1,359 questions with Microsoft Security | Microsoft Sentinel tags
Not getting Admin Access on Defender for Sentinel
{"sessionId":"2c67d037623542f7af6d8f5b9f510754","subscriptionId":"","resourceGroup":"","errorCode":"403","resourceName":"","details":"No…
Microsoft Security | Microsoft Sentinel
Content Hub in not Accessible
Hey Everyone, Can anyone help me in setting upon my Microsoft Sentinel Account, I am not find to find Content Hub.
Microsoft Security | Microsoft Sentinel
how to setup sentinel
I am trying to set up a Microsoft Sentinel demo account for personal training. My aim is to use the live environment to investigate incidents and become familiar with the steps involved in resolving them. Could anyone advise on how to create one?
Microsoft Security | Microsoft Sentinel
Forward Alerts from a Secondary Sentinel to a Primary Sentinel Workspace Using Logic Apps
HI, I am exploring the feasibility of forwarding Microsoft Sentinel alerts from a Secondary sentinel Workspace to a Primary Sentinel Workspace. There are two Sentinels for two LAWs and now we want to forward the alerts in One sentinel (secondary) to…
Microsoft Security | Microsoft Sentinel
The azure activity connector for Azure sentinel is not working. I've run through the launch wizard and install multiple times and cannot get a connected status.
The azure activity connector for Azure sentinel is not working. I've run through the launch wizard and install multiple times and cannot get a connected status. My CISO who is a owner over all subscription has the same issues.
Microsoft Security | Microsoft Sentinel
Failure in creating Sentinel space: Temporary server failure
I get constant failures when creating my first Sentinel workspace . Would you please help me investigate or raise a platform incident? The failure "Encountered a temporary server problem" happens for more then 48 hour whenever I try. The…
Microsoft Security | Microsoft Sentinel
Sentinel wont add my Log analysis workspace it reports Internal server error
Sentinel wont add my Log analysis workspace it reports Internal server error
Microsoft Security | Microsoft Sentinel
Sentinel restore refuses to delete forcing charges
We have been asked by an auditor to prove we can restore data in sentinel but when we try and delete it, it refuses to delete and then shows a date issue along side the restore. We are charged for this but cannot find a phone number or a single way to…
Microsoft Security | Microsoft Sentinel
Microsoft Sentinel does not appear in the Microsoft Defender Portal
Microsoft Sentinel does not appear in the Microsoft Defender portal. The user has Global Administrator permissions as well as the Microsoft Sentinel Contributor role on the workspace. However, when logging into the Defender portal, the Sentinel option is…
Microsoft Security | Microsoft Sentinel
update error for data connector through sentinel or defender portal
I keep getting this error when i try to update a data connector for Defender XDR. It used to work up until azure had an issue. Message- The workspace is enabled through the Microsoft Threat Protection Portal. Changes to the connector in Microsoft…
Microsoft Security | Microsoft Sentinel
how affect the integration of sentinel in Defender XDR to partners with GDAP permissions?
how affect the integration of sentinel in Defender XDR?. In my case i'm security partner and my clients give me GDAP permissions to manage his Defender XDR. Now with Sentinel integration we would want to manage all in the unified portal but we see that…
Microsoft Security | Microsoft Sentinel
HOw to resolve the error'where' operator: Failed to resolve table or column expression named 'Okta_CL' for Analytics rule User Session Impersonation(Okta)
Name is User Session Impersonation(Okta) Logic is : Okta_CL | where eventType_s == "user.session.impersonation.initiate" and outcome_result_s == "SUCCESS" // Expand the JSON array in 'target_s' field to extract detailed information…
Microsoft Security | Microsoft Sentinel
401 UnauthorizedAccess when calling STIX Threat Intelligence Upload API
We are calling the Threat Intelligence Upload API (Preview) using a registered Microsoft Entra app. We’ve followed all required steps: App is registered in Entra ID with correct permissions client_credentials flow is used with scope…
Microsoft Security | Microsoft Sentinel
How can I integrate Azure Cognitive Services into a .NET application?
I am currently learning about Azure on Microsoft Learn and want to integrate Azure Cognitive Services (like Text Analytics or Computer Vision) into a .NET 6 application. I am looking for guidance on: Setting up the Azure resources needed. …
Microsoft Security | Microsoft Sentinel
Change path on Linux for Azure AMA and CEF Collectors
I'm setting up Azure Monitoring Agents on Linux with CEF Collector. I would like to change the cache directories to a separate drive. Can anyone point me to where these paths are configured?
Azure Monitor
Microsoft Security | Microsoft Sentinel
Unable to configure Microsoft XDR connector in Sentinel
Hi Currently, it is not possible to configure the Microsoft Defender XDR connector via browser from Switzerland. Access to the URL https://partnersgw.securitycenter.windows.com/api/mdgw/sentinel/workspaces/isOnboarded is blocked unless a Microsoft…
Microsoft Security | Microsoft Sentinel
How to Correlate Defender XDR Signals with Non-Microsoft Logs in Microsoft Sentinel?
I am exploring advanced threat detection scenarios in Microsoft Sentinel and trying to correlate high-fidelity signals from Microsoft Defender XDR with non-Microsoft telemetry such as firewall logs, DNS logs, identity events from third-party providers,…
Microsoft Security | Microsoft Sentinel
Failed to add Microsoft Sentinel to workspace 'hn-ws-sentinel'. Internal server error
Tried adding microsoft sentinel, already created new workspace, selected said workspace but : tried again a few minutes later but still failed. please advise
Microsoft Security | Microsoft Sentinel
Unable to deploy "Atlassian Confluence Audit (via Codeless Connector Platform)" data connector on Microsoft Sentinel
I am unable to deploy "Atlassian Confluence Audit (via Codeless Connector Platform)"data connector on Azure Sentinel. Getting following error message: Connectivity check failed. ConnectorId: ConfluenceAuditCCPPolling, Status code:Unauthorized,…
Microsoft Security | Microsoft Sentinel
how can participate for Advanced KQL for SecOps?
how can participate for Advanced KQL for SecOps? Best Regards. Ignacio.