Forum Discussion
Azure Sentinel with Lighthouse
fm1984 In regards to the 3rd bullet point, you are correct that Azure Lighthouse will not be able to assign local users to an Incident. From my research, this would require "Directory Reader" rights that can only be granted at the Azure AD level and not through Lighthouse.
Thanks for the info. This is what we are seeing. In the customer tenant, security user can see who is assigned an incident. In the Lighthouse tenant, he can not see who is assigned, even though he has privileges' in the customer tenant. Assigning Directory Reader in the customer tenant does not allow the user to see any users assigned.
- GaryBusheyJun 25, 2020Bronze Contributor
lmpalermo That is what I would expect. Even if you are using the same account in your own tenant and in the customer's tenant, Lighthouse doesn't check to see what rights that account has on the customer's tenant. It only checks to see what rights have been granted via the ARM Template used to enable Lighthouse (and you cannot assign Directory Reader via Lighthouse).
If you need to assign customers to incidents, then Lighthouse will not work for you and you will need to login to the customer's tenant directly.
- lmpalermoJun 25, 2020Copper Contributor
- GaryBusheyJun 26, 2020Bronze Contributor
lmpalermo That is correct. You don't have permission to translate the GUID to a username