Geographical availability and data residency in Microsoft Sentinel

After your data is collected, stored, and processed, compliance can become an important design requirement, with a significant impact on your Microsoft Sentinel architecture. Having the ability to validate and prove who has access to what data under all conditions is a critical data sovereignty requirement in many regions, and assessing risks and getting insights in Microsoft Sentinel workflows is a priority for many customers.

This article can help you meet compliance requirements by describing where Microsoft Sentinel data is stored.

Collected data

Microsoft Sentinel collects the following types of data:

  • Raw data, such as event data collected from connected Microsoft services and partner systems. Data from multiple clouds and sources are streamed to the customer's Azure Log Analytics workspace associated with Microsoft Sentinel, under the customer's tenant's subscription. This approach gives the customer the ability to choose region and retention and deletion policies.
  • Processed data, such as incidents, alerts, and so on.
  • Configuration data, such as connector settings, rules, and so on.

Data storage location

Data used by the service, including customer data, might be stored and processed in the following locations:

Data type Location
Raw data Stored in the same region as the Azure Log Analytics workspace associated with Microsoft Sentinel. For more information, see Supported regions.
For Log Analytics workspaces located in any of the China 21Vianet regions, customer data is processed in China 21Vianet.
Processed data and configuration data Processed data and configuration data is stored and processed using the same methodology as raw data.

Supported regions

Regions supported for Microsoft Sentinel raw data, and for processed and configuration data in workspaces, include:

China 21Vianet

- China East 2
- China North 3

Data retention

Data from Microsoft Sentinel is retained until the earliest of the following dates:

Until that time, customers can always delete their data.

Customer data is kept and is available while the license is under a grace period or in suspended mode. At the end of this period, and no later than 90 days from contract termination or expiration, the data is erased from Microsoft's systems to make it unrecoverable.

For more information, see details about Azure regions when designing your workspace architecture.