A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Microsoft Sentinel Analytics Page Redirecting to Defender – UI Inconsistency?
Hi everyone,
I’m running into a small but confusing UI behavior in Microsoft Sentinel and wanted to check if others have seen something similar.
In our environment, Microsoft Sentinel is fully configured and actively ingesting logs. We can clearly see data flowing into Log Analytics, including custom analytics rules, incidents, and detections generated from our application layer.
However, when navigating to the Analytics section in Sentinel, the portal sometimes prompts us to “go to Microsoft Defender” instead of showing the Analytics rules directly. Interestingly, if I perform a hard refresh (Ctrl + Shift + R) or reload the page the Analytics rules suddenly appear correctly, including all custom rules configured using zapper edge app service
For context, this setup is part of Zapper Edge (zapperedge.com), an Azure-native Managed File Transfer (MFT) platform where we’ve deeply integrated Microsoft Sentinel to treat file movement as a first-class security signal. All MFT activities (uploads, downloads, encryption events, PGP key usage, malware scanning, access anomalies, etc.) are streamed directly into Sentinel using managed identities and native Azure pipelines — no agents, no manual SIEM work.
From a functionality perspective, everything works perfectly once the page refreshes:
· Logs are present
· Analytics rules are active
· Incidents trigger as expected
This feels more like a portal UI a configuration problem.
Would appreciate any insights or confirmation from others running production Sentinel deployments with custom analytics rules.
Thanks in advance!