Microsoft Sentinel
Cloud and workloads

Move To Defender

In brief

The article’s metadata, role link, multitenant portal name, connector-routing wording, and analytics-rule reference were updated.

What Defender admins need to know

Administrators following the transition guidance will see refreshed terminology and cross-references.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Microsoft Sentinel is available in the Microsoft Defender portal with Microsoft Defender XDR or on its own. It delivers a unified experience across SIEM and XDR for faster, more accurate threat detection and response, simpler workflows, and better operational efficiency.

This article explains how to transition your Microsoft Sentinel experience from the Azure portal to the Defender portal. If you use Microsoft Sentinel in the Azure portal, transition to Microsoft Defender for unified security operations and the latest features. Before you begin, review the Prerequisites for transitioning to the Defender portal section for required access and preparatory steps. For more information, see Microsoft Sentinel in the Microsoft Defender portal or watch our Microsoft Sentinel in the Defender portal video playlist.

Before you start, note:

Configure multi-workspace and multitenant management

Defender supports one or more workspaces across multiple tenants through the Microsoft Defender multitenant portal, which serves as a central place to manage incidents and alerts, hunt for threats across tenants, and lets Managed Security Service Partners (MSSPs) see across customers.

In multi-workspace scenarios, the multitenant portal lets you connect one primary workspace and multiple secondary workspaces per tenant. Onboard each workspace to the Defender portal separately for each tenant, just like onboarding for a single tenant.

Alerts related to Defender products are streamed directly from the Microsoft Defender connector to ensure consistency. Make sure that you have incidents and alerts from this connector turned on in your workspace. Once you have this data connector configured in your workspace, offboarding the workspace from Microsoft Defender also disconnects the Microsoft Defender connector.

To migrate analytics rule incident creation and alert grouping settings, see Migrate Microsoft Sentinel incident creation rules and alert grouping settings to Defender XDR.

Configure analytics rules

Microsoft Sentinel analytics rules are available in the Defender portalavailable in the Defender portal for detection, configuration, and management. For more information, see Microsoft Sentinel configuration in the Defender portal. The functionalities of analytics rules remain the same, including creation, updating, and management through the wizard, repositories, and the Microsoft Sentinel API. Incident correlation and multi-stage attack detection also continue to work in the Defender portal. The alert correlation functionality managed by the Fusion analytics rule in the Azure portal is handled by the Defender XDR engine in the Defender portal, which consolidates all signals in one place.

When moving to the Defender portal, the following changes are important to note:

Feature Description
Custom detection rules If you have detection use cases that involve both Defender XDR and Microsoft Sentinel data, where you don't need to retain Defender XDR data for more than 30 days, we recommend creating custom detection rules that query data from both Microsoft Sentinel and Defender XDR tables.

ThisCreating custom detection rules that query both sources is supported without needing to ingest Defender XDR data into Microsoft Sentinel. For more information, see Use Microsoft Sentinel custom functions in advanced hunting in Microsoft Defender.
Alert correlation In the Defender portal, correlations are automatically applied to alerts against both Microsoft Defender data and third-party data ingested from Microsoft Sentinel, regardless of alert scenarios.

The criteria used to correlate alerts together in a single incident are part of the Defender portal's proprietary, internal correlation logic. For more information, see Alert correlation and incident merging in the Defender portal.
Alert grouping and incident merging While you will still see the alert grouping configuration in Analytics rules, the Defender XDR correlation engine fully controls alert grouping and incident merging when necessary in the Defender portal. This ensures a comprehensive view of the full attack story by stitching together relevant alerts for multi-stage attacks.

For example, multiple individual analytics rules configured to generate an incident for each alert may result in merged incidents if they match Defender XDR correlation logic.
Alert visibility If you have Microsoft Sentinel analytics rules configured to trigger alerts only (see Configure incident creation settings), with incident creation turned off, these alerts aren't visible in the Defender portal.
Alert tuning Once your Microsoft Sentinel workspace is onboarded to Defender, all incidents, including those from your Microsoft Sentinel analytics rules, are generated by the Defender XDR engine. As a result, the alert tuning capabilities in the Defender portal, previously available only for Defender XDR alerts, can now be applied to alerts from Microsoft Sentinel.

This featureAlert tuning allows you to streamline incident response by automating the resolution of common alerts, reducing false positives, and minimizing noise, so analysts can prioritize significant security incidents.
Fusion: Advanced multistate attack detection The Fusion analytics rule, which in the Azure portal, creates incidents based on alert correlations made by the Fusion correlation engine, is disabled when you onboard Microsoft Sentinel to the Defender portal.

You don't lose alert correlation functionality because the Defender portal uses Microsoft Defender XDR's incident-creation and correlation functionalities to replace those of the Fusion engine.

For more information, see Advanced multistage attack detection in Microsoft Sentinel

Configure automation rules and playbooks

Feature Description
Threat analytics Supported for Microsoft Defender XDR customers. An in-product solution provided by Microsoft security researchers, designed to help security teams by offering insights on emerging threats, active threats, and their impacts. The data is presented in an intuitive dashboard with cards, rows of data, filters, and more.
Intel Profiles Supported for Microsoft Defender Threat IntelligenceMicrosoft Defender Threat Intelligence customers. Categorize threats and behaviors by a Threat Actor Profile, making it easier to track and correlate. These profiles include any Indicators of Compromise (IoC) related to tactics, techniques, and tools used in attacks.
Intel Explorer Supported for Microsoft Defender Threat IntelligenceMicrosoft Defender Threat Intelligence customers. Consolidates available IoCs and provides threat-related articles as they are posted, enabling security teams to stay updated on emerging threats.
Intel Projectsprojects Supported for Microsoft Defender Threat Intelligence customers. Allows teams to consolidateDeprecated. To organize and investigate threat intelligence into a 'project' for reviewing all artifacts related to a specific scenario of interest.indicators, link indicators to a case.

In the Defender portal, use the ThreatIntelOjbects and ThreatIntelIndicators together with Indicators for Compromise for threat hunting, incident response, Copilot, reporting, and to create relational graphs showing connections between indicators and entities.

Use workbooks to visualize and report on Microsoft Defender data

Similar incidents (Preview) aren't supported in the Defender portal

The Microsoft Sentinel similar incidents in case investigations feature is in Preview and isn't supported in the Defender portal. This means that when viewing an incident details pageBecause this feature isn't supported in the Defender portal, the Similar incidents tab isn't available.available when viewing an incident details page.

Related content