Skip to content

Commit ccc9f01

Browse files
authored
Merge pull request #302081 from batamig/sentinel-azure-sunset
Sentinel azure sunset - sentinel docs
2 parents e6a4cfb + f8ddcfd commit ccc9f01

File tree

5 files changed

+46
-12
lines changed

5 files changed

+46
-12
lines changed
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
---
2+
title: Microsoft Sentinel in the Azure portal retirement announcement
3+
description: Provides an include file for reuse of the Microsoft Sentinel in the Azure portal retirement announcement.
4+
services: microsoft-sentinel
5+
author: batamig
6+
ms.topic: "include"
7+
ms.date: 07/01/2025
8+
ms.author: bagol
9+
ms.custom: "include file"
10+
---
11+
12+
13+
Microsoft Sentinel is [generally available in the Microsoft Defender portal](../microsoft-sentinel-defender-portal.md), including for customers without Microsoft Defender XDR or an E5 license. This means that you can use Microsoft Sentinel in the Defender portal even if you aren't using other Microsoft Defender services.
14+
15+
Starting in **July 2026**, Microsoft Sentinel will be supported in the Defender portal only, and any remaining customers using the Azure portal will be automatically redirected.
16+
17+
If you're currently using Microsoft Sentinel in the Azure portal, we recommend that you start planning your transition to the Defender portal now to ensure a smooth transition and take full advantage of the [unified security operations experience offered by Microsoft Defender](/unified-secops-platform/overview-unified-security).
18+
19+
For more information, see:
20+
21+
- [Microsoft Sentinel in the Microsoft Defender portal](../microsoft-sentinel-defender-portal.md)
22+
- [Transition your Microsoft Sentinel environment to the Defender portal](../move-to-defender.md)
23+
- [Planning your move to Microsoft Defender portal for all Microsoft Sentinel customers](https://techcommunity.microsoft.com/blog/microsoft-security-blog/planning-your-move-to-microsoft-defender-portal-for-all-microsoft-sentinel-custo/4428613) (blog)
Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: "include file"
3-
description: "include file"
2+
title: General Microsoft Sentinel Azure portal retirement announcement, with no extra formatting.
3+
description: Provides an include file for the general Microsoft Sentinel Azure portal retirement announcement, with no extra formatting.
44
services: microsoft-sentinel
55
author: batamig
66
ms.topic: "include"
@@ -9,4 +9,4 @@ ms.author: bagol
99
ms.custom: "include file"
1010
---
1111

12-
Microsoft Sentinel is generally available in the Microsoft Defender portal, including for customers without Microsoft Defender XDR or an E5 license. For more information, see [Microsoft Sentinel in the Microsoft Defender portal](../microsoft-sentinel-defender-portal.md).
12+
[Microsoft Sentinel is generally available in the Microsoft Defender portal](../microsoft-sentinel-defender-portal.md), including for customers without Microsoft Defender XDR or an E5 license. Starting in **July 2026**, Microsoft Sentinel will be supported in the Defender portal only, and any remaining customers using the Azure portal will be automatically redirected. We recommend that any customers using Microsoft Sentinel in Azure start planning the [transition to the Defender portal](../move-to-defender.md) for the full [unified security operations experience offered by Microsoft Defender](/unified-secops-platform/overview-unified-security). For more information, see [Planning your move to Microsoft Defender portal for all Microsoft Sentinel customers](https://techcommunity.microsoft.com/blog/microsoft-security-blog/planning-your-move-to-microsoft-defender-portal-for-all-microsoft-sentinel-custo/4428613) (blog).
Lines changed: 9 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
---
2-
title: "include file"
3-
description: "include file"
2+
title: General Microsoft Sentinel Azure portal retirement announcement, with extra formatting.
3+
description: Provides an include file for the general Microsoft Sentinel Azure portal retirement announcement, with extra formatting.
44
services: microsoft-sentinel
55
author: batamig
66
ms.topic: "include"
7-
ms.date: 10/16/2024
7+
ms.date: 07/01/2025
88
ms.author: bagol
99
ms.custom: "include file"
1010
---
1111

