Skip to content

Commit 2348776

Browse files
Merge pull request #311838 from MicrosoftDocs/main
Auto Publish – main to live - 2026-02-16 06:00 UTC
2 parents 580a12d + bfacc2a commit 2348776

4 files changed

Lines changed: 17 additions & 14 deletions

File tree

articles/azure-vmware/ecosystem-disaster-recovery-vms.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ You can find more information about their solutions in the following links:
3030
| Supported Version in Azure VMware Solution Gen 1 | Supported Version in Azure VMware Solution Gen 2 | Links | Support |
3131
|-------------------------------------------|-------------------------------------------|------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------|
3232
| VMware Live Site Recovery 9.0.2.1 | VMware Live Site Recovery 9.0.2.1 | [Deploy VMware Live Site Recovery](/azure/azure-vmware/disaster-recovery-using-vmware-site-recovery-manager) | Azure VMware Solution owns only install, Uninstall & Upgrade of Live Site Recovery. Customers should create Broadcom support tickets for all other areas. |
33-
| Zerto 10.0 U7 GA| Zerto vSphere APIs for IO (VAIO) Timeline - TBD | [Deploying Zerto on Azure VMware Solution](https://help.zerto.com/category/AVS) | All Zerto related issues and RunCommand errors, Customers are requested to reach [Zerto Support](https://www.zerto.com/myzerto/support/create-case/). |
33+
| Zerto 10.8 GA| Zerto Timeline - TBD | [Deploying Zerto on Azure VMware Solution](https://help.zerto.com/category/AVS) | All Zerto related issues and RunCommand errors, Customers are requested to reach [Zerto Support](https://www.zerto.com/myzerto/support/create-case/). |
3434
| JetStream version: 5.0 GA | JetStream version: 5.0 GA | [Deploy JetStream](https://www.jetstreamsoft.com/2020/09/28/disaster-recovery-for-avs/) | All support—including install, uninstall, upgrade, configuration, replication—is handled by the JetStream support team. Contact [JetStream Support](https://jetstreamsoft.com/about/contact/). |
3535
|Veeam Backup & Replication 12 for VCD Azure VMware Solution |Timeline - TBD | [Veeam Backup for VMware Cloud Director on Azure VMware Solution](https://helpcenter.veeam.com/docs/backup/vsphere/vcloud_director_backup.html?ver=120) |Veeam Backup and Recovery solution for Azure VMware Solution supports VMware Cloud Director multi-tenancy|
3636
|Refer to Backup Recovery Partner Compatibility Guidance |Refer to Backup Recovery Partner Compatibility Guidance | [Backup solutions for Azure VMware Solution VMs](/azure/azure-vmware/ecosystem-back-up-vms) | Kindly reach out to the Backup and Recovery Product team for all support cases. |
@@ -45,12 +45,12 @@ Customers aren't permitted to open Microsoft support tickets for partner product
4545

