A multinational corporation is deploying Microsoft Sentinel across several Azure regions to comply with various data sovereignty laws. They need to ensure that logs collected from resources in a specific region (e.g., 'Canada Central') are processed and stored exclusively within that region. Additionally, they want to centralize the management of all Sentinel instances from a single Azure subscription. How should the architect design this deployment to meet both data sovereignty and centralized management requirements?
- ADeploy a single Log Analytics workspace in a central region and ingest all data, then use Azure Policy for regional access control.
- BCreate a single Microsoft Sentinel instance in the central region and connect it to multiple regional Log Analytics workspaces.
- CDeploy multiple Log Analytics workspaces, each in its respective geographic region, and link separate Sentinel instances to each workspace.
- DUse Azure Lighthouse to delegate management of regional Sentinel instances to a central management subscription.
Show answer & explanationAnswer & explanation
Correct answer: C. Deploy multiple Log Analytics workspaces, each in its respective geographic region, and link separate Sentinel instances to each workspace.
To meet strict data sovereignty, each region must have its own Log Analytics workspace, as the workspace's location dictates data residency. Since Sentinel is deployed on top of a Log Analytics workspace, this means deploying a separate Sentinel instance for each regional workspace. Centralized management can then be achieved through Azure management groups or Azure Lighthouse, but the fundamental data residency is addressed by regional workspaces.
Why the other options are wrong
- A. A single central workspace violates data sovereignty for logs originating from other regions.
- B. A single Sentinel instance can only be linked to *one* Log Analytics workspace, so it cannot connect to multiple regional workspaces directly for data ingestion.
- D. Azure Lighthouse is for delegated management across subscriptions/tenants but doesn't solve the underlying data residency problem if the workspaces aren't regionally isolated.
Microsoft Sentinel Multi-Region Deployment
For strict data sovereignty, Microsoft Sentinel deployments often involve multiple Log Analytics workspaces and corresponding Sentinel instances, each located in a specific geographic region, with centralized management typically layered on top.
- Log Analytics workspace location determines data residency.
- Each Sentinel instance is tied to one Log Analytics workspace.
- Centralized management can be achieved via Azure management groups or Azure Lighthouse.
Memory trick: Regional Workspaces: Rule Your Data's Realm!