Microsoft Sentinel
Cloud and workloads

Sap Audit Log Workbook

In brief

The page no longer includes guidance about the workbook’s hosting workspace or selecting a different SOC workspace when SOC data is stored elsewhere.

What Defender admins need to know

Administrators configuring SAP and SOC data across different workspaces will no longer find this guidance in the page; no required action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • The SAP - Security Audit log and Initial Access workbook installed in your Log Analytics workspace enabled for Microsoft Sentinel. For more information, see Visualize and monitor your data by using workbooks in Microsoft Sentinel.

  • At least one incident in your Microsoft Sentinel workspace, with at least one entry available in the SecurityIncident table. This doesn't need to be an SAP incident, and you can generate a demo incident using a basic analytics rule if you don't have another one.

  • If your Microsoft Entra data is in a different Log Analytics workspace, make sure you select the relevant subscriptions and workspaces at the top of the workbook, under Azure audit and activities.

  • At least one incident in your Microsoft Sentinel workspace, with at least one entry available in the SecurityIncident table. This doesn't need to be an SAP incident, and you can generate a demo incident using a basic analytics rule if you don't have another one.

  • If your Microsoft Entra data is in a different Log Analytics workspace, make sure you select the relevant subscriptions and workspaces at the top of the workbook, under Azure audit and activities.