Hi all. We are MSSP running Sentinel for around 40 tenants now , the business is growing but already the simple operations is getting painful.
Lighthouse for delegated access , WOrkspace Manager for pushing rules and workbooks. WM updates is slow and sometimes not reflecting , my colleague opened support cases a few times. Cross workspace() work but performance variables. Updating one rule across the tenants when MS changes a template is basically someones entire job.
Per customer tunings , their watchlists , exclusions, also hard to keep separate from the baseline we push.
Anyone running 50-80 tenants in Lighthouse smoothly? Or is just pain at that scale?
Workspace Manager in production or you rolled your own with Bicep , Terraform , Sentinel as COde?
Analysts in Defender XDR unified portal or jumping per-tenant?
And same playbook copied 40 times with small differences, how you handle that?