Forum Discussion
leo_szalk
Jun 14, 2021Copper Contributor
Azure Sentinel MSP - Non-Scheduled Alert Queries
What is the best approach to take to pull alerts/incidents from non-scheduled rule queries, such as Azure AD Identity Protection) into the MSSP Tenant?
Should it be done by using cross-workspace queries to create a custom query that pulls in events from the SecurityAlert table with the rule frequency being near real-time to mimic the events coming in from particular connectors? Or is there an easier, built-in method?
- Javier-Soriano
Microsoft
HI Leo, why do you need to bring alerts/incidents from the customer tenant to the MSSP tenant?
Just trying to understand before I answer- leo_szalkCopper ContributorHi Javier,
Looking to stay aligned with best practices and protect intellectual property for some custom content.
Based on this:
https://docs.microsoft.com/en-us/azure/sentinel/mssp-protect-intellectual-property- Javier-Soriano
Microsoft
Yes, but protecting intellectual property only makes sense for scheduled rules, For non-scheduled rules, there's really no IP to protect, right?
The best practices is to ONLY use cross-ws analytics rules when there's a need to protect IP.
Regards