---
title: How do I deploy the NC Protect Data Connector for Microsoft Sentinel from Azure Marketplace?
description: Instructions on how to deploy the NC Protect Data Connector to a Sentinel-enabled Log Analytics Workspace (LAW).
---

[Skip to content](https://help.archtis.com/knowledgebase/how-do-i-deploy-the-nc-protect-data-connector-for-microsoft-sentinel-from-azure-marketplace#main-content)

English

Show submenu for translations

[Log a Support Ticket](https://help.archtis.com/knowledgebase/kb-tickets/new)

![archTIS-logo-cmyk-3.png\]](https://help.archtis.com/hs-fs/hubfs/archTIS-logo-cmyk-3.png?height=40&name=archTIS-logo-cmyk-3.png)

- [Knowledgebase](https://help.archtis.com/knowledgebase)
- [Support Tickets](https://help.archtis.com/tickets)
- [Blog](https://www.archtis.com/blog/)

Open main navigation

Close main navigation

- [Knowledgebase](https://help.archtis.com/knowledgebase)
- [Support Tickets](https://help.archtis.com/tickets)
- [Blog](https://www.archtis.com/blog/)
- English
  
  Show submenu for translations
- [Log a Support Ticket](https://help.archtis.com/knowledgebase/kb-tickets/new)
- [archtis.com](https://www.archtis.com/)

[archtis.com](https://www.archtis.com/)

 Search the Knowledgebase

- There are no suggestions because the search field is empty.

1. [Knowledgebase](https://help.archtis.com/knowledgebase)
2. [NC Protect v8.X](https://help.archtis.com/knowledgebase/nc-protect-v8-x)
3. [Azure Marketplace](https://help.archtis.com/knowledgebase/nc-protect-v8-x#azure-marketplace)

# How do I deploy the NC Protect Data Connector for Microsoft Sentinel from Azure Marketplace?

## Instructions on how to deploy the NC Protect Data Connector to a Sentinel-enabled Log Analytics Workspace (LAW).

The NC Protect Data Connector for Microsoft Sentinel enables customers to easily ingest user activity and logs collected in NC Protect and push them into Microsoft Sentinel to analyze the data at cloud scale using pre-built workbooks, as well as trigger alerts. NC Protect’s Data Connector for Microsoft Sentinel is deployed to a Sentinel-enabled Log Analytics Workspace (LAW). 

For more information or to download the NC Protect Data Connector from the Azure Marketplace, refer to: [https://azuremarketplace.microsoft.com/en/marketplace/apps/nucleuscyber.nc-protect-azure-sentinel-data-connector?tab=Overview](https://azuremarketplace.microsoft.com/en/marketplace/apps/nucleuscyber.nc-protect-azure-sentinel-data-connector?tab=Overview)

### Deployment Instructions

To deploy and use the NC Protect Data Connector for Microsoft Sentinel, follow the steps below.

### Pre-requisites

1. 1. The NC Protect Data Connector for Microsoft Sentinel is free to NC Protect users. A valid instance of NC Protect for Microsoft 365 is required in order to use the connector.
     2. Create and elevate an Azure Log Analytics Workspace as a Sentinel Workspace. For more information, see [Quickstart: Onboard in Microsoft Sentinel | Microsoft Learn](https://aus01.safelinks.protection.outlook.com/?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fquickstart-onboard&data=05%7C01%7CIrena.Mroz%40archtis.com%7Cee4467f466014188408008db5b30fcbf%7C09da75094ada4cc6b386d88451e2c7a2%7C0%7C0%7C638204038180093389%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=VnxqbKYvjfYe40vMDYIqv8Dszi%2F7DJEtw8mjUOprUaM%3D&reserved=0)
        
        ***NOTE:*** After successfully creating the LAW from the Microsoft Sentinel page, verify that the LAW created has been added to Microsoft Sentinel by going back to the Microsoft Sentinel menu and clicking Add.
     3. Ensure NC Protect for M365 is installed. Then configure the SIEM options to point to this LAW (*refer to the NC Protect for M365 installation guide*).
   
   ### **Deploy the NC Protect Data Connector for Microsoft Sentinel**
   
     1. Go to the Azure Marketplace NC Protect Data Connector offer, using this link:  
        [https://azuremarketplace.microsoft.com/en/marketplace/apps/nucleuscyber.nc-protect-azure-sentinel-data-connector?tab=Overview](https://azuremarketplace.microsoft.com/en/marketplace/apps/nucleuscyber.nc-protect-azure-sentinel-data-connector?tab=Overview )
     2. Click **Get it Now** and after logging in with the appropriate credentials (see the Quickstart link above). Click on **Create**:![Sentinel Fig 1](https://help.archtis.com/hs-fs/hubfs/Sentinel%20Fig%201.jpg?width=688&height=234&name=Sentinel%20Fig%201.jpg)
     3. Select the **Subscription, Resource Group and Sentinel-enabled LAW** as defined in Pre-requisite 1 above.  
        ![Sentinel Fig 2](https://help.archtis.com/hs-fs/hubfs/Sentinel%20Fig%202.jpg?width=688&height=305&name=Sentinel%20Fig%202.jpg)
     4. Complete the deployment by **clicking Next** (Data Connectors -\> Workbooks, both of which are contained in the NC Protect Data Connector pack).
     5. **Click on Review + Create** to proceed with the Validation.
     6. Once Validation is passed, **review the Terms of Use**, and your subscription details then **click Create**. This proceeds with the deployment of the various resources:
        
