Microsoft Sentinel
Cloud and workloads

Configure Table Settings in Microsoft Sentinel

In brief

The page now focuses on retention and data tier settings for Sentinel and Defender XDR tables, adds Table insights for monitoring ingestion health and costs, and revises its permissions section and related-content links.

What Defender admins need to know

Administrators using this guidance should review the updated scope and permissions table when configuring or monitoring table settings.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure table settings in Microsoft Sentinel

Permissions to manage table settings

The following table lists the permissions required to view or configure table settings.

Action Unified role-based access control (RBAC)RBAC in the Defender portal Microsoft Sentinel workspace permissions
View table settings Security data basics (read) permissions under the Security operations permissions group Microsoft.OperationalInsights/workspaces/tables/read permissions to the Log Analytics workspace, as provided by the Log Analytics Reader built-in role, for example.
Configure table settings Data (manage) permissions under the Data operations permissions group Microsoft.OperationalInsights/workspaces/write and Microsoft.OperationalInsights/workspaces/tables/write permissions to the Log Analytics workspace, as provided by the Log Analytics Contributor built-in role, for example.
Alerting Table insights is a visualization surface only. To alert on table health, such as when a connector goes silent, create a scheduled analytics rule that uses the SentinelHealth table or a Kusto Query Language (KQL) query against Usage or a table-specific schema.
Multi-workspace view Table insights shows data for the currently selected workspace only. If you manage multiple workspaces, switch workspaces to review each one separately.

Next stepsRelated content

Learn more about: