Microsoft Sentinel stuck in redirect loop to SIEM workspaces in Defender portal

Manivel K 15 Reputation points
2026-08-19T04:51:19.2633333+00:00

Hello Microsoft Team,

I am experiencing an issue with Microsoft Sentinel in the Microsoft Defender portal on a newly created Azure Free Trial tenant. I can successfully sign in to Azure Portal, Microsoft Defender portal and Microsoft 365 Admin Center. However, whenever I try to open Microsoft Sentinel features in the Defender portal, including Analytics, Data Connectors, Content Hub, Automation, Watchlists, Hunting, and Notebooks, the portal immediately redirects back to Settings → Microsoft Sentinel → SIEM Workspaces. As a result, I cannot access any Sentinel features from the Defender portal. I have already tested with multiple browsers, InPrivate and Incognito modes, cleared browser cache and cookies, used multiple global admin accounts (including a new cloud-only global admin), verified tenant ID is identical across Azure, Defender, and M365, assigned Microsoft Sentinel Contributor and Reader roles, verified the workspace is Primary and Connected, verified data ingestion is working, confirmed KQL queries execute successfully in Azure Log Analytics, and confirmed Microsoft Defender XDR connector is connected. HAR analysis shows isUsxOnboarded=true, navigation reaches /sentinel/analytics, but then redirects back to /sentinel/settings with no 401, 403, or 5xx errors, and workspaceMetadata.workspaceStatusis consistently null.

Has anyone encountered this behavior before? Could this be a known provisioning or routing issue? Could Microsoft please verify whether the workspace has been correctly provisioned for the Unified Security Operations experience?

Could Microsoft verify whether this workspace has been fully provisioned for the Unified Security experience, given that isUsxOnboarded = true but all Sentinel pages redirect back to SIEM Workspaces.

Screen Recording 2026-08-18 121535.gif

Thanks,

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud

3 answers

Sort by: Most helpful
  1. David Swan 0 Reputation points
    2026-09-04T02:52:17.57+00:00

    Assign yourself Microsoft Sentinel Contributor and Log Analytics Reader on the Sentinel workspace under Access Control

    Was this answer helpful?

    0 comments No comments

  2. Wian Swart 1 Reputation point
    2026-08-27T16:02:43.4933333+00:00

    I had the same issue and tried to remove the worskspace and re-add it from the Defender settings portal, but it still went into the loop. Gave it another day to sort it out and still had the loop. Ended up in the Defender portal under Sentinel again today and clicked the "Remove subscriptions" option (not as a test, but just because I'm all out of options). Low and behold, the loop is gone!!

    Was this answer helpful?


  3. Manivel K 15 Reputation points
    2026-08-19T04:52:04.3666667+00:00

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.