Skip to content

Commit db86e5f

Browse files
committed
fixing links and location
1 parent da28233 commit db86e5f

File tree

3 files changed

+17
-17
lines changed

3 files changed

+17
-17
lines changed

articles/sentinel/includes/unified-soc-preview-without-alert.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,4 +9,4 @@ ms.author: bagol
99
ms.custom: "include file"
1010
---
1111

12-
New customers onboarding after July 1, 2025 with the relevant permissions are automatically onboarded to the Microsoft Defender portal and access Microsoft Sentinel in the Azure portal only. Existing customers, and new users without relevant permissions, can continue to use Microsoft Sentinel in the Azure portal. We recommend that you onboard to the Microsoft Defender portal for a unified security operations (SecOps) experience. For more information, see [Automatic onboarding and redirects for new customers](../microsoft-sentinel-defender-portal.md#automatic-onboarding-and-redirects-for-new-customers).
12+
New customers onboarding after July 1, 2025 with the relevant permissions are automatically onboarded to the Microsoft Defender portal and access Microsoft Sentinel in the Azure portal only. Existing customers, and new users without relevant permissions, can continue to use Microsoft Sentinel in the Azure portal. We recommend that you onboard to the Microsoft Defender portal for a unified security operations (SecOps) experience. For more information, see [Sunset timeline for Microsoft Sentinel in the Azure portal (new customers only)](../microsoft-sentinel-defender-portal.md#sunset-timeline-for-microsoft-sentinel-in-the-azure-portal-new-customers-only).

articles/sentinel/includes/unified-soc-preview.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,5 +14,4 @@ ms.custom: "include file"
1414
>
1515
>Existing customers, and new users without relevant permissions, can continue to use Microsoft Sentinel in the Azure portal. We recommend that you onboard to the Microsoft Defender portal for a unified security operations (SecOps) experience.
1616
>
17-
>For more information, see [Automatic onboarding and redirects for new customers](../microsoft-sentinel-defender-portal.md#automatic-onboarding-and-redirects-for-new-customers).
18-
17+
>For more information, see [Sunset timeline for Microsoft Sentinel in the Azure portal (new customers only)](../microsoft-sentinel-defender-portal.md#sunset-timeline-for-microsoft-sentinel-in-the-azure-portal-new-customers-only).

articles/sentinel/microsoft-sentinel-defender-portal.md

Lines changed: 15 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -22,20 +22,6 @@ Microsoft Sentinel is generally available in the Microsoft Defender portal, eith
2222

2323
This article describes the Microsoft Sentinel experience in the Defender portal.
2424

25-
## Sunset timeline for Microsoft Sentinel in the Azure portal (new customers only)
26-
27-
Microsoft Sentinel is generally available in the Microsoft Defender portal, including for customers without Microsoft Defender XDR or an E5 license. This means that you can use Microsoft Sentinel in the Defender portal even if you aren't using other Microsoft Defender services.
28-
29-
Starting in July 2025, new customers onboarding to Microsoft Sentinel with permissions of a subscription [Owner](/azure/role-based-access-control/built-in-roles#owner) or a [User access administrator](/azure/role-based-access-control/built-in-roles#user-access-administrator) are automatically onboarded to the Defender portal, and use Microsoft Sentinel in the Defender portal only.
30-
31-
Existing customers and other new customers without the relevant permissions, such as Azure-Lighthouse delegated users, can continue using Microsoft Sentinel in the Azure portal. However, we recommend that you [onboard to the Defender portal](/defender-xdr/microsoft-sentinel-onboard) for a [unified security operations experience](/unified-secops-platform/overview-unified-security). For more information, see [Transition your Microsoft Sentinel environment to the Defender portal](move-to-defender.md).
32-
33-
In most cases, users of workspaces that are automatically onboarded to the Defender portal use Microsoft Sentinel in the Defender portal only, and are redirected to the Defender portal from Microsoft Sentinel in the Azure portal. The exception is for Azure Lighthouse-delegated users who are accessing a new customer workspace onboarded to Microsoft Sentinel in the Azure portal. These users won't see the automatic redirection and can work in the Azure portal.
34-
35-
When manually onboarding to the Defender portal, you must onboard each workspace individually. When working with multiple workspaces and other Defender services, make sure to define the primary workspace where you want to correlate Microsoft Sentinel incidents with Microsoft Defender incidents. View incidents in other workspaces separately.
36-
37-
For more information, see [Onboard Microsoft Sentinel](quickstart-onboard.md) and [Multiple Microsoft Sentinel workspaces in the Defender portal](workspaces-defender-portal.md).
38-
3925
## New and improved capabilities
4026

4127
The following table describes the new or improved capabilities available in the Defender portal with the integration of Microsoft Sentinel. Microsoft continues to innovate in this new experience with features that might be exclusive to the Defender portal.
@@ -57,6 +43,21 @@ When you onboard Microsoft Sentinel to the Defender portal without Defender XDR
5743
- [Custom detection rules](/defender-xdr/custom-detections-overview), provided by Microsoft Defender XDR
5844
- The [Action center](/defender-xdr/m365d-action-center), provided by Microsoft Defender XDR
5945

46+
47+
## Sunset timeline for Microsoft Sentinel in the Azure portal (new customers only)
48+
49+
Microsoft Sentinel is generally available in the Microsoft Defender portal, including for customers without Microsoft Defender XDR or an E5 license. This means that you can use Microsoft Sentinel in the Defender portal even if you aren't using other Microsoft Defender services.
50+
51+
Starting in July 2025, new customers onboarding to Microsoft Sentinel with permissions of a subscription [Owner](/azure/role-based-access-control/built-in-roles#owner) or a [User access administrator](/azure/role-based-access-control/built-in-roles#user-access-administrator) are automatically onboarded to the Defender portal, and use Microsoft Sentinel in the Defender portal only.
52+
53+
Existing customers and other new customers without the relevant permissions, such as Azure-Lighthouse delegated users, can continue using Microsoft Sentinel in the Azure portal. However, we recommend that you [onboard to the Defender portal](/defender-xdr/microsoft-sentinel-onboard) for a [unified security operations experience](/unified-secops-platform/overview-unified-security). For more information, see [Transition your Microsoft Sentinel environment to the Defender portal](move-to-defender.md).
54+
55+
In most cases, users of workspaces that are automatically onboarded to the Defender portal use Microsoft Sentinel in the Defender portal only, and are redirected to the Defender portal from Microsoft Sentinel in the Azure portal. The exception is for Azure Lighthouse-delegated users who are accessing a new customer workspace onboarded to Microsoft Sentinel in the Azure portal. These users won't see the automatic redirection and can work in the Azure portal.
56+
57+
When manually onboarding to the Defender portal, you must onboard each workspace individually. When working with multiple workspaces and other Defender services, make sure to define the primary workspace where you want to correlate Microsoft Sentinel incidents with Microsoft Defender incidents. View incidents in other workspaces separately.
58+
59+
For more information, see [Onboard Microsoft Sentinel](quickstart-onboard.md) and [Multiple Microsoft Sentinel workspaces in the Defender portal](workspaces-defender-portal.md).
60+
6061
## Quick reference
6162

6263
Some Microsoft Sentinel capabilities, like the unified incident queue, are integrated with Microsoft Defender XDR in the Defender portal. Many other Microsoft Sentinel capabilities are available in the **Microsoft Sentinel** section of the Defender portal.

0 commit comments

Comments
 (0)