mssentinel data.md

Microsoft Sentinel

Microsoft Sentinel

{% hint style="success" %} Microsoft Sentinel is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.

Note that this is different from Microsoft 365/Microsoft Defender. {% endhint %}

The Dropzone platform integrates with the Microsoft Sentinel security SIEM. Many customers ingest other alert sources into Microsoft Sentinel (e.g. IDPs) and integrate Dropzone into Microsoft Sentinel rather than the source systems.

Integration Overview

To enable these integrations you will perform the following actions:

See the Microsoft Integrations page for instructions on how to register a new application, locate your Client ID and Tenant ID, and to create a Client Secret.

Set Application Permissions

General instructions on how to assign API permissions to the application can be found in the Microsoft Integrations page.

Enabling MS Sentinel will require the following APIs and permissions:

API Permissions
Log Analytics Data.Read
Microsoft Graph SecurityEvents.Read.All

To add the Log Analytics API, do the following:

Select Log Analytics API

Add the Data.Read permission

Grant admin consent

Grant admin consent

If your integration requires access to security alerts via Microsoft Graph, do the following:

Select Microsoft Graph

Add the SecurityEvents.Read.All permission

Grant admin consent

Grant admin consent

Assign Roles in Microsoft Sentinel

To allow the application to access Microsoft Sentinel data, you must assign the application roles based on your desired access level.

Navigate to Microsoft Sentinel

Select your workspace

Navigate to Settings

Click on Workspace settings

Click on Access control (IAM)

Add a role assignment

{% hint style="info" %} If you wish to enable Ticket Sync, you must assign the application a Read and write access role. {% endhint %}

Select your role

{% hint style="info" %} For the purpose of this documentation, the Log Analytics Reader role has been selected. {% endhint %}

Click Select members

Assign members

Click Review + assign

Workspace IDs

To obtain your Workspace Name and Workspace ID, do the following:

Navigate to Microsoft Sentinel

Select your workspace

Navigate to settings

Navigate to settings

Copy the integration details

Enable Microsoft Sentinel

To enable the Data Source integration, you will need the following information:

Dropzone Field Source
Client ID The Application ID copied earlier
Tenant ID The Directory ID copied earlier
Client Secret The Client Secret Value copied earlier
Workspace ID The Workspace ID copied earlier
Subscription ID The Subscription ID copied earlier
Resource Group The Resource group copied earlier

To enable the Data Source integration, do the following:

Integrations Dropdown

Click Available

The Microsoft Sentinel Tile

The Microsoft Sentinel Data Integration pt 1

The Microsoft Sentinel Data Integration pt 2

If you have any errors engage your Dropzone AI support representative.