New Blog Post | Reusing Microsoft Sentinel Watchlists Across Tenants

Brass Contributor

JasonCohen1994_0-1658775619766.png

Reusing Microsoft Sentinel Watchlists Across Tenants - Azure Cloud & AI Domain Blog (azurecloudai.bl...

 

Here’s a common question (just received it again today, in fact).

Q: Is it possible to do cross-tenant retrieval of watchlists?

A: Retrieving Watchlist content through API isn’t available yet and Repositories doesn’t support Watchlists. So, here’s suggestions of a couple things you could do:

[1] Query the Watchlist and export the results to a .csv. Then import the Watchlist into the other tenant…

[2] Maintain a single .csv somewhere externally (blob or local storage) that gets updated in some fashion and then imported directly into each tenant (possibly continuously through automation) using Bulk update using the API.

API: https://rodtrent.com/u9f

0 Replies