Microsoft Unified SecOps Platform
General

Use workbooks in multitenant management

In brief

The article was rewritten with clearer steps for opening Workbooks and using the Situational Awareness workbook. It also clarifies tenant selection and current workbook limitations.

What Defender admins need to know

Administrators can use the revised guidance to navigate the portal and understand workbook scope and limitations. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Use workbooks in multitenant management

The Workbooks feature in Microsoft Sentinel enables users tolets you manage and view workbooks across multiple tenants from a single page one page. You can use the built-in the multitenant Organization portal. ​The Workbooks feature allows usersSituational Awareness workbook to access an out-of-the-box multitenant workbook, Situational Awareness, which provides insights intotrack tenant health, trends, and key metrics. ​ThisThis article explainsshows how to access and use the Workbooks featureworkbooks in Microsoft Sentinel multitenant management. Before you begin, make sure you meet the prerequisites for using workbooks in multitenant management.

Prerequisites

Access a workbook​

To navigateFollow these steps to open the workbookWorkbooks page in the multitenant Organization portal in Microsoft Sentinel. ​portal.

  1. In the left-hand navigation pane, select Microsoft Sentinel > Workbooks. ​The WorkbooksThis page displays an aggregatedshows a combined list of all workbooks across your tenants.

    :::image type="content" source="./media/mto-workbooks/access-workbook.png" alt-text="Screenshot of Workbooks homepage.":::

Open the situational awareness workbook

Use theThe Situational Awareness workbook to get insights across your tenants, includingshows health status, trends, and metrics. The Situational Awareness workbook is multitenant supported,metrics across your tenants. It supports multiple tenants, so you can selectpick which tenantsones to include.

  1. FromIn the multitenant management portal, select the button belowon the Situational Awareness cardcard.

    :::image type="content" source="./media/mto-workbooks/situational-awareness-card.png" alt-text="Screenshot of Situational Awareness button.":::

  2. To choose which tenants to include, useUse the tenant selector in the top-right corner. ​ Optionally,corner to pick which tenants to include. To pick specific workspaces, select Edit selection to select specific workspaces. ​ Ensure. Make sure your home tenant is included in the scope and has threat intelligence data in the selected workspace, anddata. Then select Apply.

    :::image type="content" source="./media/mto-workbooks/tenant-scope.png" alt-text="Screenshot of tenant selector.":::

Explore the Workbook ​situational awareness workbook

Use the following workbook features to analyze data across tenants:

Workbook limitations in multitenant management

Be aware ofNote the following limitations when usinglimits for Workbooks in multitenant management:

  • The Situational Awareness workbook only uses threat intelligence data exclusively from the home tenant, and this settingtenant. You can't be changed.change this setting.
  • TheYou can't edit or create workbooks from the Workbooks page doesn't currently support editing or creating workbooks.page.
  • Workbook templates are currently not supporteddon't appear in the aggregatedcombined view.