Hello @ANDREAS TSOURAS ,
This is usually not a 24h propagation issue. In Defender XDR, the workspace must be explicitly available/onboarded under System > Settings > Microsoft Sentinel > Workspaces / Connect a workspace. The list only shows Sentinel-enabled Log Analytics workspaces that your account has access to.
Please check the following:
The Log Analytics workspace has Microsoft Sentinel enabled.
You are signed in to the same Entra tenant as the Sentinel workspace.
Your account has the required roles. To onboard the workspace, Microsoft requires Security Administrator or higher in Entra ID, plus Owner or User Access Administrator on the subscription, and Microsoft Sentinel Contributor on the workspace/resource group/subscription. For simply viewing Sentinel in Defender, Microsoft Sentinel Reader is required.
If this is an MSSP / cross-tenant scenario, don’t rely only on GDAP + Azure Lighthouse, because Microsoft notes that this isn’t supported for Sentinel data in the Defender portal; use Entra B2B access instead.
Once the workspace is connected, Microsoft Sentinel should appear in the Defender portal navigation and the workspace should be visible under the Sentinel settings. If all permissions and tenant context are correct but it still shows 0 workspaces, I’d open a Microsoft support request because that points to a backend/onboarding issue rather than normal delay.