Microsoft Sentinel | Dropzone AI Documentation

Microsoft Sentinel

Microsoft Sentinel is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.

Note that this is different from Microsoft 365/Microsoft Defender.

The Dropzone platform integrates with the Microsoft Sentinel security SIEM. Many customers ingest other alert sources into Microsoft Sentinel (e.g. IDPs) and integrate Dropzone into Microsoft Sentinel rather than the source systems.

Integration Overview

To enable these integrations you will perform the following actions:

See the Microsoft Integrations page for instructions on how to register a new application, locate your Client ID and Tenant ID, and to create a Client Secret.

Set Application Permissions

General instructions on how to assign API permissions to the application can be found in the Microsoft Integrations page.

Enabling MS Sentinel will require the following APIs and permissions:

API Permissions
Log Analytics Data.Read
Microsoft Graph SecurityEvents.Read.All

To add the Log Analytics API, do the following:

Select Log Analytics API

If your integration requires access to security alerts via Microsoft Graph, do the following:

Assign Roles in Microsoft Sentinel

To allow the application to access Microsoft Sentinel data, you must assign the application roles based on your desired access level.

Select a role based on your desired access level:

If you wish to enable Ticket Sync, you must assign the application a Read and write access role.

For the purpose of this documentation, the Log Analytics Reader role has been selected.

Workspace IDs

To obtain your Workspace Name and Workspace ID, do the following:

Enable Microsoft Sentinel

To enable the Data Source integration, you will need the following information:

Dropzone Field Source
Client ID The Application ID copied earlier
Tenant ID The Directory ID copied earlier
Client Secret The Client Secret Value copied earlier
Workspace ID The Workspace ID copied earlier
Subscription ID The Subscription ID copied earlier
Resource Group The Resource group copied earlier

To enable the Data Source integration, do the following:

If you have any errors engage your Dropzone AI support representative.