Microsoft Expands Multi-Account Support for Sentinel Data Connectors
Microsoft has expanded its Microsoft Sentinel data connectors to support multi-account ingestion. This enhancement allows security teams to centralize telemetry from multiple environments, simplifying management and improving cross-environment correlation.
The capability applies to connectors for Auth0, CrowdStrike Falcon, and Salesforce Service Cloud, built using Microsoft's Codeless Connector Framework.
For example, administrators can ingest authentication events and other logs from multiple tenants into one Sentinel workspace. Once connected, existing Sentinel analytics rules, workbooks, and playbooks can operate across the ingested accounts.
This update addresses a common challenge in enterprise security operations centers: security tooling frequently spans multiple vendor tenants. Centralizing telemetry can improve management, but organizations still need to maintain appropriate access controls and data-retention policies for the consolidated security data.