is connected, the banner on the **Overview** page shows tha
110110

111111
## Explore Microsoft Sentinel features in the Defender portal
112112

113-
After you connect your workspace to the Defender portal, **Microsoft Sentinel** is on the left-hand side navigation pane. If you have Defender XDR enabled, pages like **Overview**, **Incidents**, and **Advanced Hunting** have unified data from the primary workspace for Microsoft Sentinel and Defender XDR. If you don't have Defender XDR enabled, these pages just include data from Microsoft Sentinel (preview). For more information about the unified capabilities and differences between portals, see [Microsoft Sentinel in the Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2263690).
113+
After you connect your workspace to the Defender portal, **Microsoft Sentinel** is on the left-hand side navigation pane. If you have Defender XDR enabled, pages like **Overview**, **Incidents**, and **Advanced Hunting** have unified data from the primary workspace for Microsoft Sentinel and Defender XDR. If you don't have Defender XDR enabled, these pages just include data from Microsoft Sentinel. For more information about the unified capabilities and differences between portals, see [Microsoft Sentinel in the Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2263690).
114114

115115
Many of the existing Microsoft Sentinel features are integrated into the Defender portal. For these features, notice that the experience between Microsoft Sentinel in the Azure portal and Defender portal are similar. Use the following articles to help you start working with Microsoft Sentinel in the Defender portal. When using these articles, keep in mind that your starting point in this context is the [Defender portal](https://security.microsoft.com/) instead of the Azure portal.
116116

unified-secops-platform/mto-advanced-hunting.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -24,8 +24,6 @@ appliesto:
2424

2525
Advanced hunting in Microsoft Defender multi-tenant management allows you to proactively hunt for intrusion attempts and breach activity in email, data, devices, and accounts across multiple tenants and workspaces at the same time. If you have multiple tenants with Microsoft Sentinel workspaces onboarded to the Microsoft Defender portal, search for security information and event management (SIEM) data together with extended detection and response (XDR) data across multiple tenants and workspaces.
2626

27-
Multiple workspaces per tenant are supported in multi-tenant Advanced hunting as preview.
28-
2927
## Run cross-tenant queries
3028

3129
You can run any query that you already have access to in the multi-tenant management **Advanced hunting** page.
@@ -61,7 +59,7 @@ You can run any query that you already have access to in the multi-tenant manage
6159

6260
To learn more about advanced hunting in Microsoft Defender XDR, read [Proactively hunt for threats with advanced hunting in Microsoft Defender XDR](/defender-xdr/advanced-hunting-overview).
6361

64-
## Run cross-workspace queries (Preview)
62+
## Run cross-workspace queries
6563

6664
To run queries across multiple workspaces in the same tenant, use the [workspace( ) expression](/azure/azure-monitor/logs/cross-workspace-query#query-across-log-analytics-workspaces-using-workspace), with the workspace identifier as the argument in your query to refer to a table in a different workspace.
6765

unified-secops-platform/mto-incidents-alerts.md

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -26,8 +26,6 @@ Multi-tenant management for Microsoft Defender XDR and Microsoft Sentinel in the
2626

2727
Manage incidents & alerts originating from multiple tenants and workspaces under **Incidents & alerts**.
2828

29-
Multiple workspaces per tenant are supported in multitenant management as preview.
30-
3129
## View and investigate incidents
3230

3331
To view or investigate an incident:

unified-secops-platform/mto-overview.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ Multitenant management for Microsoft Defender XDR and Microsoft Sentinel in the
2727

2828
## Microsoft Sentinel support
2929

30-
For each tenant, the Defender portal allows you to connect to one primary workspace and multiple secondary workspaces for Microsoft Sentinel (preview). In the context of this article, a workspace is a Log Analytics workspace with Microsoft Sentinel enabled.
30+
For each tenant, the Defender portal allows you to connect to one primary workspace and multiple secondary workspaces for Microsoft Sentinel. In the context of this article, a workspace is a Log Analytics workspace with Microsoft Sentinel enabled.
3131

3232
If you have tenants with Microsoft Sentinel workspaces onboarded to the Defender portal, you're able to:
3333

unified-secops-platform/overview-deploy.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,7 @@ For more information, see [Get started with Security Copilot](/copilot/security/
6161

6262
## Architect your workspace and onboard to Microsoft Sentinel
6363

64-
The first step in using Microsoft Sentinel is to create a Log Analytics workspace, if you don't have one already. A single Log Analytics workspace might be sufficient for many environments, but many organizations create multiple workspaces to optimize costs and better meet different business requirements. Microsoft's unified security operations platform supports a primary workspace and multiple secondary workspaces (preview).
64+
The first step in using Microsoft Sentinel is to create a Log Analytics workspace, if you don't have one already. A single Log Analytics workspace might be sufficient for many environments, but many organizations create multiple workspaces to optimize costs and better meet different business requirements. Microsoft's unified security operations platform supports a primary workspace and multiple secondary workspaces.
6565

6666
1. Create a Security resource group for governance purposes, which allows you to isolate Microsoft Sentinel resources and role-based access to the collection.
6767
1. Create a Log Analytics workspace in the Security resource group and onboard Microsoft Sentinel into it.

unified-secops-platform/whats-new.md

Lines changed: 15 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.service: unified-secops-platform
66
ms.author: bagol
77
author: batamig
88
ms.localizationpriority: medium
9-
ms.date: 03/31/2025
9+
ms.date: 04/24/2025
1010
manager: orspodek
1111
audience: ITPro
1212
ms.collection:
@@ -20,6 +20,20 @@ ms.topic: concept-article
2020

2121
This article lists recent features added into Microsoft's unified SecOps platform within the Microsoft Defender portal, and new features in related services that provide an enhanced user experience in the platform.
2222

23+
## May 2025
24+
25+
- [Microsoft Sentinel use cases generally available in Microsoft's unified SecOps platform](#microsoft-sentinel-use-cases-generally-available-in-microsofts-unified-secops-platform)
26+
27+
### Microsoft Sentinel use cases generally available in Microsoft's unified SecOps platform
28+
29+
All Microsoft Sentinel use cases that are in general availability, including [multi-tenant](mto-overview) and [multi-workspace](/azure/sentinel/workspaces-defender-portal) capabilities and support for all government and commercial clouds, are now also supported for general availability in the unified SecOps platform in the Defender portal.
30+
31+
We recommend that you [onboard your workspaces to the Defender portal](microsoft-sentinel-onboard.md) to take advantage of a single location for all your security operations. For more information, see:
32+
33+
<!--link to blog-->
34+
- [Moving to Microsoft's unified SecOps platform, by persona](https://aka.ms/move-to-defender)
35+
- [Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md)
36+
2337
## April 2025
2438

2539
- [Multi workspace and multi tenant support for Microsoft Sentinel (preview)](#multi-workspace-and-multi-tenant-support-for-microsoft-sentinel-preview)

0 commit comments

Comments
 (0)