{"id":20834,"date":"2021-12-07T06:15:05","date_gmt":"2021-12-07T14:15:05","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/azuregov\/?p=20834"},"modified":"2021-12-07T06:11:31","modified_gmt":"2021-12-07T14:11:31","slug":"building-and-monitoring-zero-trust-tic-3-0-workloads-for-federal-information-systems-with-microsoft-sentinel","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/azuregov\/building-and-monitoring-zero-trust-tic-3-0-workloads-for-federal-information-systems-with-microsoft-sentinel\/","title":{"rendered":"Building and monitoring Zero Trust (TIC 3.0) workloads for federal information systems with Microsoft Sentinel"},"content":{"rendered":"<p><em>This blog is co-authored by <a href=\"https:\/\/www.linkedin.com\/in\/lilidavoudian\/\" target=\"_blank\" rel=\"noopener\">Lili Davoudian<\/a>, Program Manager II; and <a href=\"https:\/\/www.linkedin.com\/in\/tjbanasik\/\" target=\"_blank\" rel=\"noopener\">TJ Banasik<\/a>, CISSP-ISSEP, ISSAP, ISSMP, Senior Program Manager of Microsoft Cloud &amp; AI Security.<\/em><\/p>\n<p><a href=\"https:\/\/youtu.be\/OVGgRIzAvCI\"><img decoding=\"async\" class=\"wp-image-20838 aligncenter\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/12\/Zero-Trust-TIC3.0-Video-Image-Dec2021-300x150.jpg\" alt=\"Image Zero Trust TIC3 0 8211 Video Image 8211 Dec2021\" width=\"721\" height=\"360\" \/><\/a><\/p>\n<p><a href=\"https:\/\/youtu.be\/OVGgRIzAvCI\"><span data-contrast=\"none\">In\u00a0this video<\/span><\/a><span data-contrast=\"none\">, we discuss the new Microsoft Sentinel: Zero Trust (TIC3.0) solution\u202fwhich provides additional functionality to empower US government customers as they incorporate a Zero Trust perspective into their architecture.<\/span><\/p>\n<p><span data-contrast=\"none\">In addition to design improvements,\u00a0we\u2019ve\u00a0improved the better-together integration with Microsoft Defender for Cloud\u202ffor\u202fassessments and\u202falerting rules to actively monitor and\u00a0alert on\u00a0compliance posture deviations across each\u202fTIC\u00a03.0\u202fcontrol family.\u202f<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The solution includes the new Zero Trust (TIC\u00a03.0) Workbook, (11) Analytics Rules, and (1) Playbook; enabling governance and compliance teams to design, build, monitor, and respond to Zero Trust (TIC\u00a03.0) requirements.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">We appreciate\u00a0all\u00a0the\u00a0positive feedback\u00a0and\u00a0input\u00a0from the government community\u00a0which resulted\u00a0in\u00a0these\u00a0updates to\u00a0our\u00a0workbook.\u00a0<\/span><a href=\"https:\/\/youtu.be\/OVGgRIzAvCI\"><span data-contrast=\"none\">Watch our demo<\/span><\/a><span data-contrast=\"none\">\u00a0to learn more.\u00a0<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Getting\u00a0started<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In addition to the video,\u00a0we\u2019re sharing\u00a0content designed to provide the foundation for designing, building, and monitoring workload compliance within Zero Trust and TIC\u00a03.0 requirements.\u00a0Here\u00a0are the steps to onboard required dependencies, enable connectors, review content, and provide feedback.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p>1.\u00a0 Onboard: <a href=\"https:\/\/docs.microsoft.com\/azure\/sentinel\/quickstart-onboard\">Microsoft Sentinel<\/a>\u00a0and <a href=\"https:\/\/docs.microsoft.com\/azure\/security-center\/security-center-get-started\">Microsoft Defender for Cloud<\/a><\/p>\n<p>2.\u00a0 <a href=\"https:\/\/docs.microsoft.com\/azure\/security-center\/update-regulatory-compliance-packages?WT.mc_id=Portal-fx#add-a-regulatory-standard-to-your-dashboard\">Add the Azure Security Benchmark and NIST SP 800-53 R5 Assessments to your dashboard<\/a><\/p>\n<p>3.\u00a0 <a href=\"https:\/\/docs.microsoft.com\/azure\/security-center\/continuous-export\">Continuously export Security Center Data to Log Analytics Workspace<\/a><\/p>\n<p>4.