Customer intent: As an administrator I want to onboard to the Microsoft Sentinel data lake from my Defender portal so that I can benefit from the sto…
In brief
The article adds guidance for recreated workspaces, regional-capacity workarounds, generic setup errors, and workspaces missing from the Defender portal. It also adds a warning that deleting a Log Analytics workspace can cause permanent data loss.
What Defender admins need to know
Administrators can use the added troubleshooting steps and should review the data-loss warning before deleting a workspace.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Onboard to Microsoft Sentinel data lake from the Defender portal
This article walks you through onboarding your tenant to the Microsoft Sentinel data lake from the Microsoft Defender portal. Before you start, you need a Microsoft Sentinel workspace connected to the Defender portal as the Primary SIEM workspace and the required roles. The onboarding process is a one-time setup that also enables graph capabilities.
Onboarding your tenant to the Microsoft Sentinel data lake occurs once and starts from the Microsoft Defender portal. The onboarding process creates a new Microsoft Sentinel data lake for your tenant in the subscription specified during the onboarding process. Graph enablement is included as part of onboarding. If you had onboarded to the data lake during public preview, you're automatically upgraded to the generally available data lake and graph.
Can't onboard a new workspace after the tenant is already onboarded
- Scenario: You delete and recreate workspaces and then try to onboard a newly created workspace to the data lake.
- Resolution: Once the tenant is onboarded to the data lake, additional workspaces aren't onboarded automatically. Ensure the workspace is connected to the Defender portal and is in the same region as the workspace initially onboarded to the data lake. If you need assistance, submit a support request
Can't onboard a new workspace after the tenant is already onboarded
Use the following guidance if a recreated workspace can't be onboarded after the tenant is already onboarded.
- Scenario: You delete and recreate workspaces and then try to onboard a newly created workspace to the data lake.
- Resolution: Once the tenant is onboarded to the data lake, additional workspaces aren't onboarded automatically. Ensure the workspace is connected to the Defender portal and is in the same region as the workspace initially onboarded to the data lake. If you need assistance, submit a support request.
Capacity limitations in specific regions
If onboarding fails because of regional capacity limits, use the following workaround.
- Symptom: Onboarding doesn't complete in specific regions due to capacity constraints.
- Resolution: Use an alternate supported region.
Delete the current Log Analytics workspace, create a new workspace in a different region (for example, Central US), add Microsoft Sentinel, connect it as thePrimaryworkspace in the Defender portal, and set up the data lake.
"Something went wrong" during setup
Symptom: After selectingSet up data lake, the setup flow doesn't complete and you see an error "Something went wrong, Please try again."Resolution: Check whether the resource group associated with the onboarded Sentinel workspace was previously deleted, or whether the subscription used for data lake billing was deleted or canceled. If the issue persists, submit a support requestDelete the current Log Analytics workspace, create a new workspace in a different region (for example, Central US), add Microsoft Sentinel, connect it as the **Primary** workspace in the Defender portal, and set up the data lake."Something went wrong" during setup
If setup fails with a generic error message, use the following checks to diagnose the issue.
- Symptom: After selecting Set up data lake, the setup flow doesn't complete and you see an error "Something went wrong, Please try again."
- Resolution: Check whether the resource group associated with the onboarded Sentinel workspace was previously deleted, or whether the subscription used for data lake billing was deleted or canceled. If the issue persists, submit a support request
Sentinel workspace not visible in Defender
Check the following if your Sentinel workspace doesn't appear in the Defender portal.
- Scenario: You created a Log Analytics workspace and added Sentinel, but the Defender portal doesn't show the workspace, or UI filters don't populate correctly.
- Resolution: Verify the required roles end-to-end. The minimum combination is Security Administrator or higher in Entra ID, plus Azure Subscription Owner or (User Access Administrator + Microsoft Sentinel Contributor).
