Minimum tier: Enterprise (bundled in platform commit — no separate Marketplace SKU for production).
Blekline for Microsoft Sentinel ships governance events, NHIM findings, and enforcement metadata into Microsoft Sentinel workspaces using native data connectors and ARM-deployable solution templates.
Entitlement gate
| Tier | Sentinel connector |
|---|---|
| Local / Mark / Redact | Not available |
| Enterprise | Included in platform commit |
Redact includes a basic HTTPS SIEM webhook (JSON/CEF). Enhanced CEF/ASIM retention and Ledger add-ons are separate from the Sentinel native connector.
For SAML/SCIM before full Enterprise, use Enterprise FastTrack private offer — SSO is not sold on Mark.
ARM deployment overview (stub)
Production deployment uses an Azure Resource Manager template published as blekline-for-sentinel (Azure Application offer). Operator steps:
- Prerequisites: Active Enterprise workspace on
app.blekline.com; Sentinel workspace in the buyer subscription; outbound HTTPS from Blekline sidecar or control-plane sync to Azure Monitor. - Deploy template: Partner Center preview → Deploy to Azure → parameterize
workspaceId,bleklineTenantId,eventHubOrLogAnalyticsResourceId. - Configure connector: Map Blekline event types (
governance.tool_deny,nhim.finding,lineage.contamination) to Sentinel tables (custom log or ASIM-aligned). - Validate ingest: Send test event from Operations → Integrations → Sentinel; confirm row in Sentinel within SLA window.
- Harden: Restrict API keys to Sentinel egress IPs; enable dual-control on enforce mode before production traffic.
Detailed runbook and parameter reference: contact enterprise@blekline.com. Public ARM artifact ships with R3 Enterprise + Azure cert.