You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/includes/unified-soc-preview-without-alert.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,9 +4,9 @@ description: Describes the current announcement for Microsoft Sentinel in the De
4
4
services: microsoft-sentinel
5
5
author: batamig
6
6
ms.topic: "include"
7
-
ms.date: 06/12/2025
7
+
ms.date: 07/01/2025
8
8
ms.author: bagol
9
9
ms.custom: "include file"
10
10
---
11
11
12
-
New customers onboarding after **July 1, 2025** with the relevant permissions are automatically onboarded to the Microsoft Defender portal and access Microsoft Sentinel in the Azure portal only. Existing customers, and new users without relevant permissions, can continue to use Microsoft Sentinel in the Azure portal. Starting in **July 2026**, all customers using Microsoft Sentinel in the Azure portal will be redirected to the Defender portal. We recommend that you start planning your transition to the Defender portal to ensure a smooth transition and take full advantage of the new features offered by Microsoft Defender. For more information, see [Microsoft Sentinel in the Azure portal deprecation timeline](../overview.md#microsoft-sentinel-in-the-azure-portal-deprecation-timeline) and [It’s Time to Move: Retiring Microsoft Sentinel’s Azure portal for greater security](https://aka.ms/time-to-move-to-defender).
12
+
Starting in **July 2026**, all customers using Microsoft Sentinel in the Azure portal will be redirected to the Defender portal and will use Microsoft Sentinel in the Defender portal only. Starting in **July 2025**, many new users are also redirected from the Azure portal to the Defender portal. If you're still using Microsoft Sentinel in the Azure portal, we recommend that you start planning your transition to the Defender portal to ensure a smooth transition and take full advantage of the new unified security operations features offered by Microsoft Defender. For more information, see [Microsoft Sentinel in the Azure portal deprecation timeline](../overview.md#microsoft-sentinel-in-the-azure-portal-deprecation-timeline) and [It’s Time to Move: Retiring Microsoft Sentinel’s Azure portal for greater security](https://aka.ms/time-to-move-to-defender).
Copy file name to clipboardExpand all lines: articles/sentinel/includes/unified-soc-preview.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,14 +4,14 @@ description: Describes the current announcement for Microsoft Sentinel in the De
4
4
services: microsoft-sentinel
5
5
author: batamig
6
6
ms.topic: "include"
7
-
ms.date: 06/12/2025
7
+
ms.date: 07/01/2025
8
8
ms.author: bagol
9
9
ms.custom: "include file"
10
10
---
11
11
12
12
> [!IMPORTANT]
13
-
>New customers onboarding after **July 1, 2025** with the relevant permissions are automatically onboarded to the Microsoft Defender portal and access Microsoft Sentinel in the Azure portal only. Existing customers, and new users without relevant permissions, can continue to use Microsoft Sentinel in the Azure portal.
13
+
>Starting in **July 2026**, all customers using Microsoft Sentinel in the Azure portal will be redirected to the Defender portal and will use Microsoft Sentinel in the Defender portal only. Starting in **July 2025**, many new users are also redirected from the Azure portal to the Defender portal.
14
14
>
15
-
>Starting in **July 2026**, all customers using Microsoft Sentinel in the Azure portal will be redirected to the Defender portal. We recommend that you start planning your transition to the Defender portal to ensure a smooth transition and take full advantage of the new features offered by Microsoft Defender.
15
+
>If you're still using Microsoft Sentinel in the Azure portal, we recommend that you start planning your transition to the Defender portal to ensure a smooth transition and take full advantage of the new unified security operations features offered by Microsoft Defender.
16
16
>
17
17
> For more information, see [Microsoft Sentinel in the Azure portal deprecation timeline](../overview.md#microsoft-sentinel-in-the-azure-portal-deprecation-timeline) and [It’s Time to Move: Retiring Microsoft Sentinel’s Azure portal for greater security](https://aka.ms/time-to-move-to-defender).
Copy file name to clipboardExpand all lines: articles/sentinel/overview.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,11 +1,11 @@
1
1
---
2
2
title: What is Microsoft Sentinel? | Microsoft Docs
3
3
description: Learn about Microsoft Sentinel, a security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution.
4
-
author: cwatson-cat
5
-
ms.author: cwatson
4
+
author: batamig
5
+
ms.author: bagol
6
6
ms.topic: overview
7
7
ms.service: microsoft-sentinel
8
-
ms.date: 05/13/2024
8
+
ms.date: 07/01/2025
9
9
10
10
11
11
#CustomerIntent: As a business decision maker, I want to understand what Microsoft Sentinel offers so that I can determine whether the service meets my organization's requirements.
@@ -126,9 +126,9 @@ If you're currently using Microsoft Sentinel in the Azure portal, we recommend t
126
126
127
127
### Changes for new customers starting July 2025
128
128
129
-
For the sake of the changes described in this section, new Microsoft Sentinel customers are customers who are [onboarding the first workspace in their tenant to Microsoft Sentinel](quickstart-onboard.md) on or after **July 1, 2025**, and are not Azure Lighthouse-delegated users.
129
+
For the sake of the changes described in this section, new Microsoft Sentinel customers are customers who are [onboarding the first workspace in their tenant to Microsoft Sentinel](quickstart-onboard.md) on or after **July 1, 2025**.
