Azure Sentinel by Patrik

Azure Sentinel Deployment

Azure Sentinel can only be enabled for a single Log Analytics Workspace. Therefore it is recommended to centralize all security logs to a dedicated central workspace. Use Azure Lighthouse if you have multiple workspaces.


To create Azure Sentinel, an active subscription and a Log Analytics workspace need to be available.

The permissions required

  • Contributor on Subscription level
  • Contributor or Reader on Resource Group or Resource level


Resource

Comments