A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
found the old ticket. you can delete this question
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
**My account was locked out and ended up being deleted and recreated by my admin and now I can't access my previous ticket. We are a normal GCC environment. Sorry for the duplicate question.
Summary of the issue:**
The issue was first reported on 2026-09-09. The customer was trying to create a Microsoft Sentinel alert for Windows Update Compliance below 90% over 30-, 60-, and 90-day windows. They had enabled Windows Update for Business reports more than a week earlier, but no data was being ingested into Sentinel. The customer also noted that the environment is GCC and asked whether that could be affecting the setup and how this data should be brought into Sentinel.
Environment:
Microsoft Sentinel in a GCC cloud environment, with Windows Update for Business reports / Update Compliance as the intended data source for compliance alerting. No workspace names, tenant details, or other identifiers were provided in the record.
What has been tried so far:
Where things stand now:
As of the latest record, the customer still had no Windows Update for Business reports data available in Sentinel after enabling it over a week earlier. The open questions raised in the thread were whether the GCC environment changes support or ingestion behavior, and what the supported path is for getting this compliance data into Sentinel. No further observations were captured.Summary of the issue:
The issue was first reported on 2026-09-09. The customer was trying to create a Microsoft Sentinel alert for Windows Update Compliance below 90% over 30-, 60-, and 90-day windows. They had enabled Windows Update for Business reports more than a week earlier, but no data was being ingested into Sentinel. The customer also noted that the environment is GCC and asked whether that could be affecting the setup and how this data should be brought into Sentinel.
Environment:
Microsoft Sentinel in a GCC cloud environment, with Windows Update for Business reports / Update Compliance as the intended data source for compliance alerting. No workspace names, tenant details, or other identifiers were provided in the record.
What has been tried so far:
-
Where things stand now:
As of the latest record, the customer still had no Windows Update for Business reports data available in Sentinel after enabling it over a week earlier. The open questions raised in the thread were whether the GCC environment changes support or ingestion behavior, and what the supported path is for getting this compliance data into Sentinel. No further observations were captured.
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
found the old ticket. you can delete this question