Deploy the Microsoft Sentinel module to enable SIEM integration, real-time incident streaming, detection rules via CMS, and advanced threat hunting capabilities.
The Microsoft Sentinel module connects ContraForce to your Microsoft Sentinel workspace, enabling centralized monitoring, real-time incident streaming, and the ability to act on Sentinel security data directly from the ContraForce platform.
What this module adds: Sentinel incident ingestion, Content Management System (CMS) for detection rules, email notifications, log search, and Azure Lighthouse cross-tenant management.
Who is this for? Workspace Admins and Data Source Admins deploying the Sentinel module from the Modules tab of a workspace in the ContraForce portal.
Global Administrator — required to grant admin consent for ContraForce enterprise applications (service principals). Cloud Application Administrator and Application Administrator cannot grant consent for Microsoft Graph application permissions.
Workspace Role
ContraForce Workspace Role: Owner or Admin
Subscription Owner
Microsoft Subscription Permission: Owner — required to deploy the supporting Azure infrastructure
Active Sentinel workspace in your Azure subscription
Log Analytics Workspace
The workspace linked to your Sentinel deployment
Resource Group Access
Ability to create resources in the subscription
No Conflicting Policies
Azure Policy must allow Lighthouse delegations
If you don’t have Subscription Owner permissions, the Azure deployment will fail. Contact your Azure administrator to obtain the necessary access or have them complete the deployment with you.
Consent model. ContraForce enterprise applications are consented with application (app-only) Microsoft Graph permissions. Admin consent for Microsoft Graph application permissions must be granted by a Global Administrator — Cloud Application Administrator and Application Administrator cannot grant it. Global Administrator is required for the one-time consent only and is not retained; activate it just-in-time with Privileged Identity Management (PIM) and deactivate afterward.Because actions run as the application (no signed-in user required), operator control is enforced through Gamebook approval gates — only Workspace Owners can approve high-impact actions — and a complete audit trail in the Gamebooks History page.
When you deploy the Sentinel module, ContraForce automatically provisions the Azure resources needed for integration. You do not deploy Lighthouse or the streaming infrastructure as separate manual steps — they are created as part of module deployment.
Component
Purpose
Azure Lighthouse
Cross-tenant delegation for multi-tenant management
Apollo Resource Group
Infrastructure for incident streaming
Logic App
Streams Sentinel incidents to ContraForce in real-time
Automation Rule
Triggers the Logic App when incidents are created/updated
Role Assignments
Grants ContraForce service principals access to Sentinel
Azure Resources Reference
Complete list of all deployed resources with details
Consent is a single action per module on the Modules tab. Clicking Consent grants everything ContraForce needs for this module in one step.
1
Click Consent
On the Microsoft Sentinel module, click Consent.
2
Sign In as Global Administrator
A Microsoft consent window opens. Sign in with Global Administrator credentials.
3
Accept Permissions
Review the requested permissions and click Accept to consent on behalf of your organization.
4
Deploy the Supporting Azure Infrastructure
Consenting the module automatically deploys the supporting Azure resources — Azure Lighthouse delegation, the Apollo resource group, and the Sentinel-side Logic App and automation rule. You may be prompted to sign in with an account that has Subscription Owner permissions so the resources can be created.
Apollo resources are created in the customer’s Azure subscription. Standard Azure charges may apply for Logic App executions.