130
130
131
-
Starting **July 1, 2025**, such new customers who have the permissions of a subscription [Owner](/azure/role-based-access-control/built-in-roles#owner) or a [User access administrator](/azure/role-based-access-control/built-in-roles#user-access-administrator), have their workspaces automatically onboarded to the Defender portal together with onboarding to Microsoft Sentinel. Users of such workspaces, who also aren't Azure Lighthouse-delegated users, see links in Microsoft Sentinel in the Azure portal that redirect them to the Defender portal. Such users use Microsoft Sentinel in the Defender portal only. For example:
131
+
Starting **July 1, 2025**, such new customers who are not Azure Lighthouse-delegated users, and who have the permissions of a subscription [Owner](/azure/role-based-access-control/built-in-roles#owner) or a [User access administrator](/azure/role-based-access-control/built-in-roles#user-access-administrator), have their workspaces automatically onboarded to the Defender portal together with onboarding to Microsoft Sentinel. Users of such workspaces, who also aren't Azure Lighthouse-delegated users, see links in Microsoft Sentinel in the Azure portal that redirect them to the Defender portal. Such users use Microsoft Sentinel in the Defender portal only. For example:
132
132
133
133
New customers who don't have relevant permissions aren't automatically onboarded to the Defender portal, but they do still see redirection links in the Azure portal, together with prompts to have a user with relevant permissions manually onboard the workspace to the Defender portal.
134
134
@@ -138,7 +138,7 @@ The following table summarizes these experience:
138
138
|---------|---------|
139
139
|**Existing customers** creating new workspaces in a tenant where there is already a workspace enabled for Microsoft Sentinel | Workspaces are not automatically onboarded, and users don't see redirection links |
140
140
|**Azure Lighthouse-delegated users** creating new workspaces in any tenant | Workspaces are not automatically onboarded, and users don't see redirection links |
141
-
|**New customers** onboarding the first workspace in their tenant to Microsoft Sentinel | - Users who have the required permissions have their workspace automatically onboarded. Other users of such workspaces see redirection links in the Azure portal. <br><br>- Users who don't have the required permissions don't have their workspace automatically onboarded. All users of such workspaces see redirection links in the Azure portal, and a user with the required permissions must onboard the workspace to the Defender portal. |
141
+
|**New customers** onboarding the first workspace in their tenant to Microsoft Sentinel | - **Users who have the required permissions** have their workspace automatically onboarded. Other users of such workspaces see redirection links in the Azure portal. <br><br>- **Users who don't have the required permissions** don't have their workspace automatically onboarded. All users of such workspaces see redirection links in the Azure portal, and a user with the required permissions must onboard the workspace to the Defender portal. |
Copy file name to clipboardExpand all lines: articles/sentinel/whats-new.md
+6-4Lines changed: 6 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -27,7 +27,7 @@ The listed features were released in the last six months. For information about
27
27
28
28
Microsoft is transitioning Microsoft Sentinel from the Azure portal to the Microsoft Defender portal to provide a unified, efficient, and modern experience for security teams. This move integrates Microsoft Sentinel with Microsoft Defender's extensive threat protection capabilities, enhancing security outcomes.
29
29
30
-
Starting in July 2026, Microsoft Sentinel will be supported only in the Microsoft Defender portal, and any remaining customers in the Azure portal will be automatically redirected to the Defender portal. We recommend that such customers start planning their migration to the Defender portal to ensure a smooth transition and take full advantage of the new features offered by Microsoft Defender.
30
+
Starting in **July 2026**, Microsoft Sentinel will be supported only in the Microsoft Defender portal, and any remaining customers in the Azure portal will be automatically redirected to the Defender portal. We recommend that such customers start planning their migration to the Defender portal to ensure a smooth transition and take full advantage of the new features offered by Microsoft Defender.
31
31
32
32
For more information, see:
33
33
@@ -38,17 +38,19 @@ For more information, see:
38
38
39
39
### For new customers only: Automatic onboarding and redirection to the Microsoft Defender portal
40
40
41
-
For this update, new Microsoft Sentinel customers are customers who are onboarding the first workspace in their tenant to Microsoft Sentinel on or after July 1, 2025.
41
+
For this update, new Microsoft Sentinel customers are customers who are [onboarding the first workspace in their tenant to Microsoft Sentinel](quickstart-onboard.md) on or after **July 1, 2025**.
42
42
43
-
New customers onboarding with the permissions of a subscription [Owner](/azure/role-based-access-control/built-in-roles#owner) or a [User access administrator](/azure/role-based-access-control/built-in-roles#user-access-administrator) now automatically have their workspaces onboarded to the Microsoft Defender portal. Users of such workspaces access Microsoft Sentinel in the Defender portal only. Accessing Microsoft Sentinel in the Azure portal automatically shows redirection links to Defender.
43
+
Starting **July 1, 2025**, such new customers who are not Azure Lighthouse-delegated users, and who have the permissions of a subscription [Owner](/azure/role-based-access-control/built-in-roles#owner) or a [User access administrator](/azure/role-based-access-control/built-in-roles#user-access-administrator), have their workspaces automatically onboarded to the Defender portal together with onboarding to Microsoft Sentinel. Users of such workspaces, who also aren't Azure Lighthouse-delegated users, see links in Microsoft Sentinel in the Azure portal that redirect them to the Defender portal. Such users use Microsoft Sentinel in the Defender portal only. For example:
44
+
45
+
New customers who don't have relevant permissions aren't automatically onboarded to the Defender portal, but they do still see redirection links in the Azure portal, together with prompts to have a user with relevant permissions manually onboard the workspace to the Defender portal.
44
46
45
47
This change streamlines the onboarding process and ensures that new customers can immediately take advantage of unified security operations capabilities without the extra step of manually onboarding their workspaces.
46
48
47
49
For more information, see:
48
50
49
51
-[Onboard Microsoft Sentinel](quickstart-onboard.md)
50
52
-[Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md)
51
-
-[Changes for new customers](overview.md#changes-for-new-customers)
53
+
-[Changes for new customers starting July 2025](overview.md#changes-for-new-customers-starting-july-2025)
0 commit comments