Skip to content

Commit ee04aa1

Browse files
authored
Update mto-requirements.md
1 parent c6770ab commit ee04aa1

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

unified-secops-platform/mto-requirements.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ The following table lists the basic requirements you need to use multitenant man
4040
|:---|:---|
4141
| Microsoft Defender XDR prerequisites | Verify you meet the [Microsoft Defender XDR prerequisites](/defender-xdr/prerequisites)|
4242
| Microsoft Defender XDR for US Government customers | Check if you have the following applicable [licensing requirements](/defender-xdr/usgov#licensing-requirements)|
43-
| Multitenant access | To view and manage the data you have access to in multitenant management, you need to ensure you have the necessary access. <br><br>- **For Microsoft Defender data**, you must have either: <br>- [Granular delegated admin privileges (GDAP)](/partner-center/gdap-introduction)<br/>- [Microsoft Entra B2B authentication](/azure/active-directory/external-identities/what-is-b2b)<br><br>- **To run cross-tenant queries on Microsoft Sentinel data**, you must set up Azure Lighthouse. For example, to run cross-workspace queries with the `workspace()` operator in advanced hunting and analytics rules.|
43+
| Multitenant access | To view and manage the data you have access to in multitenant management, you need to ensure you have the necessary access. <br><br>- **For Microsoft Defender data**, you must have either: <br>- [Granular delegated admin privileges (GDAP)](/partner-center/gdap-introduction)<br/>- [Microsoft Entra B2B authentication](/azure/active-directory/external-identities/what-is-b2b)<br><br>- **To run cross-tenant queries on Microsoft Sentinel data**, you must set up [Azure Lighthouse](/azure/lighthouse/overview). For example, to run cross-workspace queries with the `workspace()` operator in advanced hunting and analytics rules.|
4444
| Permissions | Users must be assigned the correct roles and permissions at the individual tenant level, in order to view and manage the associated data in multitenant management. To learn more, see: <br/><br/> - [Manage access to Microsoft Defender XDR with Microsoft Entra global roles](/defender-xdr/m365d-permissions) <br/> - [Custom roles in role-based access control for Microsoft Defender XDR](/defender-xdr/custom-roles)<br/><br/> To learn how to grant permissions for multiple users at scale, see [What is entitlement management](/azure/active-directory/governance/entitlement-management-overview).|
4545
| Security information and event management (SIEM) data (Optional) |To include SIEM data with the extended detection and response (XDR) data, one or more tenants must include a Microsoft Sentinel workspace onboarded to Microsoft Defender. For more information, see [Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md).<br/><br/>The Defender portal allows you to connect to one primary workspace and multiple secondary workspaces for Microsoft Sentinel. For more information, see [Multiple Microsoft Sentinel workspaces in the Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2310579).<br/><br/> Access to Microsoft Sentinel data is available through [Microsoft Entra B2B authentication](/azure/active-directory/external-identities/what-is-b2b). Microsoft Sentinel doesn't support [granular delegated admin privileges (GDAP)](/partner-center/gdap-introduction) at this time. |
4646

0 commit comments

Comments
 (0)