Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Important
Attention: All Microsoft Sentinel features will be officially retired in Azure in China regions on August 18, 2026 per the announcement posted by 21Vianet.
If you're a managed security service provider (MSSP) and you're using Azure Lighthouse to offer security operations center (SOC) services to your customers, you can manage your customers' Microsoft Sentinel resources directly from your own Azure tenant, without having to connect to the customer's tenant.
Prerequisites
Before you manage multiple tenants in Microsoft Sentinel, complete the following prerequisite:
Verify registration of Microsoft Sentinel resource providers
Your MSSP tenant must have the Microsoft Sentinel resource providers registered on at least one subscription. Each of your customers' tenants must also have those resource providers registered.
If you already registered Microsoft Sentinel in your tenant, and your customers did the same in theirs, you can skip ahead to Access Microsoft Sentinel in managed tenants.
To verify registration:
Select Subscriptions from the Azure portal, and then select a relevant subscription from the menu.
From the navigation menu on the subscription screen, under Settings, select Resource providers.
From the subscription name | Resource providers screen, search for Microsoft.OperationalInsights and Microsoft.SecurityInsights. Select each one and check the Status column. If the status is NotRegistered, select Register.
Access Microsoft Sentinel in managed tenants
To access your customers' Microsoft Sentinel workspaces from your own tenant, perform the following steps:
Under Directory + subscription, select the delegated directories (each directory maps to a tenant). Also select the subscriptions that contain your customer's Microsoft Sentinel workspaces.
Open Microsoft Sentinel, where you'll see all the workspaces in the selected subscriptions and can work with them seamlessly, just like any workspace in your own tenant.
Note
You can't deploy connectors in Microsoft Sentinel from a managed workspace that uses only Azure Lighthouse. You must also configure GDAP.
Related content
For more information about Microsoft Sentinel, see the following articles:
- Get started detecting threats with Microsoft Sentinel.