        ![Sentinel Fig 3](https://help.archtis.com/hs-fs/hubfs/Sentinel%20Fig%203.jpg?width=688&height=184&name=Sentinel%20Fig%203.jpg)
     7. From the Microsoft Sentinel page, **select** the Workspace, Configuration \> Data Connectors and **search for “NC Protect”**.  
        ![Sentinel Fig 4](https://help.archtis.com/hs-fs/hubfs/Sentinel%20Fig%204.jpg?width=688&height=298&name=Sentinel%20Fig%204.jpg)
     8. **Click on the Open Connector page**, to open the NC Protect Data Connector for Sentinel page. This highlights the next steps to perform, such as configuring NC Protect with the details required to populate the Logs.  
        ![Sentinel Fig 5](https://help.archtis.com/hs-fs/hubfs/Sentinel%20Fig%205.jpg?width=688&height=324&name=Sentinel%20Fig%205.jpg)  
        Take note of the Workspace ID and Primary Key values. These 2 values will be used when configuring NC Protect for M365 for Microsoft Sentinel.
     9. Navigate to the NC Protect Administration page and select General \> User Activity Monitoring and Enable security information event management (SIEM). Click Configure.
     10. Enter the Workspace ID and Primary Key copied in step 6 and paste it into the corresponding fields on the NCP Administration page.![image-20251101-002725](https://help.archtis.com/hs-fs/hubfs/image-20251101-002725.png?width=688&height=356&name=image-20251101-002725.png)  
         To create the tables that capture the user event logs inside of the SIEM workbook, it will require the Admin/End User to create activity inside of the Proxied assets e.g Log in/Log out, upload files, download files, delete files. This will then create the tables where the Administrator can monitor user activity logs within the NC Protect Workbook on Sentinel.![image-20251101-002943](https://help.archtis.com/hs-fs/hubfs/image-20251101-002943.png?width=688&height=338&name=image-20251101-002943.png)  
         ![image-20251101-003055](https://help.archtis.com/hs-fs/hubfs/image-20251101-003055.png?width=688&height=354&name=image-20251101-003055.png)

Refer to the NC Protect for M365 Installation Guide for more information.

### Validation Checks of Pre-requisites

1. Inside the Azure Portal navigate to Microsoft Sentinel - The Name of the onboarded Log Analytics Workspace - Analytics.  
   *Expected Result* - A Near Real Time (NRT) rule will be present called DownloadRateHighRule![image-20251101-000523](https://help.archtis.com/hs-fs/hubfs/image-20251101-000523.png?width=688&height=367&name=image-20251101-000523.png)
2. Inside the Azure Portal navigate to Microsoft Sentinel - The Name of the onboarded Log Analytics Workspace - Watchlist.  
   *Expected Result* - A watchlist item will be present called wNCPFileDownloadMonitoring
   
   The watch list item allows the Administrator to configure what the parameters of the action event that requires monitoring - Administrators can configure the number threshold of the occurring event and the Time Window in minutes of that threshold, and also select the level of Incident Severity. This will then create an incident based off the time, threshold and then log the Incident based off the Watchlist Severity.  
   ![image-20251101-000614](https://help.archtis.com/hs-fs/hubfs/image-20251101-000614.png?width=688&height=366&name=image-20251101-000614.png)
3. Inside the Azure Portal navigate to Microsoft Sentinel - The Name of the onboarded Log Analytics Workspace - Automation.  
   *Expected Result* - 4 automation rules will be present
   
