Forum Discussion
Justinvw123CT
May 04, 2021Copper Contributor
Azure Security Centre and Sentinel sharing LAW
I have a question and am hoping someone can clarify something for me. We are working on a project deploying Azure Security Centre and Azure Defender (leveraging Qualys scanning engine) for vulnerabil...
CliveWatson
May 04, 2021Former Employee
Technically you can have a LAW for ASC and one for Azure Sentinel (and use the connector), but most people combine the two workspaces into one shared resource. Advise is to have as few large workspaces as possible (start at one, and only add others as exceptions). Also remember Azure Sentinel cant use a "default-" workspace, that ASC can setup, so you need a named LAW. The data not to have in Azure Sentinel is operational data (data with low or no security value) especially Perf data, Perf if mid-high volume probably should be in its own LAW. https://techcommunity.microsoft.com/t5/azure-sentinel/become-an-azure-sentinel-ninja-the-complete-level-400-training/ba-p/1246310