Skip to content

Commit d94421a

Browse files
Merge pull request #2068 from cwatson-cat/patch-14
Sentinel - onboard to defender portal - add info about connector
2 parents 2250b2a + 190580c commit d94421a

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

defender-xdr/microsoft-sentinel-onboard.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ search.appverid:
2222
appliesto:
2323
- Microsoft Defender XDR
2424
- Microsoft Sentinel in the Microsoft Defender portal
25-
ms.date: 10/16/2024
25+
ms.date: 12/02/2024
2626
---
2727

2828
# Connect Microsoft Sentinel to the Microsoft Defender portal
@@ -52,7 +52,7 @@ The Microsoft Defender portal supports a single Microsoft Entra tenant and the c
5252
To onboard and use Microsoft Sentinel in the Defender portal, you must have the following resources and access:
5353

5454
- A Log Analytics workspace that has Microsoft Sentinel enabled
55-
- The data connector for Microsoft Defender XDR enabled in Microsoft Sentinel for incidents and alerts. Install the Defender XDR solution and configure the data connector to connect Microsoft Sentinel to the Defender portal. For more information, see [Discover and manage Microsoft Sentinel out-of-the-box content](/azure/sentinel/sentinel-solutions-deploy). <!--Question to Simaya about configuring the other options on this connector - would we still need that for unified SOC. Would they go back and configure those settings? https://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-365-defender-->
55+
- The data connector for Microsoft Defender XDR enabled in Microsoft Sentinel for incidents and alerts. Install the Defender XDR solution and configure the data connector to connect Microsoft Sentinel to the Defender portal. For more information, see [Discover and manage Microsoft Sentinel out-of-the-box content](/azure/sentinel/sentinel-solutions-deploy). Within the Defender XDR data connector, the configuration option to connect incident and alerts is turned off and disabled after you onboard Microsoft Sentinel to the Defender portal.
5656
- An Azure account with the appropriate roles to onboard, use, and create support requests for Microsoft Sentinel in the Defender portal. The following table highlights some of the key roles needed.
5757

5858
|Task |Microsoft Entra or Azure built-in role required |Scope |

0 commit comments

Comments
 (0)