A global organization uses Azure Sentinel (now Microsoft Sentinel) across multiple Azure regions. They need to ensure that security data collected from each region remains within its geographical boundaries to comply with data residency regulations, while still allowing a central security operations center (SOC) to have a consolidated view of all incidents. Which Sentinel architecture approach best addresses this requirement?
- AMultiple Sentinel workspaces, one in each region, and use Azure Lighthouse to manage them centrally.
- BA single Sentinel workspace with all data connectors configured to send data globally.
- CMultiple Sentinel workspaces, one in each region, with a central Sentinel workspace for incident management.
- DA single Sentinel workspace with data filtering rules to restrict data access by region.
Show answer & explanationAnswer & explanation
Correct answer: A. Multiple Sentinel workspaces, one in each region, and use Azure Lighthouse to manage them centrally.
To meet data residency requirements while enabling centralized management, an organization should deploy multiple Sentinel workspaces (one per region for data residency) and then use Azure Lighthouse to delegate management of these workspaces to a central SOC. This allows for centralized incident management and automation without moving raw log data across regions.
Why the other options are wrong
- B. A single workspace sending all data globally violates data residency requirements.
- C. This approach introduces complexity in centralizing incident management without a specific Azure service to aggregate incidents across workspaces while respecting data residency.
- D. Data filtering rules restrict access but don't prevent data from being stored globally if it's in a single workspace, violating residency.
Sentinel Multi-Workspace Architecture
A multi-workspace architecture in Microsoft Sentinel involves deploying separate Log Analytics workspaces and Sentinel instances in different regions to satisfy data residency requirements. Azure Lighthouse can then be used to delegate management of these regional workspaces to a central Security Operations Center (SOC) for a consolidated incident view and centralized threat hunting without moving raw data.
- Ensures data residency per region.
- Uses separate Log Analytics workspaces and Sentinel instances.
- Azure Lighthouse enables delegated management across workspaces.
- Allows for centralized incident management and threat hunting.
Memory trick: Regional workspaces keep data local, Lighthouse gives a global view.