Unable to onboard Sentinel workspace from Lighthouse to Defender

Wei 40 Reputation points
2026-08-13T02:35:52.1166667+00:00

Screenshot 2026-08-13 103056

I got the following error "Failed to log-lighthouse workspace. Try again later." when I tried to connect a customer's Microsoft Sentinel workspace to Microsoft Defender XDR.

This is to migrate Microsoft Sentinel in the Azure portal to the Defender portal as after March 31, 2027, Microsoft Sentinel will no longer be supported in the Azure portal and will be available only in the Microsoft Defender portal, from here.

From the onboarding prerequisites here, I have the following permissions:

In my tenant:

  • (Entra) Security Administrator

Customer's resource group defined in the Lighthouse ARM template:

  • (Azure) User Access Administrator
  • (Azure) Contributor
  • (Azure) Microsoft Sentinel Contributor

Here is what I've tried:

  • Switching the Lighthouse ARM template from RG scope to Subscription scope
  • Create a new Log Analytics Workspace and add Microsoft Sentinel to a workspace (instead of using the one created by the customer)

Taken from the onboarding prerequisites link:

If you're working with multiple tenants, note that granular delegated admin privileges (GDAP) with Azure Lighthouse isn't supported for Microsoft Sentinel data in the Defender portal.

Correct me if I'm wrong, but my setup does not use GDAP.

If possible, I would want to avoid using B2B as my company has been using Azure Lighthouse to manage our customers' Sentinel resources.

Happy to hear any answers!

Microsoft Security | Microsoft Sentinel
0 comments No comments

Answer accepted by question author
EduardsGrebezs 1,276 Reputation points
2026-08-16T07:06:21.5033333+00:00

Azure Lighthouse can still be used for delegated management of Sentinel resources in the Azure portal, but that delegation does not provide the required access model for Sentinel when using the Microsoft Defender portal.

For MSSP / multitenant scenarios, Microsoft currently recommends using Microsoft Entra B2B authentication and configuring Microsoft Defender multitenant management instead.

The customer Sentinel workspace should be onboarded to the Defender portal in the customer tenant, and cross-tenant access should then be provided using the supported Defender multitenant management model.

The Microsoft documentation explicitly states:

Screenshot 2026-08-16 at 10.01.36

So the issue appears to be a platform limitation rather than an Azure Lighthouse RBAC configuration issue.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Newest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.