Microsoft Sentinel
Architecture and deployment

Customer intent: As an administrator I want to onboard to the Microsoft Sentinel data lake so that I can benefit from the storage and analysis capabi…

In brief

The article adds prerequisites and onboarding guidance for Sentinel data lake and graph, announces September 2026 cutoffs for onboarding or configuring data risk graph, and clarifies policy exemption and workspace offboarding behavior.

What Defender admins need to know

Administrators should account for the announced 2026 cutoffs. Azure Policy exemptions may be needed for the onboarding resource group, and disabling the data lake or offboarding individual workspaces requires Defender support.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Onboard to Microsoft Sentinel data lake and Microsoft Sentinel graph

The Microsoft Sentinel data lake is a tenant-wide repository for collecting, storing,store that collects and managing large volumes of security-relatedmanages security data from variousmany sources. It enables comprehensive,gives you unified analysis and visibility across your security landscape. Microsoft Sentinel graph is a unified graph capability withinfeature in the Microsoft Sentinel platform poweringplatform. It powers graph-based experiences across security, compliance, identity, and the entire ecosystem. These solutionsidentity. Microsoft Sentinel data lake and graph use advanced analytics, machine learning, graphs, and AI to help detect threats, investigate and respond to incidents, and improve overallyour security posture.

This article covers the prerequisites, required roles, and workspace requirements for onboarding to Microsoft Sentinel data lake and graph. Before you start, review the prerequisites section to make sure your environment is ready.

Microsoft Sentinel data lake and graph are available in the following solutions: - Microsoft Defender XDR

[!INCLUDE Customer-managed keys limitation]

To onboard to the Microsoft Sentinel data lake and graph in Microsoft Defender XDR, Data Security Investigations, and Insider Risk Management,Before you mustonboard, make sure you meet the followingthese prerequisites:

  • Microsoft Defender (security.microsoft.com) and Microsoft Sentinel must be configured. A Microsoft Defender XDR license isn't required to use Microsoft Sentinel data lake with Microsoft Sentinel in the Microsoft Defender portal.
  • An existing Azure subscription and Azure resource group to set up billing for the data lake. You must be the direct subscription owner - being the management-group-level subscription owner isn't sufficient. You can use your existing Microsoft Sentinel SIEM Azure subscription and resource group or create a new one. To learn more about billing, see Plan costs and understand Microsoft Sentinel pricing and billing.

Other prerequisites for Microsoft Purview

For Microsoft Purview scenarios, you must also meet the following prerequisites before onboarding:

  • Contributor access to the Microsoft Sentinel primary workspace to authorize ingestion of your Microsoft 365 activity data to the primary workspace.

Policy exemption for Microsoft Sentinel data lake onboarding

During onboarding of Microsoft Sentinel data lake, existing Azure Policy definitions might block deployment (DL103)

For Microsoft Purview scenarios, you must also meet the following prerequisites before onboarding:

  • Contributor access to the Microsoft Sentinel primary workspace to authorize ingestion of your Microsoft 365 activity data to the primary workspace.

Policy exemption for Microsoft Sentinel data lake onboarding

Existing Azure Policy definitions might block deployment (DL103) of required resources.resources during onboarding. To ensure successful onboarding without compromising broader policy enforcement, configureavoid this issue, create a policy exemption scoped tofor the resource group you're onboarding. Specifically, exemptExempt the resource type: Microsoft.SentinelPlatformServices/sentinelplatformservices.

This policy exemption for the Microsoft.SentinelPlatformServices/sentinelplatformservices resource type allowslets Sentinel data lake's components to deploy correctly, while maintaining compliance with overarchingcorrectly. Your other Azure governance policies you might have already applied.stay in effect.

How data is added and stored during onboarding

During onboarding, your data lake is provisioned in the same supported region as your primary Sentinel workspace. We might also automatically enable Microsoft Entra, Microsoft 365, and Azure Resource Graph asset data. If Microsoft Entra, Microsoft 365, or Azure Resource Graph asset data isn't in the same region as the data lake, by onboarding to the data lake,means you consent to ingest and store that asset data in the region where your data lake resides soregion. This lets you can use itthe data with Microsoft Sentinel data lake and graph experiences. Your asset data areis available through System tables, which youbuilt-in tables that store ingested asset data. You can select these tables in the workspace selection UI in the Lake exploration experiences. For more information, see Geographical availability and data residency in Microsoft Sentinel.

How onboarding affects existing Microsoft Sentinel workspaces

You must connect your Microsoft Sentinel primary workspace to the Defender portal to onboard to the data lake. Your data lake is located in the same region as your primary Sentinel workspace. You can connect other workspaces in the same region as your primary workspace to the Defender portal so you can use them with the data lake. If you onboarded to the data lake, data in Microsoft Sentinel workspaces that are connected to Defender and enabled for use with the data lake. For more information on how toTo connect a Microsoft Sentinel workspace to the Defender portal, see Connect Microsoft Sentinel to the Microsoft Defender portal.

You can't choose which workspaces to onboard to the data lake. All workspaces connected to Defender in the same region as your primary Sentinel workspace are onboarded automatically. You can't offboard specific workspaces from the data lake on your own. If you want to offboard a workspace, submit a Microsoft Defender support request.

Offboard from Microsoft Sentinel data lake and graph

You can't offboard individual workspaces or disable the data lake on your own. To disable Microsoft Sentinel data lake and graph, submit a Microsoft Defender support request.

Start the onboarding process

For step-by-step guidance to onboard and configure Microsoft Sentinel data lake and graphTo get started, follow the steps in Microsoft solutions, see the followingone of these articles:

Related content