You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/includes/unified-soc-preview-without-alert.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,4 +9,4 @@ ms.author: bagol
9
9
ms.custom: "include file"
10
10
---
11
11
12
-
New customers onboarding after July 1, 2025 with the relevant permissions are automatically onboarded to the Microsoft Defender portal and access Microsoft Sentinel in the Azure portal only. Existing customers, and new users without relevant permissions, can continue to use Microsoft Sentinel in the Azure portal. We recommend that you onboard to the Microsoft Defender portal for a unified security operations (SecOps) experience. For more information, see [Sunset timeline for Microsoft Sentinel in the Azure portal (new customers only)](../microsoft-sentinel-defender-portal.md#sunset-timeline-for-microsoft-sentinel-in-the-azure-portal-new-customers-only).
12
+
New customers onboarding after **July 1, 2025** with the relevant permissions are automatically onboarded to the Microsoft Defender portal and access Microsoft Sentinel in the Azure portal only. Existing customers, and new users without relevant permissions, can continue to use Microsoft Sentinel in the Azure portal. Starting in **July 2026**, all customers using Microsoft Sentinel in the Azure portal will be redirected to the Defender portal. We recommend that you start planning your transition to the Defender portal to ensure a smooth transition and take full advantage of the new features offered by Microsoft Defender. For more information, see [Microsoft Sentinel in the Azure portal deprecation timeline](../overview.md#microsoft-sentinel-in-the-azure-portal-deprecation-timeline).
Copy file name to clipboardExpand all lines: articles/sentinel/includes/unified-soc-preview.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -10,8 +10,8 @@ ms.custom: "include file"
10
10
---
11
11
12
12
> [!IMPORTANT]
13
-
>New customers onboarding after July 1, 2025 with the relevant permissions are automatically onboarded to the Microsoft Defender portal and access Microsoft Sentinel in the Azure portal only.
13
+
>New customers onboarding after **July 1, 2025** with the relevant permissions are automatically onboarded to the Microsoft Defender portal and access Microsoft Sentinel in the Azure portal only. Existing customers, and new users without relevant permissions, can continue to use Microsoft Sentinel in the Azure portal.
14
14
>
15
-
>Existing customers, and new users without relevant permissions, can continue to use Microsoft Sentinel in the Azure portal. We recommend that you onboard to the Microsoft Defender portal for a unified security operations (SecOps) experience.
15
+
>Starting in **July 2026**, all customers using Microsoft Sentinel in the Azure portal will be redirected to the Defender portal. We recommend that you start planning your transition to the Defender portal to ensure a smooth transition and take full advantage of the new features offered by Microsoft Defender.
16
16
>
17
-
>For more information, see [Sunset timeline for Microsoft Sentinel in the Azure portal (new customers only)](../microsoft-sentinel-defender-portal.md#sunset-timeline-for-microsoft-sentinel-in-the-azure-portal-new-customers-only).
17
+
>For more information, see [Microsoft Sentinel in the Azure portal deprecation timeline](../overview.md#microsoft-sentinel-in-the-azure-portal-deprecation-timeline).
The following table describes the new or improved capabilities available in the Defender portal with the integration of Microsoft Sentinel. Microsoft continues to innovate in this new experience with features that might be exclusive to the Defender portal.
@@ -43,21 +45,6 @@ When you onboard Microsoft Sentinel to the Defender portal without Defender XDR
43
45
-[Custom detection rules](/defender-xdr/custom-detections-overview), provided by Microsoft Defender XDR
44
46
- The [Action center](/defender-xdr/m365d-action-center), provided by Microsoft Defender XDR
45
47
46
-
47
-
## Sunset timeline for Microsoft Sentinel in the Azure portal (new customers only)
48
-
49
-
Microsoft Sentinel is generally available in the Microsoft Defender portal, including for customers without Microsoft Defender XDR or an E5 license. This means that you can use Microsoft Sentinel in the Defender portal even if you aren't using other Microsoft Defender services.
