Manage multiple Microsoft Sentinel workspaces with workspace manager (2024)

  • Article

Learn how to centrally manage multiple Microsoft Sentinel workspaces within one or more Azure tenants with workspace manager. This article takes you through provisioning and usage of workspace manager. Whether you're a global enterprise or a Managed Security Services Provider (MSSP), workspace manager helps you operate at scale efficiently.

Here are the active content types supported with workspace manager:

  • Analytics rules
  • Automation rules (excluding Playbooks)
  • Parsers, Saved Searches and Functions
  • Hunting and Livestream queries
  • Workbooks

Important

Support for workspace manager is currently in PREVIEW. The Azure Preview Supplemental Terms include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.

Prerequisites

  • You need at least two Microsoft Sentinel workspaces. One workspace to manage from and at least one other workspace to be managed.
  • The Microsoft Sentinel Contributor role assignment is required on the central workspace (where workspace manager is enabled on), and on the member workspace(s) the contributor needs to manage. To learn more about roles in Microsoft Sentinel, see Roles and permissions in Microsoft Sentinel.
  • Enable Azure Lighthouse if you're managing workspaces across multiple Microsoft Entra tenants. To learn more, see Manage Microsoft Sentinel workspaces at scale.

Considerations

Configure a central workspace to be the environment where you consolidate content items and configurations to be published at scale to member workspaces. Create a new Microsoft Sentinel workspace or utilize an existing one to serve as the central workspace.

Depending on your scenario, consider these architectures:

  • Direct-link is the least complex setup. Control all member workspaces with only one central workspace.
  • Co-Management supports scenarios where more than one central workspace needs to manage a member workspace. For example, workspaces simultaneously managed by an in-house SOC team and an MSSP.
  • N-Tier supports complex scenarios where a central workspace controls another central workspace. For example, a conglomerate that manages multiple subsidiaries, where each subsidiary also manages multiple workspaces.

Manage multiple Microsoft Sentinel workspaces with workspace manager (1)

Enable workspace manager on the central workspace

Enable the central workspace once you have decided which Microsoft Sentinel workspace should be the workspace manager.

  1. Navigate to the Settings blade in the parent workspace, and toggle On the workspace manager configuration setting to "Make this workspace a parent".

  2. Once enabled, a new menu Workspace manager (preview) appears under Configuration.

    Manage multiple Microsoft Sentinel workspaces with workspace manager (2)

Onboard member workspaces

Member workspaces are the set of workspaces managed by workspace manager. Onboard some or all of the workspaces in the tenant, and across multiple tenants as well (if Azure Lighthouse is enabled).

  1. Navigate to workspace manager and select "Add workspaces"
  2. Select the member workspace(s) you would like to onboard to workspace manager.Manage multiple Microsoft Sentinel workspaces with workspace manager (4)
  3. Once successfully onboarded, the Members count increases and your member workspaces are reflected in the Workspaces tab.Manage multiple Microsoft Sentinel workspaces with workspace manager (5)

Create a group

Workspace manager groups allow you to organize workspaces together based on business groups, verticals, geography, etc. Use groups to pair content items relevant to the workspaces.

Tip

Make sure you have at least one active content item deployed in the central workspace. This allows you to select content items from the central workspace to be published in the member workspace(s) in the subsequent steps.

  1. To create a group:

    • To add one workspace, select Add > Group.
    • To add multiple workspaces, select the workspaces and Add > Group from selected.Manage multiple Microsoft Sentinel workspaces with workspace manager (6)
  2. On the Create or update group page, enter a Name and Description for the group.Manage multiple Microsoft Sentinel workspaces with workspace manager (7)

  3. In the Select workspaces tab, select Add and select the member workspaces that you would like to add to the group.

  4. In the Select content tab, you have 2 ways to add content items.

    • Method 1: Select the Add menu and choose All content. All active content currently deployed in the central workspace is added. This list is a point-in-time snapshot that selects only active content, not templates.
    • Method 2: Select the Add menu and choose Content. A Select content window opens to custom select the content added.Manage multiple Microsoft Sentinel workspaces with workspace manager (8)
  5. Filter the content as needed before you Review + create.

  6. Once created, the Group count increases and your groups are reflected in the Groups tab.

Publish the Group definition

At this point, the content items selected haven't been published to the member workspace(s) yet.

Note

The publish action will fail if the maximum publish operations are exceeded.Consider splitting up member workspaces into additional groups if you approach this limit.

