You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/microsoft-sentinel-onboard.md
+3-2Lines changed: 3 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -22,7 +22,7 @@ search.appverid:
22
22
appliesto:
23
23
- Microsoft Defender XDR
24
24
- Microsoft Sentinel in the Microsoft Defender portal
25
-
ms.date: 05/29/2024
25
+
ms.date: 06/25/2024
26
26
---
27
27
28
28
# Connect Microsoft Sentinel to Microsoft Defender XDR
@@ -38,14 +38,15 @@ Before you begin, review the feature documentation to understand the product cha
38
38
39
39
-[Microsoft Sentinel in the Microsoft Defender portal](/azure/sentinel/microsoft-sentinel-defender-portal)
40
40
-[Advanced hunting in the Microsoft Defender portal](advanced-hunting-microsoft-defender.md)
41
+
-[Alerts, incidents, and correlation in Microsoft Defender XDR](alerts-incidents-correlation.md)
41
42
-[Automation with the unified security operations platform](/azure/sentinel/automation#automation-with-the-unified-security-operations-platform)
42
43
43
44
The Microsoft Defender portal supports a single Microsoft Entra tenant and the connection to one workspace at a time. In the context of this article, a workspace is a Log Analytics workspace with Microsoft Sentinel enabled.
44
45
45
46
To onboard and use Microsoft Sentinel in the Microsoft Defender portal, you must have the following resources and access:
46
47
47
48
- A Log Analytics workspace that has Microsoft Sentinel enabled
48
-
- The data connector for Microsoft Defender XDR (formerly named Microsoft 365 Defender) enabled in Microsoft Sentinel for incidents and alerts
49
+
- The data connector for Microsoft Defender XDR (formerly named Microsoft 365 Defender) enabled in Microsoft Sentinel for incidents and alerts. For more information, see [Connect data from Microsoft Defender XDR to Microsoft Sentinel](/azure/sentinel/connect-microsoft-365-defender).
49
50
- Access to Microsoft Defender XDR in the Defender portal
50
51
- Microsoft Defender XDR onboarded to the Microsoft Entra tenant
51
52
- An Azure account with the appropriate roles to onboard, use, and create support requests for Microsoft Sentinel in the Defender portal. The following table highlights some of the key roles needed.
0 commit comments