Forum Discussion
R_Moeller
Jan 21, 2022Copper Contributor
Deviating retention period in Sentinel than in other Azure Data Sources
Hi community, our company wants to set the retention period for logs of Microsoft Cloud components e.g. Teams, Exchange (Online), ... to 30 days. On the other hand, the data in Sentinel or shou...
Thijs Lecomte
Jan 21, 2022Bronze Contributor
After you ingest them into Sentinel, they are linked and the only retention they follow is the retention set on the workspace.
They don't follow the original retention from the product.
You can also set up table level RBAC if needed: https://m365securitybook.com/2021/12/21/configuring-table-level-retention-in-microsoft-sentinel/
They don't follow the original retention from the product.
You can also set up table level RBAC if needed: https://m365securitybook.com/2021/12/21/configuring-table-level-retention-in-microsoft-sentinel/