You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: unified-secops-platform/microsoft-sentinel-onboard.md
+4-13Lines changed: 4 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -25,7 +25,7 @@ search.appverid:
25
25
appliesto:
26
26
- Microsoft Defender XDR
27
27
- Microsoft Sentinel in the Microsoft Defender portal
28
-
ms.date: 07/16/2025
28
+
ms.date: 09/02/2025
29
29
---
30
30
31
31
# Connect Microsoft Sentinel to the Microsoft Defender portal
@@ -98,19 +98,10 @@ If applicable, complete these prerequisites:
98
98
This procedure describes how to onboard a Microsoft Sentinel-enabled workspace to the Defender portal.
99
99
100
100
1. Go to the [Microsoft Defender portal](https://security.microsoft.com/) and sign in.
101
-
102
-
1. If you're a Microsoft Sentinel-only customer without licenses for Defender services, and are onboarding your first workspace to Defender, start by triggering the connection to Microsoft Sentinel.
103
-
104
-
In the Defender portal, select **Investigation & response** > **Incidents**, and then wait a few minutes for the connection to complete. This step isn't needed for any subsequent workspaces you onboard to Defender.
1. Select the workspaces you want to connect and select **Next**.
109
-
110
103
1. Select the **Primary workspace**.
111
-
112
-
1. Read and understand the product changes associated with connecting your workspace.
113
-
104
+
1. Read and understand the product changes associated with connecting your workspace.
114
105
1. Select **Connect**.
115
106
116
107
After your workspace is connected, the banner on the **Home** page shows that your environment is ready. The **Home** page is updated with new sections that include metrics from Microsoft Sentinel, like the number of data connectors and automation rules.
@@ -151,7 +142,7 @@ If your workspace has the [Microsoft Defender XDR connector](/azure/sentinel/con
151
142
1. Go to the [Microsoft Defender portal](https://security.microsoft.com/) and sign in.
152
143
1. In the Defender portal, under **System**, select **Settings** > **Microsoft Sentinel**.
153
144
1. On the **Workspaces** page, select the connected workspace and **Disconnect workspace**.
154
-
1. Provide a reason why you're disconnecting the workspace.
145
+
1. Provide a reason why you're disconnecting the workspace.
155
146
1. Confirm your selection.
156
147
157
148
When your workspace is disconnected, the **Microsoft Sentinel** section is removed from the left-hand side navigation of the Defender portal. Data from Microsoft Sentinel is no longer included on the **Home** page.
0 commit comments