Microsoft Sentinel: Things to know before you start migrate to a new resource group in the same tenant

Good morning fellow friends. Hope you are having a fresh start of the day. I would like to write about my journey on Microsoft Sentinel during migration phase.

Microsoft Sentinel is SIEM and SOAR security solution providing corporate the flexibility and better visibility in terms of managing security logs from Microsoft security products and third-party products and threats prevention.

Let’s begin…

Current situation of what I have in my Microsoft Sentinel is,

  1. Solution running on a trial subscription
  2. Resource group 1
  3. Some queries
  4. Some connectors (Microsoft and third-party)
  5. Some Logic app
  6. Some Automation rules

I would like to migrate from the trial subscription to the CSP subscription, this migration would likely be perform by your license provider and request them to provide the appropriate permission so that you can perform your management on the Microsoft Sentinel in the new subscription.

Note: This is not migrating from one tenant to another tenant.

The highlighted in RED are the ones you would need to perform backup, making sure the connection is up and the authentication is establish.

The New resource group has the current resource group resources,

  1. Solution is now running on paid subscription
  2. Resource group 2 (You would need to create a new resource group)
  3. Some queries (Custom queries needs to be regenerate)
  4. Some connectors (Make sure connectors with log forwarder is working else you would have to reestablish)
  5. Some Logic app (Reauthenticate your log workflow)
  6. Some Automation rules
Example of warning in Logic app designer

That is all you would need to know in advance before you start your migration. Hopefully you would find this article knowledgeable for you if you are heading to migrating your Microsoft Sentinel to a new subscription. Is never a waste of time if you are used to double checking or triple checking that all the resources are connecting and working well after migrated.

References:

  1. https://docs.microsoft.com/en-us/azure/azure-resource-manager/management/move-resource-group-and-subscription

Author: sabrinaksy

Just an ordinary lady who love what she does best.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

%d bloggers like this: