Deploy the Microsoft Sentinel module: one consent sets up Azure Lighthouse and incident streaming so you can manage analytics rules and hunt with KQL.
The Microsoft Sentinel module connects ContraForce to your Microsoft Sentinel workspace, enabling centralized monitoring, real-time incident streaming, and the ability to act on Sentinel security data directly from the ContraForce platform.
What this module adds: Sentinel incident ingestion, the workspace’s Content Management System (CMS) for detection rules, email notifications, log search, and Azure Lighthouse cross-tenant management.
Who is this for? Workspace Owners deploying the Sentinel module from the Modules tab of a workspace in the ContraForce portal.
Global Administrator or Privileged Role Administrator — either can grant admin consent for ContraForce enterprise applications (service principals). Cloud Application Administrator and Application Administrator cannot grant consent for Microsoft Graph application permissions.
Workspace Role
ContraForce Workspace Role: Owner
Subscription Owner
Microsoft Subscription Permission: Owner — required to deploy the supporting Azure infrastructure
Active Sentinel workspace in your Azure subscription
Log Analytics Workspace
The workspace linked to your Sentinel deployment
Resource Group Access
Ability to create resources in the subscription
No Conflicting Policies
Azure Policy must allow Lighthouse delegations
If you don’t have Subscription Owner permissions, the Azure deployment will fail. Contact your Azure administrator to obtain the necessary access or have them complete the deployment with you.
Consent model. ContraForce enterprise applications are consented with application (app-only) Microsoft Graph permissions. Admin consent for Microsoft Graph application permissions must be granted by a Global Administrator or a Privileged Role Administrator — Cloud Application Administrator and Application Administrator cannot grant it. The role is required for the one-time consent only and is not retained; activate it just-in-time with Privileged Identity Management (PIM) and deactivate afterward.Because actions run as the application (no signed-in user required), operator control is enforced through Gamebook approval gates — only Workspace Owners can approve high-impact actions — and a complete audit trail in the Gamebooks History page.
When you deploy the Sentinel module, ContraForce automatically provisions the Azure resources needed for integration. You do not deploy Lighthouse or the streaming infrastructure as separate manual steps — they are created as part of module deployment.
Component
Purpose
Azure Lighthouse
Cross-tenant delegation for multi-tenant management
Apollo Resource Group
Infrastructure for incident streaming
Logic App
Streams Sentinel incidents to ContraForce in real-time
Automation Rule
Triggers the Logic App when incidents are created/updated
Role Assignments
Grants ContraForce service principals access to Sentinel
Azure Resources Reference
Complete list of all deployed resources with details
Consent is a single action per module on the Modules tab. Clicking Consent grants everything ContraForce needs for this module in one step.
1
Click Consent
On the Microsoft Sentinel module, click Consent.
2
Sign In as Global Administrator
A Microsoft consent window opens. Sign in with Global Administrator credentials.
3
Accept Permissions
Review the requested permissions and click Accept to consent on behalf of your organization.
4
Deploy the Supporting Azure Infrastructure
Consenting the module automatically deploys the supporting Azure resources — Azure Lighthouse delegation, the Apollo resource group, and the Sentinel-side Logic App and automation rule. You may be prompted to sign in with an account that has Subscription Owner permissions so the resources can be created.
Apollo resources are created in the customer’s Azure subscription. Standard Azure charges may apply for Logic App executions.
Manage this workspace’s analytics rules in its Content Management System (CMS):
1
Open the CMS
Open Workspaces → [workspace] → Modules and select the flask icon on Microsoft Sentinel. The flask icon on the workspace’s card in the Workspace Center opens the same page.
2
Review the Rules
The Detection Rules page opens on the Sentinel Analytical Rules tab. Filter by severity and status, or search by name.
3
Add or Change Rules
Select Add rule to create an analytics rule, or select rules and use Actions to enable, disable, or delete them in bulk.
To manage the same detection content across many workspaces as versioned repositories, use the Content Management Center instead.
Content Management System
Manage a workspace’s Sentinel analytics rules and Defender custom detections