Microsoft has officially started moving Sentinel, its flagship cloud-native SIEM, into the Microsoft Defender portal.
This shift isn’t just cosmetic; it’s a full consolidation of Microsoft’s security ecosystem under one roof.
By July 2026, the classic Azure Sentinel view will be retired. That means every security investigation, analytic rule, and incident correlation will happen inside the Defender portal.
For SOC teams, this is more than a UI change, it’s a new workflow reality.
Earlier this year, Microsoft announced a major step toward unifying its security ecosystem, bringing Microsoft Sentinel directly into the Microsoft Defender portal.
The goal? To simplify how SOC teams investigate, correlate, and respond to threats across Microsoft’s security stack.
Until now, Sentinel was managed entirely through the Azure portal, operating separately from the rest of the Defender suite.
But starting July 2025, new Sentinel workspaces will automatically connect to the Defender portal, and existing ones can begin transitioning ahead of the July 2026 retirement of the old interface.
This means that Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Sentinel will all live under one roof, a single dashboard for detection, response, and hunting.
Benefits for
Security Teams
Unified security operations: View and manage all Defender & Sentinel incidents in one queue.
Improved detection correlation: Defender alerts automatically correlate with Sentinel incidents.
Simplified workflows: Analysts can investigate and hunt within one interface, no more portal switching.
Consistent permissions: Unified permissions across Defender XDR and Sentinel.
Reliable synchronization: Changes to incidents are reflected instantly across both platforms.
How to Enable Microsoft Sentinel Integration
in the Defender Portal
Microsoft has made it easier than ever to manage all your security tools from one place.
Here’s a quick walkthrough of how to connect Microsoft Sentinel to the Microsoft Defender portal and start using the unified experience.
1. Check Roles and Permissions
Before you begin, make sure the right permissions are in place for the admin performing the setup.
Tenant-level (Microsoft Entra ID):
You’ll need one of the following roles:
Global Administrator
Security Administrator
Azure-level (Subscription or Resource Group):
And one of these:
Owner
Contributor
User Access Administrator
These permissions let you modify Sentinel workspace settings and authorize the Defender connection.
2. Confirm Prerequisites
Make sure your environment meets the requirements before connecting:
Microsoft Sentinel is deployed and active in a Log Analytics workspace
You have a valid Defender XDR or Microsoft 365 E5 license
Your Sentinel workspace region is supported (most commercial regions are)
If you don’t have Defender XDR, the connection will still work but incident correlation will be limited.
3. Choose the Primary Workspace
You can connect multiple Sentinel workspaces, but only one will act as the Primary workspace.
The primary workspace provides full integration with Defender XDR, including unified incidents and correlation. Secondary workspaces will still collect and analyze data but with limited visibility inside Defender.
You’ll be prompted to connect a Sentinel workspace.
Step 2: Select your workspace
Choose the workspace you want to connect, then click Next.
Step 3: Set the Primary workspace
Select the workspace that will act as your Primary connection and click Next.
Step 4: Review and confirm
Double-check your configuration and click Connect.
Step 5: Confirm the connection
You’ll see a final confirmation dialog asking you to approve the connection.
Click Connect again to proceed, or Cancel if you want to make changes.
Step 6: Finish setup
Once the connection completes, the final screen will display your newly connected workspace.
Click Close to exit.
Note: It may take up to 24 hours for all menu options and data to appear after integration.
Step 7: Manage your workspaces
To view or modify connected workspaces at any time, go to Settings → Microsoft Sentinel in the left-hand menu.
Here you can review all connected workspaces, switch the Primary if needed, or disconnect a workspace.
Impacted
Technologies
This integration involves several key Microsoft technologies that work together to deliver the new unified experience:
Microsoft Sentinel – Cloud-native SIEM providing analytics, automation, and detection.
Microsoft Defender XDR – Centralized incident and response management.
Microsoft Entra ID – Provides identity and access control for integration permissions.
Azure Log Analytics – Stores and manages the telemetry data powering Sentinel analytics.
Together, they form the foundation of the modern Microsoft SOC ecosystem.
Why This
Is Important
This integration fundamentally changes how SOCs operate within Microsoft’s security ecosystem.
By centralizing visibility, response, and detection in one platform, organizations can:
Reduce alert fatigue and duplicated workflows
Improve cross-product correlation and incident response speed
Lower operational overhead from maintaining separate portals
From a business standpoint, it strengthens threat visibility, simplifies access management, and enhances compliance readiness, all critical for enterprises managing complex hybrid environments.
How Wizard Cyber Can Help
As a Microsoft Solutions Partner for Security, Wizard Cyber helps organizations transition smoothly to this new unified SOC environment by providing:
End-to-End Migration Planning
Our experts assess your current setup, plan the optimal migration path, and ensure a smooth transition to the unified Defender portal with minimal disruption.
24/7 Monitoring and Managed Detection & Response (MDR)
Continuous monitoring powered by Microsoft Defender XDR and Sentinel ensures that every alert is analyzed, prioritized, and acted upon — day or night.
Proactive Threat Hunting and Detection Engineering
We fine-tune detection rules and leverage Microsoft’s new unified telemetry to identify threats faster and reduce false positives.
Security Governance and Identity Management
Through Entra ID and role-based governance reviews, we help strengthen access control, privilege management, and compliance posture.
Automation and Optimization Workshops
We help SOC teams modernize their processes with playbooks, automation, and AI-driven workflows that maximize the value of the unified platform.
Strategic Advisory and Enablement
Beyond implementation, our consultants partner with your leadership team to align Microsoft’s security capabilities with your business goals and digital-transformation roadmap.
Why Partner with
Wizard Cyber?
Because technology alone isn’t enough, success comes from combining the right tools with the right people and strategy.
Our clients trust us to deliver:
Proven Microsoft expertise backed by real-world SOC experience.
A proactive, partnership-first approach.
Tangible improvements in visibility, efficiency, and resilience.
Whether you’re planning the migration or already operating within the Defender portal, Wizard Cyber can help you stay ahead of threats and make the most of your Microsoft security investment.
Ready to
Get Started?
The integration between Microsoft Sentinel and the Defender portal marks a major milestone for modern SOCs, and it’s the perfect time to strengthen your organization’s security foundation.
If you’re looking to simplify operations, gain unified visibility, and enhance detection capabilities, Wizard Cyber is ready to help.
Get in touch with our team today to schedule a consultation or learn how we can tailor Microsoft’s security solutions to your environment.
Together, we’ll help you build a smarter, faster, and more resilient SOC.