Microsoft Sentinel Implementation — SharePoint File Access & Permission Monitoring
This 5-day, $1,500 service implements a focused Microsoft Sentinel configuration for organizations that need visibility into access to specific files or folders in SharePoint Online, OneDrive, and Microsoft Teams. IT Partner sets up Microsoft Sentinel, configures required connectors, analytics rules, automation rules, and Azure Logic apps so agreed file access or permission-change events can generate notifications and Microsoft Sentinel incidents for investigation.
What this engagement is
Microsoft Sentinel is a cloud-native SIEM solution powered by AI and automation that collects and analyzes security data from multiple sources. This service focuses on detecting and notifying stakeholders when specified files or folders in SharePoint Online, OneDrive, and Microsoft Teams are opened, downloaded, or affected by permission changes. For example, if a system administrator adds himself as a site member to access sensitive data, the configured solution can send an email or Teams message and create an incident in Microsoft Sentinel for further analysis. This service provides detection and notification; it does not prevent unauthorized access. Service details: SKU ITPWW090SECOT; price $1,500; duration 5 days; manager Roman Sotnik. Published date: 2022-12-23. Products: azure, microsoft 365, office 365. Type: Security and Protection. The plan may vary depending on your needs.
Success criteria
What you receive
How the work unfolds
Conduct the kickoff meeting.
Gather the required information.
Plan and approve rules.
Provision the appropriate subscriptions.
Implement the solution.
Perform testing and demonstration.
Prerequisites
Who does what
IT Partner
- Gather all the required information to implement the solution.
- Set up Microsoft Sentinel and configure the required connectors.
- Enable custom analytics rules to catch the required events.
- Configure automation rules and Azure Logic apps for notification purposes.
- Performs tests.
Your team
- Provide access to tenant and Azure subscription.
- Provide the information required for rule configuration.
What's not included
Limitations & technical notes
Frequently asked questions
What does the Microsoft Sentinel Implementation for SharePoint file access monitoring include?
This service includes setup of a focused Microsoft Sentinel configuration to monitor agreed file access and permission-change events in SharePoint Online, OneDrive, and Microsoft Teams. IT Partner configures required connectors, custom analytics rules, automation rules, and Azure Logic Apps so selected events can generate notifications and Microsoft Sentinel incidents for investigation.
What types of SharePoint, OneDrive, or Teams events can this service monitor?
The service focuses on detecting configured events such as opening or downloading specified files or folders and making permission changes that affect those items. For example, it can notify stakeholders and create a Microsoft Sentinel incident if an administrator adds themselves as a site member to access sensitive data, provided that scenario is included in the approved rule configuration.
Does this service prevent unauthorized access to sensitive files?
No, this service provides detection and notification, not access prevention. Microsoft Sentinel can help identify and escalate configured file access or permission-change events, but preventing unauthorized access would require other controls outside this service scope.
Is Microsoft Sentinel included in the service?
The service includes configuring Microsoft Sentinel for the agreed monitoring scenarios, including connectors, analytics rules, automation rules, and notifications. The client must provide access to the tenant and Azure subscription, and IT Partner should confirm whether a Microsoft Sentinel instance already exists or must be provisioned during the engagement.
How long does the implementation take?
The stated duration for this service is 5 days. The engagement includes kickoff, information gathering, rule planning and approval, subscription provisioning as needed, implementation, testing, and demonstration.
How much does this Microsoft Sentinel implementation cost?
The stated price for this service is $1,500. The service plan may vary depending on the client’s needs, so any changes to scope, scenarios, or requirements should be confirmed with IT Partner before work begins.
What are the prerequisites for this service?
The client must provide access to the Microsoft 365 tenant and Azure subscription, along with the information needed to configure the monitoring rules. The service success criteria also reference an Azure subscription with a Microsoft Sentinel instance, so clients should confirm with IT Partner whether Sentinel must already be deployed before kickoff.
What information does the client need to provide for rule configuration?
The client needs to identify the files, folders, sites, users, events, and notification scenarios that should be monitored. This information is required because IT Partner configures custom analytics and automation rules around the agreed scenarios rather than applying a generic monitoring policy to all content.
What is IT Partner responsible for during the engagement?
IT Partner is responsible for gathering required implementation information, setting up Microsoft Sentinel, configuring required connectors, enabling custom analytics rules, configuring automation rules and Azure Logic Apps, and performing tests. IT Partner also demonstrates the implemented scenarios after testing is complete.
What is the client responsible for during the engagement?
The client is responsible for providing access to the tenant and Azure subscription and supplying the information needed for rule configuration. The client also participates in approving the planned rules and confirming that the tested scenarios meet the agreed requirements.
What notifications can be configured by this service?
The service can configure notifications for agreed scenarios, such as downloading or opening a specified file or making permission changes to selected content. Notifications may be delivered through configured automation such as email or Microsoft Teams messages, depending on the approved design and Azure Logic Apps configuration.
Will Microsoft Sentinel incidents be created automatically?
Yes, for configured scenarios, the service enables Microsoft Sentinel incidents to support additional investigation. Incidents are created based on the custom analytics rules and automation configured during the engagement, not for every possible SharePoint, OneDrive, or Teams activity by default.
Does this service monitor all files across SharePoint, OneDrive, and Teams?
The service is designed to monitor access and permission changes for specified files or folders, not necessarily every file across the entire tenant. The exact monitoring scope depends on the scenarios and rule requirements approved during the planning phase.
Is there downtime or business disruption during implementation?
The provided service scope does not identify planned downtime. Because the work centers on Microsoft Sentinel configuration, connectors, analytics rules, automation rules, and testing, any operational impact should be confirmed with IT Partner based on the client’s tenant and Azure environment.
What happens during the 5-day engagement?
The engagement starts with a kickoff meeting, followed by information gathering and planning of the required rules. IT Partner then provisions appropriate subscriptions as needed, implements the Microsoft Sentinel configuration, performs testing, and demonstrates the configured monitoring and notification scenarios.
What is tested before the service is considered complete?
IT Partner tests the desired scenarios and tasks to confirm that the configured rules, notifications, and incidents work as expected. Completion is based on Microsoft Sentinel being configured according to the client’s requirements and the agreed scenarios being successfully tested and confirmed.
What is not included in this service?
This service does not include prevention of unauthorized access, Azure Information Protection implementation, or Data Loss Prevention policy implementation. Those controls are separate from the Microsoft Sentinel detection and notification scope and may require additional planning, complexity, and end-user participation.
Can this service replace Data Loss Prevention or Azure Information Protection?
No, this service should not be treated as a replacement for Data Loss Prevention or Azure Information Protection. It detects and notifies on configured access or permission-change events, while DLP and Azure Information Protection are separate services focused on policy enforcement, classification, and protection scenarios.
What happens after the implementation is completed?
After completion, the client receives a tested Microsoft Sentinel configuration for the agreed file access and permission-change monitoring scenarios. The service includes demonstration of the implemented solution, but ongoing monitoring, continuous monitoring, 24/7 support, ongoing maintenance, tuning, or additional scenarios are not included by default and are available as optional extra-cost add-ons through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement when contracted separately with IT Partner.