4646
| Solution | Limitations / Unsupported Features |
4747
|---------------------|------------------------------------------------------------------------------------------------------------------------------|
48-
| **VMware Live Site Recovery** | Array-based replication and storage policy protection groups <br> VMware vVOLs Protection Groups<br> VMware SRM IP customization using SRM command-line tools <br> Shared Site Recovery (One-to-Many and Many-to-One topologies) <br> Custom VMware SRM plug-in identifier or extension ID <br> Encrypted VMs unsupported <br> Enhanced replication supported in Gen2 only<br> VMware Live Site Recovery only supports vSAN datastores, due to a supportability limitation from Broadcom<br> Stretched cluster is not supported|
49-
| **Zerto on Azure VMware Solution** | Zerto supports version Zerto 10.0 U7 onwards <br> Zerto VAIO currently does not support the version upgrade or hotfix <br> DNS and network configuration changes for Zerto Virtual Machine aren't supported after installation.<br> Azure resource group modifications aren't supported after Zerto installation.<br> SSH or web console access for ZVML Virtual machine is restricted.<br> Service account credentials aren't shared with customers<br> A minimum of four hosts per cluster is required.<br> Backup and Snapshot features are unavailable for ZVML VM. <br> Customers are advised to coordinate directly with Zerto for timelines any fixes<br> Stretched cluster is not supported|
48+
| **VMware Live Site Recovery** | Array-based replication and storage policy protection groups <br> VMware vVOLs Protection Groups<br> VMware SRM IP customization using SRM command-line tools <br> Shared Site Recovery (One-to-Many and Many-to-One topologies) <br> Custom VMware SRM plug-in identifier or extension ID <br> Encrypted VMs unsupported <br> Enhanced replication supported in Gen2 only<br> Azure VMware Solution-Live Site Recovery currently supports vSAN datastores. Support for external datastores is under testing.<br> Currently, Live Site Recovery for Stretched cluster is not supported|
49+
| **Zerto on Azure VMware Solution** | Zerto supports version Zerto 10.8 onwards<br> DNS and network configuration changes for Zerto Virtual Machine aren't supported after installation.<br> Azure resource group modifications aren't supported after Zerto installation.<br> SSH or web console access for ZVML Virtual machine is restricted.<br> Service account credentials aren't shared with customers<br> A minimum of four hosts per cluster is required.<br> Backup and Snapshot features are unavailable for ZVML VM. <br> Customers are advised to coordinate directly with Zerto for timelines any fixes<br> Stretched cluster is not supported|
5050
| **JetStream on Azure VMware Solution**| Requires a minimum of four hosts per cluster for upgrade |
5151
| **Backup and Recovery Partners**|[Azure VMware Solution third Party BCDR](/azure/azure-vmware/ecosystem-back-up-vms) has been tested with the cloudadmin role. Azure VMware Solution can't provide more than [Cloudadmin Privilege](/azure/azure-vmware/architecture-identity). For further support, Contact the respective BCDR partners directly|
5252

5353

5454

5555

56-
Last Updated: **October 2025** – Updated monthly with the latest information. Visit Partner onboarding sites for timelines and details. Partners keep their products up to date.
56+
Last Updated: **February 2026** – Updated monthly with the latest information. Visit Partner onboarding sites for timelines and details. Partners keep their products up to date.

articles/sentinel/datalake/sentinel-mcp-billing.md

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,8 @@ ms.custom: references_regions
1414

1515
# Understand Microsoft Sentinel MCP server pricing, limits, and availability
1616

17+
> [!IMPORTANT]
18+
> Some information relates to a prerelease product that may be substantially modified before it's released. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
1719
1820
This article provides information on pricing, limits, and availability when setting up and using Microsoft Sentinel's Model Context Protocol (MCP) collection of security tools.
1921

@@ -45,9 +47,10 @@ The following limits are specific to Microsoft Sentinel data lake MCP tools:
4547
| Query window for tools | 800 characters |
4648

4749
### Microsoft Sentinel entity analyzer tool
48-
Each tenant can use the entity analyzer MCP tool up to the following limits:
49-
- 100 total runs an hour
50-
- 250 total runs a day
50+
Each tenant can use the entity analyzer MCP tool up to the following limits while this feature is in preview:
51+
- 250 total runs an hour
52+
- 500 total runs a day
53+
- 10 concurrent runs at a time (based on available service capacity)
5154

5255
### Triage tool
5356
Regular API throttling applies to the tools in the triage tool collection. In addition, tools that call the advanced hunting API are bound by the existing advanced hunting quotas and service limits. [Learn more about advanced hunting quotas and usage parameters](/defender-xdr/advanced-hunting-limits#understand-advanced-hunting-quotas-and-usage-parameters)

articles/sentinel/datalake/sentinel-mcp-data-exploration-tool.md

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -75,7 +75,7 @@ Entity analysis tools might require a few minutes to generate results, so there
7575

7676
| Parameters | Required? | Description |
7777
|----------|----------|----------|
78-
| Microsoft Entra object ID or URL| Yes |This parameter takes in the user or URL you want to analyze. |
78+
| Microsoft Entra object ID, User Principal Name (UPN), or URL| Yes |This parameter takes in the user or URL you want to analyze. |
7979
| `startTime`| Yes |This parameter takes in the start time of the analysis window. |
8080
| `endTime`| Yes |This parameter takes in the end time of the analysis window. |
8181
| `workspaceId`| No |This parameter takes in a workspace identifier to limit the search to a single connected Microsoft Sentinel data lake workspace. |
@@ -95,18 +95,19 @@ While this tool automatically polls for a few minutes until results are ready, i
9595
9696
#### Additional information
9797
- `analyze_user_entity` supports a maximum time window of seven days to maximize accuracy of the results.
98+
- `analyze_user_entity` only works for users with a Microsoft Entra object ID (cloud users). On-premises Active Directory-only users aren't supported for user analysis.
9899
- `analyze_user_entity` requires the following tables to be present in the data lake to ensure accuracy of the analysis:
99100
- [AlertEvidence](../connect-microsoft-365-defender.md)
100101
- [SigninLogs](../connect-azure-active-directory.md)
101-
- [BehaviorAnalytics](../enable-entity-behavior-analytics.md)
102102
- [CloudAppEvents](../connect-microsoft-365-defender.md)
103103
- [IdentityInfo](/defender-xdr/advanced-hunting-identityinfo-table) (Available only for tenants with Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, or Microsoft Defender for Endpoint P2 licensing)
104104

