Additional Microsoft Defender tools and services that provide security across various platforms and environments
Hi Abolarin,
This is not caused by the Azure for Students subscription or a missing Defender XDR/E5 licence. Microsoft Sentinel can work in the Defender portal without either. The missing Microsoft Sentinel settings indicate that the new workspace was never onboarded, possibly because the deleted training workspace remains registered as the tenant’s primary workspace.
If the old workspace was deleted within 14 days, open Azure Portal > Log Analytics workspaces > Open recycle bin, recover it, then go to Defender > System > Settings > Microsoft Sentinel > Workspaces and disconnect it properly. Afterwards, connect the current workspace and set it as Primary.
If the old workspace is no longer recoverable, there is no supported command to clear this tenant-level association. Open an Azure support request for Microsoft Sentinel onboarding and ask the Unified Security Operations team to remove the stale primary-workspace binding. Include the tenant ID, both workspace resource IDs and the old workspace’s deletion date.
Thank you, and feel free to respond back for more assistance.