A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Based on your description, this does not look like expected behavior.
Microsoft Defender supports one primary and multiple secondary Microsoft Sentinel workspaces per tenant. A connected secondary workspace should be available in the supported Sentinel experiences, including the workspace selector used by Advanced Hunting.
Since testspace already shows Connected and Active, and you have validated both Azure RBAC and Defender Unified RBAC, I would also confirm that the Owner assignment exists unconditionally at subscription scope, as required during Sentinel onboarding.
If this is already in place and the workspace remains missing from the selector, this is more likely a Defender/Sentinel backend registration or workspace synchronization issue rather than a primary/secondary workspace limitation.
At this stage, I would recommend opening a Microsoft support case and providing the Tenant ID, Subscription ID, Workspace ID, onboarding timestamp, and screenshots showing the workspace as Connected/Active but missing from the selector.
If this answer helps resolve your issue, please don’t forget to mark it as Accepted Answer / Resolved, as this can also help others experiencing the same behavior.