Microsoft Sentinel
Cloud and workloads

Connect Microsoft Sentinel to other Microsoft services by using diagnostic settings-based connections

In brief

The article’s metadata was updated, and its wording was clarified to state that some diagnostic settings-based connectors are managed through Azure Policy.

What Defender admins need to know

Administrators can use the updated wording to identify the applicable connector management guidance; no configuration change is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security engineer, I want to ingest diagnostic data from Azure services to Microsoft Sentinel so that analysts can monitor logs for enhanced threat detection and response.

Connect Microsoft Sentinel to other Microsoft services by using diagnostic settings-based connections

This article describes how to connect to Microsoft Sentinel by using diagnostic settings connections. Microsoft Sentinel uses the Azure foundation to provide built-in, service-to-service support for data ingestion from many Azure and Microsoft 365 services, Amazon Web Services, and various Windows Server services. There are a few different methods through which these diagnostic settings-based connections are made.

This article presents information that is common to the Microsoft Sentinel data connectors that use diagnostic settings-based connections. Some of these types ofdiagnostic settings-based connectors are managed by using Azure Policy. For diagnostic settings-based connectors that aren't managed by Azure Policy, use the standalone instructions.instructions in Connect via a standalone diagnostic settings-based connector.

[!INCLUDE reference-to-feature-availability]