Microsoft Sentinel Analytics redirects to SIEM Workspaces in Defender portal

Anupriya Sehgal 0 Reputation points
2026-09-23T02:08:38.7133333+00:00

Microsoft Sentinel Analytics redirects to SIEM Workspaces in Defender portal

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud

1 answer

Sort by: Most helpful
  1. AI answer

    2026-09-23T02:08:52.0666667+00:00

    This redirect is expected as Microsoft Sentinel is moving to the Microsoft Defender portal experience.

    Key points:

    • Microsoft Sentinel is generally available in the Microsoft Defender portal, including for customers without Microsoft Defender XDR or an E5 license.
    • After March 31, 2027, Microsoft Sentinel will no longer be supported in the Azure portal and will be available only in the Defender portal.
    • For some customers and workspaces, Sentinel experiences in Azure already redirect to the Defender portal.
    • In the Defender portal, Sentinel workspaces are managed under System > Settings > Microsoft Sentinel > Connect a workspace.

    If Analytics is redirecting to SIEM workspaces in the Defender portal, that indicates the workspace is using the Defender portal experience. To work with Sentinel there:

    1. Open the Microsoft Defender portal.
    2. Go to System > Settings > Microsoft Sentinel.
    3. Verify the workspace is connected.
    4. If needed, use Connect a workspace and select the workspace.
    5. Select a Primary workspace if prompted.

    For existing Azure portal users, the recommended action is to plan and complete the transition to the Defender portal.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.