   These 4 automation rules allow the Administrator to define the severity level of the incident configure - after activating the NRT in step Validation Checks of Pre-requisites step 1. The automation rules will all have a status of Enabled.  
   ![image-20251101-000720](https://help.archtis.com/hs-fs/hubfs/image-20251101-000720.png?width=688&height=365&name=image-20251101-000720.png)  
   *Microsoft is slowly migrating the Azure Sentinel functionalities across to its other product, Microsoft Defender. Therefore, the next steps will ensure that the validation checks are also repeated inside of Microsoft Defender.*
4. Log into Microsoft Defender ([https://security.microsoft.com/](https://security.microsoft.com/)).
5. Navigate to the SIEM workspaces by clicking System - Settings - Microsoft Sentinel.  
   ![image-20251101-001900](https://help.archtis.com/hs-fs/hubfs/image-20251101-001900.png?width=688&height=364&name=image-20251101-001900.png)
6. Inside the Microsoft Defender Portal click the drop-down Microsoft Sentinel and select Analytics under the Configuration sub-menu.  
   *Expected Result* - A Near Real Time (NRT) rule will be present called DownloadRateHighRule![image-20251101-003553](https://help.archtis.com/hs-fs/hubfs/image-20251101-003553.png?width=688&height=348&name=image-20251101-003553.png)
7. Inside the Microsoft Defender Portal click the drop-down Microsoft Sentinel and select Watchlist.  
   *Expected Result* - A watchlist item will be present called wNCPFileDownloadMonitoring![image-20251101-003739](https://help.archtis.com/hs-fs/hubfs/image-20251101-003739.png?width=688&height=350&name=image-20251101-003739.png)
8. Inside the Microsoft Defender Portal click the drop-down Microsoft Sentinel and select Automation.  
   *Expected Result* -Expected Result - 4 automation rules will be present with the status of Enabled![image-20251101-003920](https://help.archtis.com/hs-fs/hubfs/image-20251101-003920.png?width=688&height=343&name=image-20251101-003920.png)

### Validation Checks of Pre-requisites

The following steps will demonstrate the functionality of configuring the Watchlist parameters to the business needs and then displaying the Incident inside of Azure and the Defender.

1. Inside the Azure Portal navigate to Microsoft Sentinel - The Name of the onboarded Log Analytics Workspace - Watchlist.
2. Select the Watchlist ‘wNCPFileDownloadMonitoring’, click Update Watchlist - and Edit Watchlist items from the dropdown.![image-20251101-004354](https://help.archtis.com/hs-fs/hubfs/image-20251101-004354.png?width=688&height=363&name=image-20251101-004354.png)
3. For the purpose of demonstration and testing - I have updated the DocumentDownloadThreshold to 3 and TimeWindowMinutes to 5 with an IncidentSeverity of Medium. What this means is that if an end user downloads more than 3 documents within 5 minutes - NC Protect will then log a Security Incident where the Administrator will be able to read a report from.![image-20251101-004537](https://help.archtis.com/hs-fs/hubfs/image-20251101-004537.png?width=688&height=151&name=image-20251101-004537.png)
4. After downloading the documents - a security incident will be triggered and logged.![image-20251101-004645](https://help.archtis.com/hs-fs/hubfs/image-20251101-004645.png?width=688&height=333&name=image-20251101-004645.png)![image-20251101-004739](https://help.archtis.com/hs-fs/hubfs/image-20251101-004739.png?width=688&height=202&name=image-20251101-004739.png)
5. The administrator can then click into the incident and view the query, which will then show all the documents downloaded within the incident.![image-20251101-004930](https://help.archtis.com/hs-fs/hubfs/image-20251101-004930.png?width=688&height=494&name=image-20251101-004930.png)

 

- [Kojensi](https://help.archtis.com/knowledgebase/kojensi#main-content)

    - [Guided Video Tours](https://help.archtis.com/knowledgebase/kojensi#guided-video-tours)
    - [Release Notes](https://help.archtis.com/knowledgebase/kojensi#release-notes)
    - [Security](https://help.archtis.com/knowledgebase/kojensi#security)
    - [Troubleshooting](https://help.archtis.com/knowledgebase/kojensi#troubleshooting)
- [NC Protect v8.X](https://help.archtis.com/knowledgebase/nc-protect-v8-x#main-content)

    - [User Documentation](https://help.archtis.com/knowledgebase/nc-protect-v8-x#user-documentation)
    - [Azure Marketplace](https://help.archtis.com/knowledgebase/nc-protect-v8-x#azure-marketplace)
- [Spirion Sensitive Data Platform (SDP)](https://help.archtis.com/knowledgebase/spirion-sensitive-data-platform-sdp#main-content)

    - [Introduction and Architecture](https://help.archtis.com/knowledgebase/spirion-sensitive-data-platform-sdp#introduction-and-architecture)
- [Trusted Data Integration](https://help.archtis.com/knowledgebase/trusted-data-integration)
- [cp.Protect](https://help.archtis.com/knowledgebase/cp-protect)
- [Help](https://help.archtis.com/knowledgebase/help)

- [Knowledgebase](https://help.archtis.com/knowledgebase)
- [Support Tickets](https://help.archtis.com/tickets)
- [Blog](https://www.archtis.com/blog/)

[![Chill listening crop-3](https://help.archtis.com/hs-fs/hubfs/archTIS-logo-cmyk-3.png?width=121&height=24&name=archTIS-logo-cmyk-3.png "Chill listening crop-3")](https://www.archtis.com/)

Copyright © 2026, archTIS