50
-
51
-
Starting in July 2025, new customers onboarding to Microsoft Sentinel with permissions of a subscription [Owner](/azure/role-based-access-control/built-in-roles#owner) or a [User access administrator](/azure/role-based-access-control/built-in-roles#user-access-administrator) are automatically onboarded to the Defender portal, and use Microsoft Sentinel in the Defender portal only.
52
-
53
-
Existing customers and other new customers without the relevant permissions, such as Azure-Lighthouse delegated users, can continue using Microsoft Sentinel in the Azure portal. However, we recommend that you [onboard to the Defender portal](/defender-xdr/microsoft-sentinel-onboard) for a [unified security operations experience](/unified-secops-platform/overview-unified-security). For more information, see [Transition your Microsoft Sentinel environment to the Defender portal](move-to-defender.md).
54
-
55
-
In most cases, users of workspaces that are automatically onboarded to the Defender portal use Microsoft Sentinel in the Defender portal only, and are redirected to the Defender portal from Microsoft Sentinel in the Azure portal. The exception is for Azure Lighthouse-delegated users who are accessing a new customer workspace onboarded to Microsoft Sentinel in the Azure portal. These users won't see the automatic redirection and can work in the Azure portal.
56
-
57
-
When manually onboarding to the Defender portal, you must onboard each workspace individually. When working with multiple workspaces and other Defender services, make sure to define the primary workspace where you want to correlate Microsoft Sentinel incidents with Microsoft Defender incidents. View incidents in other workspaces separately.
58
-
59
-
For more information, see [Onboard Microsoft Sentinel](quickstart-onboard.md) and [Multiple Microsoft Sentinel workspaces in the Defender portal](workspaces-defender-portal.md).
60
-
61
48
## Quick reference
62
49
63
50
Some Microsoft Sentinel capabilities, like the unified incident queue, are integrated with Microsoft Defender XDR in the Defender portal. Many other Microsoft Sentinel capabilities are available in the **Microsoft Sentinel** section of the Defender portal.
Copy file name to clipboardExpand all lines: articles/sentinel/overview.md
+20Lines changed: 20 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -120,6 +120,26 @@ The following table highlights the key capabilities in Microsoft Sentinel for th
120
120
|Automation rules|Centrally manage the automation of incident handling in Microsoft Sentinel by defining and coordinating a small set of rules that cover different scenarios. |[Automate threat response in Microsoft Sentinel with automation rules](automate-incident-handling-with-automation-rules.md)|
121
121
|Playbooks|Automate and orchestrate your threat response by using playbooks, which are a collection of remediation actions. Run a playbook on-demand or automatically in response to specific alerts or incidents, when triggered by an automation rule. <br><br> To build playbooks with Azure Logic Apps, choose from a constantly expanding gallery of connectors for various services and systems like ServiceNow, Jira, and more. These connectors allow you to apply any custom logic in your workflow. |[Automate threat response with playbooks in Microsoft Sentinel](automate-responses-with-playbooks.md)<br><br>[List of all Logic App connectors](/connectors/connector-reference/connector-reference-logicapps-connectors)|
122
122
123
+
## Microsoft Sentinel in the Azure portal deprecation timeline
124
+
125
+
Microsoft Sentinel is generally available in the Microsoft Defender portal, including for customers without Microsoft Defender XDR or an E5 license. This means that you can use Microsoft Sentinel in the Defender portal even if you aren't using other Microsoft Defender services. We recommend that all customers still working in the Azure portal start planning to [onboard to the Defender portal](/defender-xdr/microsoft-sentinel-onboard) for a [unified security operations experience](/unified-secops-platform/overview-unified-security). For more information, see [Transition your Microsoft Sentinel environment to the Defender portal](move-to-defender.md).
126
+
127
+
### Changes for new customers
128
+
129
+
Starting in **July 2025**, new customers [onboarding to Microsoft Sentinel](quickstart-onboard.md) with permissions of a subscription [Owner](/azure/role-based-access-control/built-in-roles#owner) or a [User access administrator](/azure/role-based-access-control/built-in-roles#user-access-administrator) are automatically onboarded to the Defender portal, and use Microsoft Sentinel in the Defender portal only.
