Microsoft Sentinel with Azure Marketplace
Quick setup instructions for integrating Keeper SIEM events with Microsoft Sentinel through the Azure Marketplace
Overview

1. Select Subscription and Plan

2. Configure Basic Project Details
3. Review and Create


4. Access Content Hub in Microsoft Sentinel

5. Manage Installed Content
6. View Installed Content Items

7. Generate Entra Configuration

8. Configure Keeper Admin Console
Logs Ingestion URL Format Example:

9. Optional: Enable Analytics Rule - Master Password Changed

Step 1. Access Installed Content
Step 2. Open the Rule Template
Step 3. Configure General Settings
Step 4. Define Rule Logic
Step 5. Configure Incident Settings
Step 6. Optional – Add Automated Response
Step 7. Review and Create
10. Optional: Enable Analytics Rule – User MFA Changed

Step 1. Access Installed Content
Step 2. Open the Rule Template
Step 3. Configure General Settings
Step 4. Define Rule Logic
Step 5. Configure Incident Settings
Step 6. Optional – Add Automated Response
Step 7. Review and Create
11. Optional: Enable Workbook – Keeper Security Dashboard

Step 1. Access Installed Content
Step 2. Save the Workbook Template
Step 3. Open the Saved Workbook
Step 4. Visualize Keeper Events
✅ Success
Last updated
Was this helpful?