  1. Select the group > Publish content.

    Manage multiple Microsoft Sentinel workspaces with workspace manager (9)

    To bulk publish, multi-select the desired groups and select Publish.Manage multiple Microsoft Sentinel workspaces with workspace manager (10)

  2. The Last publish status column updates to reflect In progress.Manage multiple Microsoft Sentinel workspaces with workspace manager (11)

  3. If successful, the Last publish status updates to reflect Succeeded. The selected content items now exist in the member workspaces.Manage multiple Microsoft Sentinel workspaces with workspace manager (12)

    If just one content item fails to publish for the entire group, the Last publish status updates to reflect Failed.

Troubleshooting

Each publish attempt has a link to help with troubleshooting if content items fail to publish.

  1. Select the Failed hyperlink to open the job failure details window. A status for each content item and target workspace pair is displayed.

  2. Filter the Status for failed item pairs.

Common reasons for failure include:

  • Content items referenced in the group definition no longer exist at the time of publish (have been deleted).
  • Permissions have changed at the time of publish. For example, the user is no longer a Microsoft Sentinel Contributor or doesn't have sufficient permissions on the member workspace anymore.
  • A member workspace has been deleted.

Known limitations

  • The maximum published operations per group is 2000. Published operations = (member workspaces) * (content items).
    For example, if you have 10 member workspaces in a group and you publish 20 content items in that group,
    published operations = 10 * 20 = 200.
  • Playbooks attributed or attached to analytics and automation rules aren't currently supported.
  • Workbooks stored in bring-your-own-storage aren't currently supported.
  • Workspace manager only manages content items published from the central workspace. It doesn't manage content created locally from member workspace(s).
  • Currently, deleting content residing in member workspace(s) centrally via workspace manager isn't supported.

API references

  • Workspace Manager Assignment Jobs
  • Workspace Manager Assignments
  • Workspace Manager Configurations
  • Workspace Manager Groups
  • Workspace Manager Members

Next steps

  • Manage multiple tenants in Microsoft Sentinel as an MSSP
  • Work with Microsoft Sentinel incidents in many workspaces at once
  • Protecting MSSP intellectual property in Microsoft Sentinel
Manage multiple Microsoft Sentinel workspaces with workspace manager (2024)

FAQs

How many workspaces can you have in Microsoft Sentinel? ›

Multi workspace limits
DescriptionLimitDependency
Incident view100 concurrently displayed workspaces
Log query100 Sentinel workspacesLog Analytics
Analytics rules20 Sentinel workspaces per query
May 21, 2024

Which Microsoft Sentinel features can you use in multiple workspace views? ›

Use cross-workspace workbooks

Workbooks provide dashboards and apps to Microsoft Sentinel. When working with multiple workspaces, workbooks provide monitoring and actions across workspaces.

What are two primary drawbacks of implementing single tenant with regional workspaces? ›

Disadvantages of Single Tenant with Regional Workspaces Model
  • Step 1: Increased Complexity. Managing multiple workspaces across different regions can lead to increased complexity in terms of administration and maintenance. ...
  • Step 2: Data Synchronization Challenges.
Jun 7, 2024

What is the minimum number of Microsoft Sentinel workspaces that you should create? ›

Two Microsoft Sentinel workspaces, one in each Microsoft Entra tenant, to ingest data from Office 365, Azure Activity, Microsoft Entra ID, and all Azure PaaS services. All other data, coming from on-premises data sources, can be routed to one of the two Microsoft Sentinel workspaces.

Can a user have multiple WorkSpaces? ›

By default, you can create only one WorkSpace per user per directory. However, if needed, you can create more than one WorkSpace for a user, depending on your directory setup. If you have only one directory for your WorkSpaces, create multiple usernames for the user.

How do I change the WorkSpace in Sentinel? ›

Currently it is not possible to change the workspace when you have already enabled Sentinel on this. If you want the Sentinel on any other workspace, you will have to create another Sentinel Instance for that LAWS and delete the sentinel from previous one which you are not using.

When to use multi-tenancy? ›

If you are building a software application, use multi-tenancy when you:
  1. Want to support multiple customers in a cost-effective cloud environment.
  2. Don't want to have a large infrastructural footprint.
  3. Don't have a large team for deployment, maintenance, and support.
  4. Want smoother scalability.

What is the issue with multi-tenancy in cloud computing? ›

Risk: In a multitenant environment, data from different users or organizations coexist on the same physical servers. While cloud providers implement robust security measures, there is still a risk of unauthorized access or data leakage, especially in cases of misconfigurations or security breaches.

What are the alternatives to multi-tenant architecture? ›

Option 2: Per-tenant silos

This option is ideal when your application already utilizes a similar siloed architecture. The siloed approach is great for data and metadata privacy as each of your tenants uses its dedicated infrastructure. Similarly, you can scale individual tenants based on their size and needs.