105105
If you don't have any of these required tables, `analyze_user_entity` generates an error message that lists the tables you didn't onboard, along with links to their corresponding onboarding documentation.
106106

107107
- `analyze_user_entity` works best when the following table is also present in the data lake, but continues to work and assess risk, even if the said table is unavailable:
108108
- [AADNonInteractiveUserSignInLogs](../connect-azure-active-directory.md)
109-
109+
- [BehaviorAnalytics](../enable-entity-behavior-analytics.md)
110+
110111
- `analyze_url_entity` works best when the following tables are present in the data lake, but continues to work and assess risk, even if the said tables are unavailable:
111112
- [EmailUrlInfo](../connect-microsoft-365-defender.md)
112113
- [UrlClickEvents](../connect-microsoft-365-defender.md)
@@ -116,7 +117,7 @@ While this tool automatically polls for a few minutes until results are ready, i
116117

117118
If you don't have any of these tables, `analyze_url_entity` generates a response with a disclaimer that lists the tables you didn't onboard, along with links to their corresponding onboarding documentation.
118119

119-
- Running multiple instances of the entity analyzer at the same time can increase latency for each run. To prevent timeouts, start by running a maximum of five analyses at once and then adjust this number as needed based on how the analyzer runs in your organization.
120+
- Running multiple instances of the entity analyzer at the same time can increase latency for each run. To prevent timeouts and avoid hitting the entity analyzer's [preview thresholds](sentinel-mcp-billing.md#microsoft-sentinel-entity-analyzer-tool-1), start by running a maximum of five analyses at once and then adjust it as needed based on how often the logic app is triggered in your organization.
120121

121122
## Sample prompts
122123

articles/sentinel/datalake/sentinel-mcp-logic-apps.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -85,7 +85,7 @@ To add the entity analyzer tool by using an existing logic app:
8585
```
8686
{
8787
"entityType": "User",
88-
"userId": "[Microsoft Entra object ID]"
88+
"userId": "[Microsoft Entra object ID or User Prinicpal Name]"
8989
}
9090
```
9191
You can enter these properties either manually or as dynamic values from previous actions.
@@ -103,11 +103,10 @@ Every logic app connector requires an authentication connection. This new action
103103
104104
Running multiple instances of the entity analyzer at the same time can increase latency for each run. This issue is especially important when you use a **For each** loop in your entity analyzer logic apps, because it can queue multiple analyses at once (for example, multiple users in an incident, multiple incidents triggered at once).
105105
106-
To prevent timeouts from too many analyses running at once, turn on the **Concurrency control** in the **For each** action. Start by setting the **Degree of parallelism** to `5` and then adjust it as needed based on how the analyzer runs in your organization.
106+
To prevent timeouts from too many analyses running at once and to avoid hitting the entity analyzer's [preview thresholds](sentinel-mcp-billing.md#microsoft-sentinel-entity-analyzer-tool-1), turn on the **Concurrency control** in the **For each** action. Start by setting the **Degree of parallelism** to `5` and then adjust it as needed based on how often the logic app is triggered in your organization.
107107
108108
:::image type="content" source="media/sentinel-mcp/logic-app-concurrency.png" alt-text="Screenshot of the logic app loop settings." lightbox="media/sentinel-mcp/logic-app-concurrency.png":::
109109
110-
111110
For more information about loops, see [Add loops to repeat actions in workflows for Azure Logic Apps](../../logic-apps/logic-apps-control-flow-loops.md).
112111
113112

0 commit comments

Comments
 (0)