Microsoft Azure Lighthouse: Sentinel Across Multi-Tenant Environments.
Securely manage Microsoft Sentinel across multiple tenants using Azure Lighthouse delegation and RBAC, ideal for MSSPs and large enterprises.

Search for a command to run...
Securely manage Microsoft Sentinel across multiple tenants using Azure Lighthouse delegation and RBAC, ideal for MSSPs and large enterprises.

No comments yet. Be the first to comment.
Designing a Resilient Linux Application Stack on Windows Infrastructure.

A deep dive on ClickFix, mapping fake CAPTCHA lures to endpoint code execution, covering investigation, response, and preventative controls.

Overview. Prerequisites. Join types. LAPS is only supported on: Microsoft Entra joined devices. Microsoft Entra hybrid joined devices. Microsoft Entra registered devices are not supported. License requirements. LAPS is available to all customers ...

A complete analysis of a compromised identity in Microsoft 365, covering key tactics, techniques, and procedures.

Streamlining Level RMM deployment across Windows devices using PowerShell and a Microsoft Intune deployment script.

Ciaran Doherty's SecOps Blog
24 posts
Security teams within Managed Security Service Providers (MSSPs) or multi-brand organisations often require visibility into several isolated Microsoft Sentinel instances. Without centralisation, analysts must switch between portals or accounts—inefficient, error-prone, and lacking holistic visibility.
Azure Lighthouse solves this by delegating access to customer tenants using Azure Resource Manager (ARM), allowing a single security operations team to manage incidents, hunting, workbooks, and automation across all tenants.
Security operations teams often face challenges when managing multiple isolated Sentinel deployments. Without a centralised approach, analysts must log into separate portals or switch accounts, reducing efficiency and increasing the risk of misconfigurations or oversight.
Azure Lighthouse addresses this by enabling secure, delegated access to customer tenants. With proper configuration, it allows central SOC teams to investigate incidents, run queries, and manage Sentinel workspaces without direct tenant access or identity switching.
Using Azure Lighthouse with Microsoft Sentinel provides several operational advantages. It allows for centralised security monitoring, role-based access control using Azure RBAC, streamlined analyst workflows, and consistent deployment of processes and automation. Analysts can interact with delegated Sentinel environments as if they were part of their own tenant, reducing friction and increasing responsiveness to threats.
With Lighthouse in place, a central SOC team can monitor multiple environments simultaneously. Analysts can perform triage on incidents, investigate threats using Kusto Query Language (KQL), and trigger Logic App playbooks to respond to alerts.
Although each Sentinel workspace operates independently in terms of data and analytics rules, centralised access simplifies day-to-day security operations and governance.
There are some limitations to be aware of. Data ingestion and retention remain within the customer tenant and are billed accordingly. Analytics rules and hunting queries must be deployed individually per tenant; there is no global rule propagation across workspaces.
Workbooks, playbooks, and custom connectors are also isolated and must be manually deployed or automated via DevOps processes. Additionally, role scoping should always adhere to the principle of least privilege.
Deploying Microsoft Sentinel in multi-tenant environments can introduce significant operational complexity if not centralised properly. Azure Lighthouse provides a scalable, secure, and compliant method for centralising access to Microsoft Sentinel workspaces across tenant boundaries.
For MSSPs and enterprise security teams, this integration enables streamlined investigations, consistent automation, and enhanced visibility without compromising on control or security.
If you require a downloadable version of the ARM templates or diagrams to support this article, please get in touch or refer to Microsoft’s Azure Lighthouse documentation.