A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Hello @meherzad javed
The key point here is that the account performing the onboarding must have all required permissions itself.
For connecting a Sentinel workspace to the Defender portal, Microsoft currently requires:
- Security Administrator or higher in Entra ID. Global Administrator satisfies this requirement.
- Either unconditional Owner at subscription scope, or User Access Administrator + Microsoft Sentinel Contributor.
Global Administrator doesn't replace the Azure User Access Administrator/Owner requirement.
From your description, if the user you're signing into Defender with is only Global Administrator + Microsoft Sentinel Contributor, but User Access Administrator is assigned to another administrator, that would explain why the Connect workspace option isn't available and the direct page returns "You don't have permission."
Assign User Access Administrator to the same account at subscription scope (or unconditional Owner), make sure any PIM assignments are activated, then sign out and back into the Defender portal to refresh the token.
If the same account already has Global Administrator + User Access Administrator + Microsoft Sentinel Contributor and the workspace still isn't visible, this should be raised with Microsoft Support to check the Defender/Sentinel onboarding state, as Microsoft's troubleshooting guidance specifically says that a workspace missing from the Defender portal after the required roles are verified needs further investigation.
If this answer helps, please mark it as Answered.