Microsoft Sentinel: Loading Data Issues in Defender Portal — Ongoing Investigation

kristich-5860 5 Reputation points
2026-09-04T01:26:00.0266667+00:00

Problem description

I am experiencing issues accessing Microsoft Sentinel features through the Defender portal. Since September 3, 2026, all Sentinel features such as Content Hub, Analytics, Automation, Logs, and Hunting immediately redirect back to the Workspaces overview page without any specific error messages.

Environment

The affected environment is a Log Analytics workspace enabled for Microsoft Sentinel, deployed in an Australia-region subscription. Sentinel is connected as the Primary workspace in the Microsoft Defender portal.

What I've already tried

I confirmed the workspace's binding status in the Defender portal, verified that it shows as Connected and Primary. Support retrieved diagnostic logs related to Sentinel onboarding; no relevant errors were found. I have not performed additional configuration changes or role verifications beyond these steps.

Current status

I am seeking guidance on further troubleshooting steps to resolve the redirect issue and restore full functionality of Microsoft Sentinel features in the Defender portal.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments

1 answer

Sort by: Newest
  1. Konstantinos Lianos 830 Reputation points Student Ambassador
    2026-09-15T09:13:59.3566667+00:00

    Hello @kristich-5860

    Since the workspace is shown as Connected and Primary, but every Sentinel page immediately redirects back to the Workspaces page, this looks more like a Defender portal workspace provisioning/routing issue than a Sentinel data issue.

    Microsoft documentation confirms that after a workspace is connected, Sentinel features such as Analytics, Content Hub, Automation, Logs and Hunting should be available directly in the Defender portal.

    I would first verify that the affected account has at least Microsoft Sentinel Reader on the workspace/resource group. Sentinel continues to use Azure RBAC permissions in the Defender portal.

    There have also been other recent reports showing almost identical behavior, where the workspace is connected and Primary but Sentinel pages redirect back to SIEM Workspaces.

    If the correct Azure RBAC permissions are already assigned, especially if this was working before September 3, I wouldn't recommend repeatedly disconnecting/reconnecting the workspace. I would continue the Microsoft support case and ask the Sentinel/Unified Security Operations team to verify the backend workspace provisioning and routing state.

    Providing a HAR capture while reproducing the redirect, along with the tenant ID, workspace resource ID and UTC timestamp, should help Microsoft investigate it.

    If this answer helps, please mark it as Answered.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.