Multiple Defender functions missing for my Sentinel workspace: no Incidents, Advanced Hunting, Cases, or Analytics rules showing up

Abolarin Seyi 20 Reputation points
2026-08-26T02:50:00.0766667+00:00

I'm stuck on this and I've run out of things to try, so hoping someone's seen it before.

I have a Log Analytics workspace with Sentinel enabled, on an Azure for Students subscription. Sentinel itself works fine on the Azure side, I'm ingesting logs from an on-prem machine and can query them fine under Logs in Azure Sentinel. The problem is that none of the Defender-side functionality is showing up for this workspace. Specifically missing in the Defender portal:

  • Incidents
  • Advanced Hunting
  • Cases
  • Analytics rules

Clicking Incidents inside Sentinel just bounces me to Defender where it's empty.

Here's what I've already ruled out:

  • Global Admin and Security Admin in Entra, Owner on the subscription with no conditions on it
  • Microsoft.SecurityInsights resource provider is registered
  • No "Microsoft Defender XDR" connect tile anywhere in the Sentinel resource's Settings
  • No connect banner on the Sentinel Overview page either
  • Defender's own Settings has no Microsoft Sentinel section at all
  • Going straight to the Sentinel settings URL in Defender either 404s or just bounces me back to the Defender home page
  • No orphaned or ghost workspace entries showing up anywhere

One thing that might be relevant: earlier I had a different workspace on this same tenant, from a training lab, that was connected to Defender and had full Incidents, Hunting, and Analytics rules working. That workspace got deleted later by a cleanup script.

Is there any way to check what state the tenant thinks it's in, or force it to let me connect this workspace properly, given there's nothing left in the UI to click on either side?I'm stuck on this and I've run out of things to try, so hoping someone's seen it before.

Microsoft Security | Microsoft Defender | Other
0 comments No comments

Answer accepted by question author
Mohammad Wasi Haider 165 Reputation points
2026-08-27T14:23:20.56+00:00

Hi Abolarin,

This is not caused by the Azure for Students subscription or a missing Defender XDR/E5 licence. Microsoft Sentinel can work in the Defender portal without either. The missing Microsoft Sentinel settings indicate that the new workspace was never onboarded, possibly because the deleted training workspace remains registered as the tenant’s primary workspace.

If the old workspace was deleted within 14 days, open Azure Portal > Log Analytics workspaces > Open recycle bin, recover it, then go to Defender > System > Settings > Microsoft Sentinel > Workspaces and disconnect it properly. Afterwards, connect the current workspace and set it as Primary.

If the old workspace is no longer recoverable, there is no supported command to clear this tenant-level association. Open an Azure support request for Microsoft Sentinel onboarding and ask the Unified Security Operations team to remove the stale primary-workspace binding. Include the tenant ID, both workspace resource IDs and the old workspace’s deletion date.

Thank you, and feel free to respond back for more assistance.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.