Hello Microsoft Team,
I am experiencing an issue with Microsoft Sentinel in the Microsoft Defender portal on a newly created Azure Free Trial tenant. I can successfully sign in to Azure Portal, Microsoft Defender portal and Microsoft 365 Admin Center. However, whenever I try to open Microsoft Sentinel features in the Defender portal, including Analytics, Data Connectors, Content Hub, Automation, Watchlists, Hunting, and Notebooks, the portal immediately redirects back to Settings → Microsoft Sentinel → SIEM Workspaces. As a result, I cannot access any Sentinel features from the Defender portal. I have already tested with multiple browsers, InPrivate and Incognito modes, cleared browser cache and cookies, used multiple global admin accounts (including a new cloud-only global admin), verified tenant ID is identical across Azure, Defender, and M365, assigned Microsoft Sentinel Contributor and Reader roles, verified the workspace is Primary and Connected, verified data ingestion is working, confirmed KQL queries execute successfully in Azure Log Analytics, and confirmed Microsoft Defender XDR connector is connected. HAR analysis shows isUsxOnboarded=true, navigation reaches /sentinel/analytics, but then redirects back to /sentinel/settings with no 401, 403, or 5xx errors, and workspaceMetadata.workspaceStatusis consistently null.
Has anyone encountered this behavior before? Could this be a known provisioning or routing issue? Could Microsoft please verify whether the workspace has been correctly provisioned for the Unified Security Operations experience?
Could Microsoft verify whether this workspace has been fully provisioned for the Unified Security experience, given that isUsxOnboarded = true but all Sentinel pages redirect back to SIEM Workspaces.
Screen Recording 2026-08-18 121535.gif
Thanks,