A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Hello @kristich-5860
Since the workspace is shown as Connected and Primary, but every Sentinel page immediately redirects back to the Workspaces page, this looks more like a Defender portal workspace provisioning/routing issue than a Sentinel data issue.
Microsoft documentation confirms that after a workspace is connected, Sentinel features such as Analytics, Content Hub, Automation, Logs and Hunting should be available directly in the Defender portal.
I would first verify that the affected account has at least Microsoft Sentinel Reader on the workspace/resource group. Sentinel continues to use Azure RBAC permissions in the Defender portal.
There have also been other recent reports showing almost identical behavior, where the workspace is connected and Primary but Sentinel pages redirect back to SIEM Workspaces.
If the correct Azure RBAC permissions are already assigned, especially if this was working before September 3, I wouldn't recommend repeatedly disconnecting/reconnecting the workspace. I would continue the Microsoft support case and ask the Sentinel/Unified Security Operations team to verify the backend workspace provisioning and routing state.
Providing a HAR capture while reproducing the redirect, along with the tenant ID, workspace resource ID and UTC timestamp, should help Microsoft investigate it.
If this answer helps, please mark it as Answered.