From 0607f09825dee0e8e07695c5846d14f3469b0364 Mon Sep 17 00:00:00 2001 From: Mark Date: Mon, 7 Sep 2026 14:41:01 -0600 Subject: [PATCH] Update Sentinel audit export edition --- azure-ts-sentinel-audit-logs/README.md | 2 +- azure-ts-sentinel-audit-logs/index.ts | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/azure-ts-sentinel-audit-logs/README.md b/azure-ts-sentinel-audit-logs/README.md index f8161c9620..c495ef4670 100644 --- a/azure-ts-sentinel-audit-logs/README.md +++ b/azure-ts-sentinel-audit-logs/README.md @@ -39,7 +39,7 @@ The poller authenticates to the Pulumi Cloud API using an access token and handl ## Prerequisites -- A Pulumi Cloud organization with a **Business Critical** subscription (audit logs require this tier) +- A Pulumi Cloud organization on the **Pro** or **Enterprise** edition. Automated audit-log export starts with Pro. - A [Pulumi access token](https://app.pulumi.com/account/tokens) with audit log read permissions — we recommend an **org-scoped service token** (survives employee offboarding, can be scoped to minimum permissions) - An Azure resource group with a Log Analytics workspace and Microsoft Sentinel enabled. If you don't have these: ```bash diff --git a/azure-ts-sentinel-audit-logs/index.ts b/azure-ts-sentinel-audit-logs/index.ts index 43f477a114..f41a8cb7b7 100644 --- a/azure-ts-sentinel-audit-logs/index.ts +++ b/azure-ts-sentinel-audit-logs/index.ts @@ -192,7 +192,7 @@ const connectorDefinition = new azure_native.securityinsights.CustomizableConnec description: [ "A Pulumi Cloud [personal access token](https://www.pulumi.com/docs/pulumi-cloud/access-management/access-tokens/)", "with permissions to read audit logs is required.", - "The organization must have a Pulumi Enterprise or Business Critical subscription with audit logs enabled.", + "The organization must use the Pulumi Cloud Pro or Enterprise edition. Automated audit-log export starts with Pro.", ].join(" "), }], },