@@ -4,21 +4,24 @@ titleSuffix: Microsoft Security description: This article describes how to onboard to the Microsoft Sentinel data lake for customers who are currently using Microsoft Defender. author: mberdugo ms.topic: how-to -ms.date: 06/24/2026+ms.date: 07/01/2026 ms.author: monaberdugo ms.service: microsoft-sentinel ms.subservice: sentinel-platform ai-usage: ai-assisted+ms.custom: msecd-doc-authoring-1016 # Customer intent: As an administrator I want to onboard to the Microsoft Sentinel data lake from my Defender portal so that I can benefit from the storage and analysis capabilities of the data lake. --- # Onboard to Microsoft Sentinel data lake from the Defender portal +This article walks you through onboarding your tenant to the Microsoft Sentinel data lake from the Microsoft Defender portal. Before you start, you need a Microsoft Sentinel workspace connected to the Defender portal as the **Primary** SIEM workspace and the [required roles](sentinel-lake-onboarding.md#required-roles). The onboarding process is a one-time setup that also enables graph capabilities.+ Onboarding your tenant to the Microsoft Sentinel data lake occurs once and starts from the Microsoft Defender portal. The onboarding process creates a new Microsoft Sentinel data lake for your tenant in the subscription specified during the onboarding process. Graph enablement is included as part of onboarding. If you had onboarded to the data lake during public preview, you're automatically upgraded to the generally available data lake and graph. > [!IMPORTANT]-> Do not delete the subscription or resource group that contains your Microsoft Sentinel data lake. If you do, the data lake-related experiences will be suspended and ingestion will stop after 3 days. To restore the data lake-related experiences and ingestion, you must set up the data lake again using the steps below. All data previously ingested to the data lake will be restored and available after you set up the data lake again.+> Do not delete the subscription or resource group that contains your Microsoft Sentinel data lake. If you do, the data lake-related experiences will be suspended and ingestion will stop after 3 days. To restore the data lake-related experiences and ingestion, you must [set up the data lake again](#onboard-to-microsoft-sentinel-data-lake-from-the-defender-portal) using the onboarding procedure described in this article. All data previously ingested to the data lake will be restored and available after you set up the data lake again. > [!NOTE] > You'll always have one data lake that you can use with multiple Microsoft Security products. During onboarding, we check for and automatically use your existing data lake. When you ingest and store security data in your data lake, this data can be used with multiple Microsoft Security products.@@ -94,21 +97,34 @@ The following are errors that you might encounter during the onboarding process. ### Can't onboard a new workspace after the tenant is already onboarded +Use the following guidance if a recreated workspace can't be onboarded after the tenant is already onboarded.+ - **Scenario**: You delete and recreate workspaces and then try to onboard a newly created workspace to the data lake. - **Resolution**: Once the tenant is onboarded to the data lake, additional workspaces aren't onboarded automatically. Ensure the workspace is connected to the Defender portal and is in the same region as the workspace initially onboarded to the data lake. If you need assistance, [submit a support request](/defender-xdr/contact-defender-support). ### Capacity limitations in specific regions +If onboarding fails because of regional capacity limits, use the following workaround.+ - **Symptom**: Onboarding doesn't complete in specific regions due to capacity constraints.-- **Resolution**: Use an alternate [supported region](../geographical-availability-data-residency.md#supported-regions). Delete the current Log Analytics workspace, create a new workspace in a different region (for example, Central US), add Microsoft Sentinel, connect it as the **Primary** workspace in the Defender portal, and set up the data lake.+- **Resolution**: Use an alternate [supported region](../geographical-availability-data-residency.md#supported-regions).++ > [!WARNING]+ > Deleting a Log Analytics workspace can result in permanent data loss. Ensure you have appropriate backups or accept the data loss before proceeding.++ Delete the current Log Analytics workspace, create a new workspace in a different region (for example, Central US), add Microsoft Sentinel, connect it as the **Primary** workspace in the Defender portal, and set up the data lake. ### "Something went wrong" during setup +If setup fails with a generic error message, use the following checks to diagnose the issue.+ - **Symptom**: After selecting **Set up data lake**, the setup flow doesn't complete and you see an error "Something went wrong, Please try again." - **Resolution**: Check whether the resource group associated with the onboarded Sentinel workspace was previously deleted, or whether the subscription used for data lake billing was deleted or canceled. If the issue persists, [submit a support request](/defender-xdr/contact-defender-support). ### Sentinel workspace not visible in Defender +Check the following if your Sentinel workspace doesn't appear in the Defender portal.+ - **Scenario**: You created a Log Analytics workspace and added Sentinel, but the Defender portal doesn't show the workspace, or UI filters don't populate correctly. - **Resolution**: Verify the [required roles](sentinel-lake-onboarding.md#required-roles) end-to-end. The minimum combination is Security Administrator or higher in Entra ID, plus Azure Subscription Owner or (User Access Administrator + Microsoft Sentinel Contributor). 