You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As you have heard or seen in the community call on 29th January 2025 we are considering the future of Sentinel in ALZ and whether we need to change the architecture or not.
We are looking for your input on what your are doing or seeing in the wild today, to help shape the changes to ALZ (if required) so it is based on real-world deployments 👍
Questions to answer (we want to hear from you 🫵 - reply in the comments below)
Do we need a separate LAW dedicated to Sentinel?
We think so, mainly due to platform logs increasing costs and causing noise from required security logs
Even though this will lead to some double logging into both LAWs (Platform + Sentinel)
Often organizations have separate Security teams requesting/driving for this
Product Group guidance leans to single workspace by default, see here.
Do we need a separate “Security” platform Subscription?
Can it not just live in Management?
Does this need to be in a separate “Security” Management Group?
Could it just live inside of Platform > Management?
Does it need to be somewhere else?
RBAC is suggested to be done at Subscription scope, not MG.
MGs are primarily for policy assignments
Should ALZ deploy anything Sentinel related? Or should we just just provide placement guidance and platform pre-reqs?
e.g. Should we just deploy and move a subscription to a management group that ALZ creates?
This then allows security teams to deploy and mange sentinel however they wish
Also, they then work with the ALZ/Platform team to get any additional RBAC and policy assignments created as they see fit?
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
-
As you have heard or seen in the community call on 29th January 2025 we are considering the future of Sentinel in ALZ and whether we need to change the architecture or not.
We are looking for your input on what your are doing or seeing in the wild today, to help shape the changes to ALZ (if required) so it is based on real-world deployments 👍
Questions to answer (we want to hear from you 🫵 - reply in the comments below)
Beta Was this translation helpful? Give feedback.
All reactions