A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
This redirect is expected as Microsoft Sentinel is moving to the Microsoft Defender portal experience.
Key points:
- Microsoft Sentinel is generally available in the Microsoft Defender portal, including for customers without Microsoft Defender XDR or an E5 license.
- After March 31, 2027, Microsoft Sentinel will no longer be supported in the Azure portal and will be available only in the Defender portal.
- For some customers and workspaces, Sentinel experiences in Azure already redirect to the Defender portal.
- In the Defender portal, Sentinel workspaces are managed under System > Settings > Microsoft Sentinel > Connect a workspace.
If Analytics is redirecting to SIEM workspaces in the Defender portal, that indicates the workspace is using the Defender portal experience. To work with Sentinel there:
- Open the Microsoft Defender portal.
- Go to System > Settings > Microsoft Sentinel.
- Verify the workspace is connected.
- If needed, use Connect a workspace and select the workspace.
- Select a Primary workspace if prompted.
For existing Azure portal users, the recommended action is to plan and complete the transition to the Defender portal.