Manage multiple tenants in Microsoft Sentinel as an MSSP

Important

Attention: All Microsoft Sentinel features will be officially retired in Azure in China regions on August 18, 2026 per the announcement posted by 21Vianet.

If you're a managed security service provider (MSSP) and you're using Azure Lighthouse to offer security operations center (SOC) services to your customers, you can manage your customers' Microsoft Sentinel resources directly from your own Azure tenant, without having to connect to the customer's tenant.

Prerequisites

Before you manage multiple tenants in Microsoft Sentinel, complete the following prerequisite:

Verify registration of Microsoft Sentinel resource providers

Your MSSP tenant must have the Microsoft Sentinel resource providers registered on at least one subscription. Each of your customers' tenants must also have those resource providers registered.

If you already registered Microsoft Sentinel in your tenant, and your customers did the same in theirs, you can skip ahead to Access Microsoft Sentinel in managed tenants.

To verify registration:

  1. Select Subscriptions from the Azure portal, and then select a relevant subscription from the menu.

  2. From the navigation menu on the subscription screen, under Settings, select Resource providers.

  3. From the subscription name | Resource providers screen, search for Microsoft.OperationalInsights and Microsoft.SecurityInsights. Select each one and check the Status column. If the status is NotRegistered, select Register.

    Screenshot of checking resource providers.

Access Microsoft Sentinel in managed tenants

To access your customers' Microsoft Sentinel workspaces from your own tenant, perform the following steps:

  1. Under Directory + subscription, select the delegated directories (each directory maps to a tenant). Also select the subscriptions that contain your customer's Microsoft Sentinel workspaces.

    Choose tenants and subscriptions

  2. Open Microsoft Sentinel, where you'll see all the workspaces in the selected subscriptions and can work with them seamlessly, just like any workspace in your own tenant.

Note

You can't deploy connectors in Microsoft Sentinel from a managed workspace that uses only Azure Lighthouse. You must also configure GDAP.

For more information about Microsoft Sentinel, see the following articles: