Microsoft Sentinel
Cloud and workloads

Multiple Tenants Service Providers

In brief

The article now presents prerequisites and steps more clearly, including resource-provider registration, delegated directory and subscription selection, and the GDAP requirement for deploying connectors from Lighthouse-only managed workspaces.

What Defender admins need to know

Administrators can use the revised instructions to verify tenant setup and connector deployment prerequisites.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As an MSSP, I want to manage multiple Microsoft Sentinel tenants from my own Azure tenant so that I can efficiently provide SOC services to my customers.

Prerequisites

Before you manage multiple tenants in Microsoft Sentinel, complete the following prerequisite:

Verify registration of Microsoft Sentinel resource providers

To manage multiple tenants properly, yourYour MSSP tenant must have the Microsoft Sentinel resource providers registered on at least one subscription, and eachsubscription. Each of your customers' tenants must also have thethose resource providers registered.

If you havealready registered Microsoft Sentinel in your tenant, and your customers did the same in theirs, you're ready can skip ahead to get started and can continue with Access Microsoft Sentinel in managed tenants.

To verify registration:

  1. From the navigation menu on the subscription screen, under Settings, select Resource providers.

  2. From the subscription name | Resource providers screen, search for and select Microsoft.OperationalInsights and Microsoft.SecurityInsights,. Select each one and check the Status column. If the provider's status is NotRegistered, select Register.

    :::image type="content" source="media/multiple-tenants-service-providers/check-resource-provider.png" alt-text="Screenshot of checking resource providers.":::

To access your customers' Microsoft Sentinel workspaces from your own tenant, perform the following steps:

  1. Under Directory + subscription, select the delegated directories (directory =(each directory maps to a tenant), and. Also select the subscriptions wherethat contain your customer's Microsoft Sentinel workspaces are located.workspaces.

    :::image type="content" source="media/multiple-tenants-service-providers/directory-subscription.png" alt-text="Choose tenants and subscriptions":::

  2. Open Microsoft Sentinel, where you'll see all the workspaces in the selected subscriptions and can work with them seamlessly, just like any workspace in your own tenant.

Related content