What is the maximum retention for Sentinel Workspace? ›

Data retention and archived logs costs

Retain all data ingested into the workspace at no charge for the first 90 days. Retention beyond 90 days is charged per the standard Log Analytics retention prices.

What is a Sentinel workspace manager? ›

Workspace Manager is a feature in Microsoft Sentinel that allows users to centrally manage multiple workspaces. Whether you're a global enterprise or a Managed Security Services Provider (MSSP), Workspace Manager helps you operate at scale efficiently.

What is the maximum number of repository connections allowed for each Microsoft Sentinel workspace? ›

Each Microsoft Sentinel workspace is currently limited to five repository connections. Each Azure resource group is limited to 800 deployments in its deployment history.

What is the maximum number of repository connections allowed for each Microsoft Sentinel WorkSpace? ›

Each Microsoft Sentinel workspace is currently limited to five repository connections. Each Azure resource group is limited to 800 deployments in its deployment history.

Can you have multiple ROS WorkSpaces? ›

You also have the option of sourcing an “overlay” - a secondary workspace where you can add new packages without interfering with the existing ROS 2 workspace that you're extending, or “underlay”.

What is the maximum retention for Sentinel WorkSpace? ›

Data retention and archived logs costs

Retain all data ingested into the workspace at no charge for the first 90 days. Retention beyond 90 days is charged per the standard Log Analytics retention prices.

Is Microsoft Sentinel high availability? ›

High Availability and Disaster Recovery: Microsoft Sentinel benefits from the high availability and disaster recovery capabilities built into the Azure cloud platform. Your SIEM infrastructure can be resilient to outages and disruptions, with data replicated across multiple geographic locations.

Top Articles
How to Buy I Bonds: Step-by-Step Instructions | The Motley Fool
Money Market Account vs. Money Market Fund: What’s the Difference?
Cooking Chutney | Ask Nigella.com
Faridpur Govt. Girls' High School, Faridpur Test Examination—2023; English : Paper II
Junk Cars For Sale Craigslist
The Atlanta Constitution from Atlanta, Georgia
Kraziithegreat
Usborne Links
Sissy Hypno Gif
OnTrigger Enter, Exit ...
Our Facility
Turning the System On or Off
Lax Arrivals Volaris
Hoe kom ik bij mijn medische gegevens van de huisarts? - HKN Huisartsen
Nba Rotogrinders Starting Lineups
Lake Nockamixon Fishing Report
Gdp E124
Gdlauncher Downloading Game Files Loop
Second Chance Maryland Lottery
111 Cubic Inch To Cc
Nick Pulos Height, Age, Net Worth, Girlfriend, Stunt Actor
Rondom Ajax: ME grijpt in tijdens protest Ajax-fans bij hoofdbureau politie
TBM 910 | Turboprop Aircraft - DAHER TBM 960, TBM 910
Craigslist West Valley
Gopher Hockey Forum
/Www.usps.com/International/Passports.htm
Today Was A Good Day With Lyrics
Www Va Lottery Com Result
Discord Nuker Bot Invite
Rainfall Map Oklahoma
Rek Funerals
Amazing Lash Bay Colony
Elanco Rebates.com 2022
Warren County Skyward
Seymour Johnson AFB | MilitaryINSTALLATIONS
10 Most Ridiculously Expensive Haircuts Of All Time in 2024 - Financesonline.com
Skip The Games Ventura
Grapes And Hops Festival Jamestown Ny
Edict Of Force Poe
Hebrew Bible: Torah, Prophets and Writings | My Jewish Learning
Indiana Jones 5 Showtimes Near Cinemark Stroud Mall And Xd
Vocabulary Workshop Level B Unit 13 Choosing The Right Word
Express Employment Sign In
Tunica Inmate Roster Release
Unblocked Games - Gun Mayhem
Paperlessemployee/Dollartree
Sams Gas Price San Angelo
Grandma's Portuguese Sweet Bread Recipe Made from Scratch
Tweedehands camper te koop - camper occasion kopen
Selly Medaline
Qvc Com Blogs
Latest Posts
Article information

Author: Sen. Ignacio Ratke

Last Updated:

Views: 6163

Rating: 4.6 / 5 (56 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Sen. Ignacio Ratke

Birthday: 1999-05-27

Address: Apt. 171 8116 Bailey Via, Roberthaven, GA 58289

Phone: +2585395768220

Job: Lead Liaison

Hobby: Lockpicking, LARPing, Lego building, Lapidary, Macrame, Book restoration, Bodybuilding

Introduction: My name is Sen. Ignacio Ratke, I am a adventurous, zealous, outstanding, agreeable, precious, excited, gifted person who loves writing and wants to share my knowledge and understanding with you.