Streaming Data from Microsoft Purview to Microsoft Sentinel: Unlocking the Potential of Information Protection
🔐Streaming Data from Microsoft Purview to Microsoft Sentinel: Unlocking the Potential of Information Protection🔐
With the Microsoft Purview Information Protection connector, you can stream auditing events generated from unified labeling clients and scanners. The data is then emitted to the Microsoft 365 audit log for central reporting in Microsoft Sentinel.
📝With the connector, you can:
✔️Track adoption of labels, explore, query, and detect events.
✔️Monitor labeled and protected documents and emails.
✔️Monitor user access to labeled documents and emails, while tracking classification changes.
✔️Gain visibility into activities performed on labels, policies, configurations, files and documents. This visibility helps security teams identify security breaches, and risk and compliance violations.
✔️Use the connector data during an audit, to prove that the organization is compliant.
📝To get started, you only need:
✔️The Microsoft Sentinel solution enabled.
✔️A defined Microsoft Sentinel workspace.
✔️A valid license to Microsoft Purview Information Protection.
✔️Enabled Sensitivity labels for Office and enabled auditing.
✔️The Global Administrator or Security Administrator role on the workspace.
Are you ready to protect your data and take your compliance to the next level?
📝Microsoft Docs: https://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-purview
#microsoft #dlp #informationprotection #datalossprevention #purview #microsoft365 #soc #siem #microsoftsentinel #data #MSPartnerUK