Share via

Microsoft Sentinel Stuck in a Loop in the Defender Portal

Malaurm 0 Reputation points
2026-05-12T03:48:26.8633333+00:00

In the microsoft defender portal with sentinel, i have connected, disconnected and waited 30 minutes, and reconnected the SIEM workspace. if i go to sentinel and any of the tabs in defender, it just loops to the connectors page as if the workspace is not at all connected. this is stopping me from being able to do certain actions like get content from the content hub, manage incidents, hunting, etc because Sentinel the defender portal is stuck in this infinite loop. In the image below is just showing it is from the defender portal. i can click on any tab under sentinel and it takes me to this page

User's image

I also have confirmed the XDR connector is connected

User's image

Any help would be much appreciated

Microsoft Security | Microsoft Sentinel

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-05-12T03:48:51.4633333+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    The behavior described usually occurs when the Defender portal does not have a valid primary Microsoft Sentinel workspace context, or when the signed‑in account does not meet the Sentinel permissions required in the Defender portal.

    Use the following checks and fixes in the Defender portal (https://security.microsoft.com):

    1. Confirm the primary workspace
      1. Go to System > Settings > Microsoft Sentinel > Workspaces.
      2. Verify that the intended workspace is listed as Connected and marked Primary.
      3. If it is not primary, select the workspace and choose Set as primary, then confirm the change.
      4. Wait a few minutes and then try opening Microsoft Sentinel > Threat management (for example Workbooks, Hunting, or MITRE ATT&CK).
    2. Verify required roles and scope Ensure the account has at least the following on the Sentinel workspace (or its resource group/subscription):
      • Microsoft Sentinel Reader to view Sentinel in the Defender portal and query data tables or view incidents.
      • Microsoft Sentinel Contributor to take investigative actions on incidents or manage content. Also make sure the account has the necessary Azure RBAC scope (subscription, resource group, or workspace) where Sentinel is enabled. If there is more than one Sentinel workspace in the tenant, the account must also be at least Security administrator in Microsoft Entra ID.
    3. Reconnect or switch workspaces if needed
      • If the workspace was disconnected and reconnected multiple times, from System > Settings > Microsoft Sentinel > Workspaces, select the workspace and choose Disconnect workspace, confirm, then connect it again.
      • If there is another Sentinel workspace, try temporarily setting that one as primary, confirm that Sentinel opens, and then switch back to the desired workspace as primary. When switching the primary workspace, the Defender XDR connector is automatically moved to the new primary and disconnected from the former one.
    4. Validate data connector behavior
      • In the Azure portal, confirm the Microsoft Defender XDR connector is connected and that incidents and alerts are enabled for the Sentinel workspace.
      • Be aware that after onboarding to Defender, the Defender product connectors (Defender for Endpoint, Identity, Cloud Apps, Office 365) no longer appear in the Defender portal Data connectors page; this is expected and does not indicate a connection issue.

    If, after confirming the primary workspace and permissions, the Defender portal still loops back to the connectors page for all Sentinel blades, collect a portal session recording and open a support request from the affected subscription so that Microsoft can review the tenant’s Sentinel–Defender integration state.


    References:

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.