Microsoft Sentinel
Cloud and workloads

Sentinel Solutions Delete

In brief

The documentation now states that deleting a solution does not delete active, cloned, saved, or custom items. The page date and authoring metadata were also updated.

What Defender admins need to know

No administrator action is required; the clarification helps set expectations when deleting solutions.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security operations center (SOC) analyst, I want to delete Microsoft Sentinel out-of-the-box content and solutions so that I can manage and customize my security monitoring environment effectively.

Delete the solution

Delete a solution and its content templates from the content hub or the manage solution view. This actionDeleting a solution doesn't delete active, cloned, saved, or custom items.

  1. In the content hub, select an installed solution.
  2. On the solutions details page, select Delete.