Azure / Azure-Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Home Page:https://azure.microsoft.com/en-us/services/azure-sentinel/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Tenant-based Microsoft Defender for Cloud (Preview) installs but does not exist

fujiant opened this issue · comments

Describe the bug
I have deployed a Sentinel all in one deployment that installed and connected the legacy Defender for Cloud subscription based connector. I tried to install the latest Defender for Cloud solution from Content Hub, but the install ended up in an error because the legacy connector already existed. I removed the legacy connector and tried a reinstall from Content Hub and it seemingly worked, but I get an error that says "Data Connector Not Found - The data connector that corresponds to the data type MicrosoftDefenderForCloudTenantBased could not be found" when I try to open the data connector page for the tenant-based preview connector.

I uninstalled the solution and its components from Content Hub blade, and also deleted all Defender for Cloud connectors from Data Connector blade, and then proceeded to install again from Content Hub. The issue still remains, I get an error "Data Connector Not Found - The data connector that corresponds to the data type MicrosoftDefenderForCloudTenantBased could not be found" when trying to access the data connector page of the tenant based connector.

The legacy data connector seems to work without issues while the tenant based does not.

To Reproduce
Steps to reproduce the behavior:

  1. Deploy a sentinel all in one build that enables the subscription based legacy data connector for Defender for Cloud
  2. Try to install Defender for Cloud solution from Content Hub, ends up in error
  3. Disconnect and delete Defender for Cloud legacy connector
  4. Try to reinstall from Content Hub
  5. Both Preview and Legacy connector show up in the Data Connectors blade of Sentinel
  6. Accessing the Preview Connector page results in an error
  7. Deleting the data connectors and deleting from Content Hub and starting over do not fix this.

Expected behavior
Data Connector page for the Tenant based preview connector accessible in the Sentinel UI.

Screenshots
If applicable, add screenshots to help explain your problem.

Desktop (please complete the following information):

  • OS: Windows 10
  • Browser Chrome
  • Version Latest

Hi @fujiant, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 28-05-2024 Thanks!

Hi @fujiant, could you please try it once using custom deploy the Solution MainTemplate and check whether your issue get resolved.
Sharing the MainTemplate and Custom deployment steps-

Custom Deployment - Custom Deployment of the Solution - Copy.docx

Main template: - mainTemplate.json

Thanks!

I checked the situation today and for some reason it now works. I have done nothing on my end apart from leaving it as is. Seems that there was some sort of an Azure backend delay?

@fujiant, Maybe the solution does not get install/delete properly into the workspace.
As your issue has resolved, closing this issue. If you still need support for this issue, feel free to re-open it any time. Thank you for your co-operation.