Best approach to centralize Microsoft Defender for Cloud alerts in Microsoft Sentinel

Suji Kim (김수지) 80 평판 포인트
2026-04-15T08:27:06.4766667+00:00

We have the following setup:

Tenant A

  • Microsoft Sentinel is deployed
  • Acts as the HQ SOC

Tenant B

  • Microsoft Defender for Cloud (MDC) is enabled
  • Security alerts are generated from MDC

Operational goal We want to centrally monitor MDC security alerts generated in Tenant B from the SOC in Tenant A. Our primary objective is centralized security alert monitoring and investigation, rather than log retention or redesigning the SIEM architecture.

We are currently considering the following two approaches:

  1. Using Azure Lighthouse for cross-tenant security alert monitoring
  2. Exporting MDC security alerts via Event Hub and ingesting them into Microsoft Sentinel in Tenant A

From a cost and operational efficiency perspective, which approach is considered best practice and recommended by Microsoft for this use case?

Any guidance on the recommended architecture and typical usage scenarios for each option would be appreciated.

Azure Lighthouse
Azure Lighthouse

파트너와 고객을 위한 안전한 관리되는 서비스와 액세스 제어를 제공하는 Azure 서비스입니다.

댓글 0개 설명 없음

질문 작성자가 수락한 답변
Rukmini 43,995 평판 포인트 Microsoft 외부 직원 중재자
2026-04-15T09:10:24.4333333+00:00

안녕하세요 Suji Kim (김수지)

권장되는 접근 방식은 Azure Lighthouse와 클라우드 커넥터용 네이티브 Defender를 함께 사용하는 것입니다.

  • Sentinel에 실시간 경고 및 사건 동기화 기능을 제공합니다.
  • 운영 오버헤드가 매우 적습니다. 특별한 파이프라인이 필요하지 않습니다.

경제적입니다. Sentinel 데이터 수집 수수료만 발생합니다.

  • 활성화 시 양방향 사건 상태 업데이트가 가능합니다.

Lighthouse 프로젝트가 실행 불가능할 경우의 대안: 이벤트 허브 내보내기 + 사용자 지정 가져오기

  • 특정 처리 요구 사항 또는 제한된 네트워크를 준수해야 합니다.

운영 비용 및 오버헤드 증가(이벤트 허브 수신 + 함수/로직 앱).

  • 알림 상태가 자동으로 동기화되지 않습니다.

영어에서 번역하는 중이라 문법 오류가 있을 수 있습니다. 양해 부탁드립니다!

궁금한 점이 있으면 언제든지 문의해 주세요!

이 대답이 도움이 되었나요?

1명이 이 답변이 도움이 된다고 생각했습니다.
댓글 0개 설명 없음

0 추가 답변

정렬 기준: 최신순

답변

질문 작성자는 답변을 '승인됨'으로 표시하고, 중재자는 답변을 '추천됨'으로 표시할 수 있습니다. 이를 통해 사용자는 해당 답변이 작성자의 문제를 해결했다는 것을 알 수 있습니다.