Multiple Defender functions missing for my Sentinel workspace: no Incidents, Advanced Hunting, Cases, or Analytics rules showing up

Abolarin Seyi 0 Reputation points
2026-08-26T02:50:00.0766667+00:00

I'm stuck on this and I've run out of things to try, so hoping someone's seen it before.

I have a Log Analytics workspace with Sentinel enabled, on an Azure for Students subscription. Sentinel itself works fine on the Azure side, I'm ingesting logs from an on-prem machine and can query them fine under Logs in Azure Sentinel. The problem is that none of the Defender-side functionality is showing up for this workspace. Specifically missing in the Defender portal:

  • Incidents
  • Advanced Hunting
  • Cases
  • Analytics rules

Clicking Incidents inside Sentinel just bounces me to Defender where it's empty.

Here's what I've already ruled out:

  • Global Admin and Security Admin in Entra, Owner on the subscription with no conditions on it
  • Microsoft.SecurityInsights resource provider is registered
  • No "Microsoft Defender XDR" connect tile anywhere in the Sentinel resource's Settings
  • No connect banner on the Sentinel Overview page either
  • Defender's own Settings has no Microsoft Sentinel section at all
  • Going straight to the Sentinel settings URL in Defender either 404s or just bounces me back to the Defender home page
  • No orphaned or ghost workspace entries showing up anywhere

One thing that might be relevant: earlier I had a different workspace on this same tenant, from a training lab, that was connected to Defender and had full Incidents, Hunting, and Analytics rules working. That workspace got deleted later by a cleanup script.

Is there any way to check what state the tenant thinks it's in, or force it to let me connect this workspace properly, given there's nothing left in the UI to click on either side?I'm stuck on this and I've run out of things to try, so hoping someone's seen it before.

Microsoft Security | Microsoft Defender | Other
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.