Microsoft Sentinel
Architecture and deployment

How to onboard to the Microsoft Sentinel data lake

In brief

Adds a how-to guide for onboarding a tenant through the Microsoft Defender portal, including workspace setup, roles, regional requirements, and setup steps.

What Defender admins need to know

Administrators planning onboarding can use the guide to verify permissions and region selection. Onboarding takes about 60 minutes, and the region cannot be changed through the portal afterward.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

new file mode 100644

title: How to onboard to the Microsoft Sentinel data lake description: Onboard your tenant to the Microsoft Sentinel data lake from the Microsoft Defender portal so you can ingest and analyze security data. ms.author: edbaynash author: EdB-MSFT ms.reviewer: smarapareddy ms.date: 06/22/2026 ms.topic: how-to ms.service: microsoft-sentinel ms.subservice: sentinel-platform ai-usage: ai-assisted ms.custom: msecd-doc-authoring-1012

#customer intent: As an ISV developer, I want to onboard my tenant to the Microsoft Sentinel data lake so that I can ingest and analyze security data.

How to onboard to the Microsoft Sentinel data lake

Before developing platform solutions you need to onboard your tenant to the Microsoft Sentinel data lake. Onboard your tenant to the Microsoft Sentinel data lake from the Microsoft Defender portal. Onboarding is a one-time process that takes about 60 minutes and connects a Log Analytics workspace and sets up the data lake for your tenant. After you onboard, you can ingest security telemetry into the data lake and query it in later articles in this series.

Prerequisites

  • Access to the Microsoft Defender portal.
  • Decide on data lake region. The data lake is onboarded in the same region as your primary Sentinel workspace. Check your workspace's region before you start and ensure that the region is suitable for the data lake. For more information, see Supported regions.
Operation Required role
Onboarding to the Sentinel data lake Microsoft Entra ID - Security Administrator or Global Administrator
Onboard Sentinel workspace to Defender portal Subscription Owner, or User Access Administrator at subscription scope and Microsoft Sentinel Contributor at subscription or resource group scope
Onboard Sentinel workspace to Data Lake Subscription Owner or Microsoft Sentinel Contributor at subscription or resource group scope

Create a Log Analytics workspace

Before you onboard to the data lake, you need to create or identify a Log Analytics workspace to which Microsoft sentinel can be added. If you already have a workspace in a data lake supported region, you can skip workspace creation and move to the next step.

  1. If you don’t have a workspace, follow the steps in Create a Log Analytics workspace to create a workspace. Select the region of your Log Analytics workspace from the supported regions for the data lake, such as East US 2.

  2. Add Sentinel to the Log Analytics Workspace by following the steps in Add Microsoft Sentinel to your Log Analytics workspace.

Connect the workspace to the Defender portal and set it as primary

To connect your Sentinel workspace and set it as primary, complete the following steps:

  1. Sign in to the Microsoft Defender portal.

  2. Under System > Settings > Microsoft Sentinel select SIEM workspaces

  3. Select your Sentinel workspace and select Connect workspace.

  4. Set the workspace as Primary.

:::image type="content" source="./media/sentinel-data-lake-onboarding/connect-workspace.png" alt-text="Screenshot of the SIEM workspaces page with a workspace selected and the Connect workspace button highlighted." lightbox="./media/sentinel-data-lake-onboarding/connect-workspace.png":::

Start onboarding from the Defender portal

After your workspace is connected, start the onboarding process in the Defender portal.

  1. In the Microsoft Defender portal, under System > Settings select Microsoft Sentinel then select Data lake

  2. Select Start setup. If a side panel indicates missing permissions, verify that you have the roles listed in Prerequisites.

    :::image type="content" source="./media/sentinel-data-lake-onboarding/start-setup.png" alt-text="Screenshot of the Data lake page in the Defender portal with the Start setup button highlighted." lightbox="./media/sentinel-data-lake-onboarding/start-setup.png":::

Select a subscription and resource group

Choose where to enable billing for the data lake.

  1. In the setup side panel, select your target Subscription.

  2. Select the target Resource group to enable billing for the Sentinel data lake.

  3. Select Set up data lake.

    :::image type="content" source="./media/sentinel-data-lake-onboarding/set-up-data-lake.png" alt-text="Screenshot of the Set up Sentinel data lake panel showing the Subscription and Resource group fields and the Setup data lake button." lightbox="./media/sentinel-data-lake-onboarding/set-up-data-lake.png":::

Monitor onboarding progress

After you start the setup, a progress panel appears.

  1. Wait for the onboarding process to finish. Onboarding might take up to 60 minutes to complete.
  2. You can close the setup panel. The process continues in the background, and a Setup in progress banner appears on the Defender portal home page.

Validate onboarding

After the setup completes, confirm the data lake is ready:

  1. In the Defender portal > SIEM workspaces, confirm your Sentinel workspace appears as Connected and Primary.
  2. Confirm the Data lake settings page loads without errors and shows your configured subscription and resource group.
  3. Under Microsoft Sentinel in the left navigation bar, confirm the Data lake exploration options are available.

For more information, see Onboard to Microsoft Sentinel data lake from the Defender portal.

Verify the onboarding

Confirm that your data lake is ready to use.

  1. When onboarding finishes, a new banner appears with cards that describe how to use your data lake.

  2. Confirm that Data lake exploration is available under Microsoft Sentinel.

    :::image type="content" source="./media/sentinel-data-lake-onboarding/data-lake-exploration.png" alt-text="Screenshot of the Microsoft Sentinel menu with the Data lake exploration section highlighted in the Defender portal." lightbox="./media/sentinel-data-lake-onboarding/data-lake-exploration.png":::

Next step

[!div class="nextstepaction"] Ingest data to the Microsoft Sentinel data lake