130
+
131
+
Existing customers and other new customers without the relevant permissions, such as Azure-Lighthouse delegated users, can continue using Microsoft Sentinel in the Azure portal until they onboard to the Defender protal.
132
+
133
+
In most cases, users of workspaces that are automatically onboarded to the Defender portal use Microsoft Sentinel in the Defender portal only, and are redirected to the Defender portal from Microsoft Sentinel in the Azure portal. The exception is for Azure Lighthouse-delegated users who are accessing a new customer workspace onboarded to Microsoft Sentinel in the Azure portal. These users won't see the automatic redirection and can work in the Azure portal.
134
+
135
+
When manually onboarding to the Defender portal, you must onboard each workspace individually. When [working with multiple workspaces and other Defender services](workspaces-defender-portal.md), make sure to define the primary workspace where you want to correlate Microsoft Sentinel incidents with Microsoft Defender incidents. View incidents in other workspaces separately.
136
+
137
+
### Changes for existing customers
138
+
139
+
Starting in **July 2026**, Microsoft Sentinel will be supported in the Defender portal only, and any remaining customers using the Azure portal will be automatically redirected.
140
+
141
+
If you're currently using Microsoft Sentinel in the Azure portal, we recommend that you start planning your migration to the Defender portal now to ensure a smooth transition and take full advantage of the new features offered by Microsoft Defender.
142
+
123
143
## Related content
124
144
125
145
-[Onboard Microsoft Sentinel](quickstart-onboard.md)
Copy file name to clipboardExpand all lines: articles/sentinel/whats-new.md
+18-1Lines changed: 18 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -22,13 +22,30 @@ The listed features were released in the last six months. For information about
22
22
23
23
-[For new customers only: Automatic onboarding and redirection to the Microsoft Defender portal](#for-new-customers-only-automatic-onboarding-and-redirection-to-the-microsoft-defender-portal)
24
24
25
+
### Microsoft Sentinel in the Defender portal to be deprecated July 2026
26
+
27
+
Microsoft is transitioning Microsoft Sentinel from the Azure portal to the Microsoft Defender portal to provide a unified, efficient, and modern experience for security teams. This move integrates Microsoft Sentinel with Microsoft Defender's extensive threat protection capabilities, enhancing security outcomes.
28
+
29
+
Starting in July 2026, Microsoft Sentinel will be supported only in the Microsoft Defender portal, and any remaining customers in the Azure portal will be automatically redirected to the Defender portal. We recommend that such customers start planning their migration to the Defender portal to ensure a smooth transition and take full advantage of the new features offered by Microsoft Defender.
30
+
31
+
For more information, see:
32
+
33
+
-[Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md)
34
+
-[Transition your Microsoft Sentinel environment to the Defender portal](move-to-defender.md)
35
+
-[Microsoft Sentinel in the Azure portal deprecation timeline](overview.md#microsoft-sentinel-in-the-azure-portal-deprecation-timeline)
36
+
-[It’s Time to Move: Retiring Microsoft Sentinel’s Azure Portal for Greater Security](blog)
37
+
25
38
### For new customers only: Automatic onboarding and redirection to the Microsoft Defender portal
26
39
27
40
New customers onboarding to Microsoft Sentinel with the permissions of a subscription [Owner](/azure/role-based-access-control/built-in-roles#owner) or a [User access administrator](/azure/role-based-access-control/built-in-roles#user-access-administrator) now automatically have their workspaces onboarded to the Microsoft Defender portal. Users of such workspaces access Microsoft Sentinel in the Defender portal only, and accessing Microsoft Sentinel in the Azure portal automatically shows redirection links to Defender.
28
41
29
42
This change streamlines the onboarding process and ensures that new customers can immediately take advantage of unified security operations capabilities without the extra step of manually onboarding their workspaces.
30
43
31
-
For more information, see [Onboard Microsoft Sentinel](quickstart-onboard.md) and [Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md).
44
+
For more information, see:
45
+
46
+
-[Onboard Microsoft Sentinel](quickstart-onboard.md)
47
+
-[Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md)
48
+
-[Changes for new customers](overview.md#changes-for-new-customers)
0 commit comments