Microsoft Sentinel
Cloud and workloads

Powerbi

In brief

The Sentinel Power BI article now explains that scheduled refresh is configured on the report’s backing dataset, which is created when the report is published. It also specifies the required Log Analytics read-access credentials and adds detail about query results and published reports.

What Defender admins need to know

Administrators configuring scheduled refresh should use the report dataset and ensure suitable Log Analytics access credentials are available.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security analyst, I want to create and share Power BI reports from Microsoft Sentinel data so that I can provide insights to stakeholders without granting them direct access to Microsoft Sentinel.

  1. Select Run to runexecute the queryquery. The results show a summary of sign-in attempts by application over the last seven days, including failed and generate results.successful counts.

    :::image type="content" source="media/powerbi/query.png" alt-text="Screenshot showing the KQL query and results.":::

Create visualizations from the data

Now that your data isthe imported Microsoft Sentinel query results are in Power BI, you can create visualizations to provide insights into the data.

Create a table visual

Refresh the data and save the report

Refresh the Power BI dataset created from the exported Microsoft Sentinel query to retrieve the latest Microsoft Sentinel data, and then save the report.

  1. Select Refresh to get the latest data from Microsoft Sentinel.

Import the report to a Microsoft Teams channel

You also want members of the Management Teams channel to be able to see the published Power BI report. To add the report to a Teams channel:

  1. In the Management Teams channel, select + to add a tab, and in the Add a tab window, search for and select Power BI.

Schedule report refresh

Refresh yourConfigure a scheduled refresh for the report's dataset in the Power BI report on a schedule,service, so updated data always appears in the report. Before you begin, make sure you have credentials for an account with read access to the Log Analytics workspace.

In Power BI, scheduled refresh is configured on the dataset that backs your report. When you publish a report, Power BI automatically creates a corresponding dataset in the workspace.

  1. In the Power BI service, select the workspace you published your report to.