Forum Discussion

leo_szalk's avatar
leo_szalk
Copper Contributor
Jun 14, 2021

Azure Sentinel MSP - Non-Scheduled Alert Queries

What is the best approach to take to pull alerts/incidents from non-scheduled rule queries, such as Azure AD Identity Protection) into the MSSP Tenant?

Should it be done by using cross-workspace queries to create a custom query that pulls in events from the SecurityAlert table with the rule frequency being near real-time to mimic the events coming in from particular connectors? Or is there an easier, built-in method?

5 Replies

  • HI Leo, why do you need to bring alerts/incidents from the customer tenant to the MSSP tenant?

    Just trying to understand before I answer
    • leo_szalk's avatar
      leo_szalk
      Copper Contributor
      Hi Javier,

      Looking to stay aligned with best practices and protect intellectual property for some custom content.

      Based on this:
      https://docs.microsoft.com/en-us/azure/sentinel/mssp-protect-intellectual-property
      • Javier-Soriano's avatar
        Javier-Soriano
        Icon for Microsoft rankMicrosoft
        Yes, but protecting intellectual property only makes sense for scheduled rules, For non-scheduled rules, there's really no IP to protect, right?

        The best practices is to ONLY use cross-ws analytics rules when there's a need to protect IP.

        Regards

Resources