Secondary Sentinel workspace not visible in Defender portal

Akshay Gopinath 0 Reputation points
2026-08-20T11:36:46.48+00:00

Summary

Created a new Sentinel workspace (testspace) in our test subscription. It shows Connected and Active in Microsoft Defender, and I have Owner access to the subscription, resource group, and workspace plus Defender Read & Manage permissions.

However, testspace does not appear in the Sentinel workspace selector in Content Hub, Search, or Advanced Hunting. Only the existing primary workspace is visible.

Troubleshooting performed:

  • Disconnected/reconnected the workspace.
  • Deactivated/reactivated Unified RBAC.
  • Signed out/in.
  • Verified Azure RBAC/Owner permissions.
  • Verified Defender Unified RBAC permissions.
  • Workspace synchronization warning appeared initially but later disappeared.
  • Workspace Manager was enabled temporarily and then disabled.

Expected: testspace should be selectable and usable as a secondary Sentinel workspace.

Please investigate the Defender/Sentinel backend registration or workspace-context issue preventing the secondary workspace from appearing.

Microsoft Security | Microsoft Sentinel
0 comments No comments

1 answer

Sort by: Most helpful
  1. Konstantinos Lianos 830 Reputation points Student Ambassador
    2026-08-31T11:05:32.65+00:00

    Hi @Akshay Gopinath

    Based on your description, this does not look like expected behavior.

    Microsoft Defender supports one primary and multiple secondary Microsoft Sentinel workspaces per tenant. A connected secondary workspace should be available in the supported Sentinel experiences, including the workspace selector used by Advanced Hunting.

    Since testspace already shows Connected and Active, and you have validated both Azure RBAC and Defender Unified RBAC, I would also confirm that the Owner assignment exists unconditionally at subscription scope, as required during Sentinel onboarding.

    If this is already in place and the workspace remains missing from the selector, this is more likely a Defender/Sentinel backend registration or workspace synchronization issue rather than a primary/secondary workspace limitation.

    At this stage, I would recommend opening a Microsoft support case and providing the Tenant ID, Subscription ID, Workspace ID, onboarding timestamp, and screenshots showing the workspace as Connected/Active but missing from the selector.

    If this answer helps resolve your issue, please don’t forget to mark it as Accepted Answer / Resolved, as this can also help others experiencing the same behavior.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.