Microsoft is consolidating Microsoft Sentinel into the Microsoft Defender portal and requires all Sentinel workspaces to transition by March 31, 2027. Workspaces created after July 2025 are automatically connected.
The Defender portal connection is required to enable the full Synqly feature set for Microsoft Sentinel, including alerts. If your workspace is not connected, some Synqly capabilities will be unavailable.
Transitioning to the Defender portal has no extra cost and does not require a Microsoft Defender XDR or E5 license. See Microsoft's documentation for details.
- Sign in to the Microsoft Defender portal
- Go to System → Settings → Microsoft Sentinel
- If your workspace appears in the list, it is already connected — no further action is needed
- Security Administrator (or higher) in Microsoft Entra ID
- Owner or User Access Administrator on the Azure subscription containing the Sentinel workspace
- Microsoft Sentinel Contributor on the workspace
For full prerequisites, see Connect Microsoft Sentinel to the Defender portal.
- Sign in to the Microsoft Defender portal
- Go to System → Settings → Microsoft Sentinel
- Click Connect a workspace
- Select the Sentinel workspace and click Next
- Designate it as the Primary workspace (if this is your first or only workspace)
- Review the summary and click Connect
The connection typically completes within a few minutes. For multi-workspace scenarios, see Configure multi-workspace management.
After connecting to the Defender portal, ensure your Entra application has the full set of permissions described in the Microsoft Sentinel SIEM Configuration Guide. If your application was created before this migration, it may be missing permissions required for newer features.
Connecting to the Defender portal changes how incidents, alerts, analytics rules, and automation work in your Sentinel environment. Microsoft provides detailed guidance on these changes:
- Transition your Microsoft Sentinel environment to the Defender portal — comprehensive walkthrough of what changes, including incidents, automation, and advanced hunting
- Alert correlation and incident merging — how the Defender engine groups alerts into incidents
- Plan for unified security operations — planning guide covering prerequisites, permissions, and deployment
Your existing Synqly integration configuration (credentials, workspace settings, ingestion pipeline) continues to work without changes. Only the permission addition above is required.
| Date | Milestone |
|---|---|
| July 2025 | New Sentinel workspaces are automatically connected to the Defender portal |
| March 31, 2027 | Microsoft Sentinel will no longer be supported in the Azure portal |
We recommend connecting your workspace at your earliest convenience.