Can you correlate Microsoft Sentinel data across Government and Commercial clouds?
Reviewed by ContraForce team ยท Updated 2026-09-04
> Azure Lighthouse does not support delegation of subscriptions across a national cloud and the Azure public cloud, or across two national clouds, so the cross-tenant mechanism Sentinel correlation depends on does not span that boundary. Microsoft also states it is not possible to move data or a workspace from Azure to Azure Government.
Last verified: 2026-09-04. Sources linked at the foot of the page.Where exactly is the boundary?
Azure Lighthouse is the mechanism that lets a provider query customer Sentinel workspaces from its own tenant, and Microsoft lists cross-cloud delegation among the Lighthouse features not available in Azure Government. The unsupported case is stated as delegation of subscriptions across a national cloud and the Azure public cloud, or across two national clouds.
That single constraint decides the question. Without delegation across the boundary, there is no path for a query in one cloud to reach a workspace in the other.
Microsoft separately states that it is not possible to move data or a workspace from Azure to Azure Government, which closes the other obvious workaround of consolidating everything into one cloud after the fact.
What does work across clouds?
Multitenant management itself is available on both sides. Microsoft documents Defender multitenant management, including for US Government clouds, as available to GCC, GCC High, DoD, and Commercial customers.
So a provider can operate a multi-tenant practice inside Government and a multi-tenant practice inside Commercial. What it cannot do is treat them as one estate.
| Capability | Within one cloud | Across Government and Commercial |
|---|---|---|
| Azure Lighthouse delegation | Supported | Not supported |
| Cross-tenant Sentinel query | Supported | No delegation path |
| Move a workspace or its data | n/a | Not possible |
| Defender multitenant management | Available in GCC, GCC High, DoD, Commercial | Two separate practices |
What does a provider serving both actually run?
Two of everything, and the duplication is structural rather than a configuration choice. Separate delegated access, separate hunting, separate content distribution, separate reporting. An analyst covering both works two consoles, and a question asked of the whole book of business has to be asked twice and reconciled by hand.
For a provider whose government work is a minority of its customers, the practical effect is that the government segment carries a disproportionate share of operational overhead relative to its revenue.
How do you report across a boundary the platform will not cross?
Nothing removes the delegation constraint, which is a property of the clouds rather than of any tool sitting on top of them. What can change is where the reconciliation happens.
ContraForce holds the incident records, verdicts, and evidence its agents produce in its own regional deployment, separately from where the customer's logs live. Cross-customer reporting therefore reads the platform's own records rather than requiring a federated query that crosses a boundary no query can cross. The underlying access into each customer environment still respects whichever cloud that customer is in.
Sources
- Azure Lighthouse in Azure Government
- Compare Azure Government and global Azure
- Microsoft Defender multitenant management overview
- Microsoft Sentinel in Azure Government
Continue the evaluation
Sources and review method
Product capabilities were reviewed against the page-specific primary sources below on 2026-09-04. Performance claims require the population and limitations stated in the linked methodology.
- Microsoft Defender multitenant management requirements (verified 2026-09-04)
- Automation in Microsoft Sentinel (verified 2026-09-04)
Related microsoft resources
- Can Security Copilot agents run across Lighthouse-connected tenants?, Workspace and capacity boundaries that make AI capability per tenant rather than per provider.
- Can you rename or alias tenants in Defender multitenant management?, What the console reads, why directory names get expensive above about twenty tenants, and what is documented.