1212
> [!IMPORTANT]
13-
> Microsoft Sentinel is generally available in the Microsoft Defender portal, including for customers without Microsoft Defender XDR or an E5 license. For more information, see [Microsoft Sentinel in the Microsoft Defender portal](../microsoft-sentinel-defender-portal.md).
13+
> [Microsoft Sentinel is generally available in the Microsoft Defender portal](../microsoft-sentinel-defender-portal.md), including for customers without Microsoft Defender XDR or an E5 license.
14+
>
15+
> Starting in **July 2026**, Microsoft Sentinel will be supported in the Defender portal only, and any remaining customers using the Azure portal will be automatically redirected.
16+
>
17+
> We recommend that any customers using Microsoft Sentinel in Azure start planning the [transition to the Defender portal](../move-to-defender.md) for the full [unified security operations experience offered by Microsoft Defender](/unified-secops-platform/overview-unified-security). For more information, see [Planning your move to Microsoft Defender portal for all Microsoft Sentinel customers](https://techcommunity.microsoft.com/blog/microsoft-security-blog/planning-your-move-to-microsoft-defender-portal-for-all-microsoft-sentinel-custo/4428613).
18+

articles/sentinel/overview.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -20,10 +20,6 @@ Microsoft Sentinel also natively incorporates proven Azure services, like Log An
2020

2121
Use Microsoft Sentinel to alleviate the stress of increasingly sophisticated attacks, increasing volumes of alerts, and long resolution time frames. This article highlights the key capabilities in Microsoft Sentinel.
2222

23-
24-
[!INCLUDE [unified-soc-preview](includes/unified-soc-preview.md)]
25-
26-
2723
Microsoft Sentinel inherits the Azure Monitor [tamper-proofing and immutability](/azure/azure-monitor/logs/data-security#tamper-proofing-and-immutability) practices. While Azure Monitor is an append-only data platform, it includes provisions to delete data for compliance purposes.
2824

2925
[!INCLUDE [azure-lighthouse-supported-service](../../includes/azure-lighthouse-supported-service-no-note.md)]
@@ -120,6 +116,10 @@ The following table highlights the key capabilities in Microsoft Sentinel for th
120116
|Automation rules|Centrally manage the automation of incident handling in Microsoft Sentinel by defining and coordinating a small set of rules that cover different scenarios. |[Automate threat response in Microsoft Sentinel with automation rules](automate-incident-handling-with-automation-rules.md)|
121117
|Playbooks|Automate and orchestrate your threat response by using playbooks, which are a collection of remediation actions. Run a playbook on-demand or automatically in response to specific alerts or incidents, when triggered by an automation rule. <br><br> To build playbooks with Azure Logic Apps, choose from a constantly expanding gallery of connectors for various services and systems like ServiceNow, Jira, and more. These connectors allow you to apply any custom logic in your workflow. |[Automate threat response with playbooks in Microsoft Sentinel](automate-responses-with-playbooks.md)<br><br>[List of all Logic App connectors](/connectors/connector-reference/connector-reference-logicapps-connectors)|
122118

119+
## Microsoft Sentinel in the Azure portal retirement timeline
120+
121+
[!INCLUDE [sentinel-azure-deprecation](includes/sentinel-azure-deprecation.md)]
122+
123123
## Related content
124124

125125
- [Quickstart: Onboard Microsoft Sentinel](quickstart-onboard.md)

articles/sentinel/whats-new.md

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn about the latest new features and announcement in Microsoft S
44
author: batamig
55
ms.author: bagol
66
ms.topic: concept-article
7-
ms.date: 06/15/2025
7+
ms.date: 07/01/2025
88
#Customer intent: As a security team member, I want to stay updated on the latest features and enhancements in Microsoft Sentinel so that I can effectively manage and optimize my organization's security posture.
99
ms.custom:
1010
- build-2025
@@ -18,6 +18,12 @@ The listed features were released in the last six months. For information about
1818

1919
[!INCLUDE [reference-to-feature-availability](includes/reference-to-feature-availability.md)]
2020

21+
## July 2025
22+
23+
### Microsoft Sentinel in the Defender portal to be retired July 2026
24+
25+
[!INCLUDE [sentinel-azure-deprecation](includes/sentinel-azure-deprecation.md)]
26+
2127
## June 2025
2228

2329
- [Codeless Connector Platform (CCP) renamed.](#codeless-connector-platform-ccp-renamed-to-codeless-connector-framework-ccf)

0 commit comments

Comments
 (0)