Microsoft Sentinel
Architecture and deployment

Customer intent: As an administrator I want to onboard to the Microsoft Sentinel data lake from my Defender portal so that I can benefit from the sto…

In brief

The article adds guidance for recreated workspaces, regional-capacity workarounds, generic setup errors, and workspaces missing from the Defender portal. It also adds a warning that deleting a Log Analytics workspace can cause permanent data loss.

What Defender admins need to know

Administrators can use the added troubleshooting steps and should review the data-loss warning before deleting a workspace.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Onboard to Microsoft Sentinel data lake from the Defender portal

This article walks you through onboarding your tenant to the Microsoft Sentinel data lake from the Microsoft Defender portal. Before you start, you need a Microsoft Sentinel workspace connected to the Defender portal as the Primary SIEM workspace and the required roles. The onboarding process is a one-time setup that also enables graph capabilities.

Onboarding your tenant to the Microsoft Sentinel data lake occurs once and starts from the Microsoft Defender portal. The onboarding process creates a new Microsoft Sentinel data lake for your tenant in the subscription specified during the onboarding process. Graph enablement is included as part of onboarding. If you had onboarded to the data lake during public preview, you're automatically upgraded to the generally available data lake and graph.

Can't onboard a new workspace after the tenant is already onboarded

  • Scenario: You delete and recreate workspaces and then try to onboard a newly created workspace to the data lake.
  • Resolution: Once the tenant is onboarded to the data lake, additional workspaces aren't onboarded automatically. Ensure the workspace is connected to the Defender portal and is in the same region as the workspace initially onboarded to the data lake. If you need assistance, submit a support request

    Can't onboard a new workspace after the tenant is already onboarded

    Use the following guidance if a recreated workspace can't be onboarded after the tenant is already onboarded.

    • Scenario: You delete and recreate workspaces and then try to onboard a newly created workspace to the data lake.
    • Resolution: Once the tenant is onboarded to the data lake, additional workspaces aren't onboarded automatically. Ensure the workspace is connected to the Defender portal and is in the same region as the workspace initially onboarded to the data lake. If you need assistance, submit a support request.

    Capacity limitations in specific regions

    If onboarding fails because of regional capacity limits, use the following workaround.

    • Symptom: Onboarding doesn't complete in specific regions due to capacity constraints.
    • Resolution: Use an alternate supported region. Delete the current Log Analytics workspace, create a new workspace in a different region (for example, Central US), add Microsoft Sentinel, connect it as the Primary workspace in the Defender portal, and set up the data lake.

    "Something went wrong" during setup

    • Symptom: After selecting Set up data lake, the setup flow doesn't complete and you see an error "Something went wrong, Please try again."
    • Resolution: Check whether the resource group associated with the onboarded Sentinel workspace was previously deleted, or whether the subscription used for data lake billing was deleted or canceled. If the issue persists, submit a support request
      Delete the current Log Analytics workspace, create a new workspace in a different region (for example, Central US), add Microsoft Sentinel, connect it as the **Primary** workspace in the Defender portal, and set up the data lake.
      

      "Something went wrong" during setup

      If setup fails with a generic error message, use the following checks to diagnose the issue.

      • Symptom: After selecting Set up data lake, the setup flow doesn't complete and you see an error "Something went wrong, Please try again."
      • Resolution: Check whether the resource group associated with the onboarded Sentinel workspace was previously deleted, or whether the subscription used for data lake billing was deleted or canceled. If the issue persists, submit a support request.

      Sentinel workspace not visible in Defender

      Check the following if your Sentinel workspace doesn't appear in the Defender portal.

      • Scenario: You created a Log Analytics workspace and added Sentinel, but the Defender portal doesn't show the workspace, or UI filters don't populate correctly.
      • Resolution: Verify the required roles end-to-end. The minimum combination is Security Administrator or higher in Entra ID, plus Azure Subscription Owner or (User Access Administrator + Microsoft Sentinel Contributor).