trying to create an alert for Windows Update Compliance Below 90% was told to turn on Windows Update for Business... - TrackingID#2609090040005016

Adam Ring JIT 0 Reputation points
2026-09-15T16:37:33.22+00:00

**My account was locked out and ended up being deleted and recreated by my admin and now I can't access my previous ticket. We are a normal GCC environment. Sorry for the duplicate question.

Summary of the issue:**

The issue was first reported on 2026-09-09. The customer was trying to create a Microsoft Sentinel alert for Windows Update Compliance below 90% over 30-, 60-, and 90-day windows. They had enabled Windows Update for Business reports more than a week earlier, but no data was being ingested into Sentinel. The customer also noted that the environment is GCC and asked whether that could be affecting the setup and how this data should be brought into Sentinel.

 

Environment:

Microsoft Sentinel in a GCC cloud environment, with Windows Update for Business reports / Update Compliance as the intended data source for compliance alerting. No workspace names, tenant details, or other identifiers were provided in the record.

 

What has been tried so far:

    1. The customer searched online and enabled Windows Update for Business reports.
  1. After waiting more than a week, they still saw no ingested data in Sentinel.
  2. The first recorded support reply stated: “No data found.”
  3. The available record contained no additional case history or diagnostic output.
  4. Documentation reviewed during the case noted that support for Windows Update for Business reports was moved to Windows Commercial on 2023-08-01.
  5. Self-help material reviewed during the case stated that first-time data can take up to 72 hours to appear, and that Update Compliance data may be delayed if a device’s Commercial ID was recently changed.

 

Where things stand now:

As of the latest record, the customer still had no Windows Update for Business reports data available in Sentinel after enabling it over a week earlier. The open questions raised in the thread were whether the GCC environment changes support or ingestion behavior, and what the supported path is for getting this compliance data into Sentinel. No further observations were captured.Summary of the issue:

The issue was first reported on 2026-09-09. The customer was trying to create a Microsoft Sentinel alert for Windows Update Compliance below 90% over 30-, 60-, and 90-day windows. They had enabled Windows Update for Business reports more than a week earlier, but no data was being ingested into Sentinel. The customer also noted that the environment is GCC and asked whether that could be affecting the setup and how this data should be brought into Sentinel.

 

Environment:

Microsoft Sentinel in a GCC cloud environment, with Windows Update for Business reports / Update Compliance as the intended data source for compliance alerting. No workspace names, tenant details, or other identifiers were provided in the record.

 

What has been tried so far:

-

  1. The customer searched online and enabled Windows Update for Business reports.
  2. After waiting more than a week, they still saw no ingested data in Sentinel.
  3. The first recorded support reply stated: “No data found.”
  4. The available record contained no additional case history or diagnostic output.
  5. Documentation reviewed during the case noted that support for Windows Update for Business reports was moved to Windows Commercial on 2023-08-01.
  6. Self-help material reviewed during the case stated that first-time data can take up to 72 hours to appear, and that Update Compliance data may be delayed if a device’s Commercial ID was recently changed.

 

Where things stand now:

As of the latest record, the customer still had no Windows Update for Business reports data available in Sentinel after enabling it over a week earlier. The open questions raised in the thread were whether the GCC environment changes support or ingestion behavior, and what the supported path is for getting this compliance data into Sentinel. No further observations were captured.

Microsoft Security | Microsoft Sentinel
0 comments No comments

1 answer

Sort by: Most helpful
  1. Adam Ring JIT 0 Reputation points
    2026-09-15T16:44:03.22+00:00

    found the old ticket. you can delete this question

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.