\u00a0 Deploy the Microsoft Sentinel Zero Trust (TIC3.0) solution<\/p>\n<ul>\n<li>Microsoft Sentinel &gt; Content Hub &gt; Select Zero Trust (TIC3.0) Solution &gt; Configure deployment options &gt; Create<\/li>\n<li>Government: Access Solution on <a href=\"https:\/\/github.com\/Azure\/Azure-Sentinel\/tree\/master\/Solutions\/ZeroTrust(TIC3.0)\">Microsoft Sentinel\u2019s GitHub Repo<\/a>. Select Deploy to Azure Government Button &gt; Configure Options &gt; Create<\/li>\n<\/ul>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/12\/Zero-Trust-TIC3.0-Image-1-Dec2021.jpg.png\"><img decoding=\"async\" class=\"wp-image-20836 aligncenter\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/12\/Zero-Trust-TIC3.0-Image-1-Dec2021.jpg-300x95.png\" alt=\"Image Zero Trust TIC3 0 8211 Image 1 8211 Dec2021 jpg\" width=\"505\" height=\"160\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/12\/Zero-Trust-TIC3.0-Image-1-Dec2021.jpg-300x95.png 300w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/12\/Zero-Trust-TIC3.0-Image-1-Dec2021.jpg.png 408w\" sizes=\"(max-width: 505px) 100vw, 505px\" \/><\/a><\/p>\n<p>5.\u00a0 Review the Zero Trust (TIC 3.0) Workbook<\/p>\n<ul>\n<li>Microsoft Sentinel &gt; Workbooks &gt; Select Zero Trust (TIC 3.0)<\/li>\n<\/ul>\n<p>6.\u00a0 Review\/Enable Zero Trust (TIC 3.0) Analytics Rules<\/p>\n<ul>\n<li>Microsoft Sentinel &gt; Analytics &gt; Search Zero Trust (TIC 3.0)<\/li>\n<\/ul>\n<p>7.\u00a0 Review Playbook Automation<\/p>\n<ul>\n<li>Microsoft Sentinel &gt; Automation &gt; Active playbooks &gt; Search Notify-GovernanceComplianceTeam &gt; Enable<\/li>\n<li>Create Automation Rule<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Analytics &gt; Search Zero Trust &gt; Edit &gt; Automated Response &gt; Add new &gt; Select Actions: Run Playbook &gt; Select Notify-GovernanceComplianceTeam and configure automation options &gt; Review &gt; Save &gt; Mirror configuration across all Zero Trust (TIC3.0) analytics rules.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/12\/Zero-Trust-TIC3.0-Image-2-Dec2021.jpg.png\"><img decoding=\"async\" class=\"wp-image-20837 aligncenter\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/12\/Zero-Trust-TIC3.0-Image-2-Dec2021.jpg-300x268.png\" alt=\"Image Zero Trust TIC3 0 8211 Image 2 8211 Dec2021 jpg\" width=\"505\" height=\"451\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/12\/Zero-Trust-TIC3.0-Image-2-Dec2021.jpg-300x268.png 300w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/12\/Zero-Trust-TIC3.0-Image-2-Dec2021.jpg.png 418w\" sizes=\"(max-width: 505px) 100vw, 505px\" \/><\/a><\/p>\n<p>8.\u00a0 <span style=\"font-size: 1rem;\">Review the content and provide feedback through the <\/span><a style=\"background-color: #f7f7f9; font-size: 1rem;\" href=\"https:\/\/forms.office.com\/r\/Xe5UWtv23H\">survey<\/a><\/p>\n<p><b><span data-contrast=\"auto\">Learn\u00a0more about Zero Trust (TIC 3.0) with Microsoft Security<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/security\/zero-trust\/\">Zero Trust Guidance Center<\/a><\/li>\n<li><a href=\"http:\/\/www.aka.ms\/ZeroTrust\">Embracing Zero Trust<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>See how to build and monitor Zero Trust (TIC 3.0) workloads for Federal Information Systems with the Microsoft Sentinel solution.<\/p>\n","protected":false},"author":62910,"featured_media":20838,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2,1,29],"tags":[75,95,315,502,573,2404],"class_list":["post-20834","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-announcements","category-azuregov","category-security","tag-azure","tag-azure-government","tag-government","tag-security","tag-video","tag-zero-trust"],"acf":[],"blog_post_summary":"<p>See how to build and monitor Zero Trust (TIC 3.0) workloads for Federal Information Systems with the Microsoft Sentinel solution.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/20834","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/users\/62910"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/comments?post=20834"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/20834\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media\/20838"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media?parent=20834"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/categories?post=20834"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/tags?post=20834"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}