Microsoft Sentinel Analytics Page Redirecting to Defender – UI Inconsistency?

Prabhu Srivastava 20 Reputation points
2025-12-18T08:21:27.31+00:00

Hi everyone,

I’m running into a small but confusing UI behavior in Microsoft Sentinel and wanted to check if others have seen something similar.

 In our environment, Microsoft Sentinel is fully configured and actively ingesting logs. We can clearly see data flowing into Log Analytics, including custom analytics rules, incidents, and detections generated from our application layer.

 However, when navigating to the Analytics section in Sentinel, the portal sometimes prompts us to “go to Microsoft Defender” instead of showing the Analytics rules directly. Interestingly, if I perform a hard refresh (Ctrl + Shift + R) or reload the page the Analytics rules suddenly appear correctly, including all custom rules configured using zapper edge app service

 For context, this setup is part of Zapper Edge (zapperedge.com), an Azure-native Managed File Transfer (MFT) platform where we’ve deeply integrated Microsoft Sentinel to treat file movement as a first-class security signal. All MFT activities (uploads, downloads, encryption events, PGP key usage, malware scanning, access anomalies, etc.) are streamed directly into Sentinel using managed identities and native Azure pipelines — no agents, no manual SIEM work.

 From a functionality perspective, everything works perfectly once the page refreshes:

·       Logs are present

·       Analytics rules are active

·       Incidents trigger as expected

This feels more like a portal UI a configuration problem.

Would appreciate any insights or confirmation from others running production Sentinel deployments with custom analytics rules.

 Thanks in advance!

User's image

Microsoft Security | Microsoft Sentinel

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.