Manage multiple tenants in Microsoft Sentinel as an MSSP

If you're a managed security service provider (MSSP) and you're using Azure Lighthouse to offer security operations center (SOC) services to your customers, you can manage your customers' Microsoft Sentinel resources directly from your own Azure tenant, without having to connect to the customer's tenant.

Important

After March 31, 2027, Microsoft Sentinel will no longer be supported in the Azure portal and will be available only in the Microsoft Defender portal. All customers using Microsoft Sentinel in the Azure portal will be redirected to the Defender portal.

If you're still using Microsoft Sentinel in the Azure portal, we recommend that you start planning your move to the Defender portal to ensure a smooth experience and to take full advantage of unified security operations and multitenant management capabilities offered by the Defender portal. For guidance and best practices, see the Microsoft Defender portal implementation guide for MSSPs.

Prerequisites

Before you manage multiple tenants in Microsoft Sentinel, complete the following prerequisite:

Verify registration of Microsoft Sentinel resource providers

Your MSSP tenant must have the Microsoft Sentinel resource providers registered on at least one subscription. Each of your customers' tenants must also have those resource providers registered.

If you already registered Microsoft Sentinel in your tenant, and your customers did the same in theirs, you can skip ahead to Access Microsoft Sentinel in managed tenants.

To verify registration:

  1. Select Subscriptions from the Azure portal, and then select a relevant subscription from the menu.

  2. From the navigation menu on the subscription screen, under Settings, select Resource providers.

  3. From the subscription name | Resource providers screen, search for Microsoft.OperationalInsights and Microsoft.SecurityInsights. Select each one and check the Status column. If the status is NotRegistered, select Register.

    Screenshot of checking resource providers.

Access Microsoft Sentinel in managed tenants

To access your customers' Microsoft Sentinel workspaces from your own tenant, perform the following steps:

  1. Under Directory + subscription, select the delegated directories (each directory maps to a tenant). Also select the subscriptions that contain your customer's Microsoft Sentinel workspaces.

    Choose tenants and subscriptions

  2. Open Microsoft Sentinel, where you'll see all the workspaces in the selected subscriptions and can work with them seamlessly, just like any workspace in your own tenant.

Note

You can't deploy connectors in Microsoft Sentinel from a managed workspace that uses only Azure Lighthouse. You must also configure GDAP. For more details, see Microsoft Defender portal implementation guide for MSSPs.

For more information about Microsoft Sentinel, see the following articles: