Security operations

Microsoft Sentinel is leaving the Azure portal: what to do before March 2027

Sentinel now lives in the Microsoft Defender portal. Here is what changes, the deadline, and a checklist for moving.

By Vikas Garg · 6 min read

If your team still opens Microsoft Sentinel from the Azure portal, that route has an end date. Microsoft is moving Sentinel into the Microsoft Defender portal, and the Azure portal experience is on its way out.

The deadline

After 31 March 2027, Microsoft Sentinel is no longer supported in the Azure portal. Anyone still using it there is redirected to the Defender portal. The original date was July 2026; Microsoft extended it. (Microsoft Learn)

You don't need Microsoft Defender XDR or an E5 licence to use Sentinel in the Defender portal. It works on its own there too.

New customers are already there

Since July 2025, organisations onboarding their first Sentinel workspace are moved to the Defender portal automatically when the person onboarding is a subscription Owner or User Access Administrator. Links in the Azure portal then redirect them. (What's new in Sentinel)

What changes day to day

A checklist for the move

  1. List every Sentinel workspace you run and who uses each one.
  2. Onboard each workspace to the Defender portal, following Microsoft's transition guide.
  3. Check permissions: confirm analysts can see and work incidents in the new portal before you tell them to switch.
  4. Test your automation rules and playbooks end to end with a sample incident, especially anything that opens tickets in ServiceNow or another ITSM tool.
  5. Update runbooks, bookmarks and training material to the new navigation.
  6. Set a cut-over date well before 31 March 2027, so the redirect never surprises anyone.

Learn it in the new portal

My short course Microsoft Sentinel in Practice is recorded entirely in the Defender portal, from onboarding to playbooks that open ServiceNow tickets. If you'd rather have help with the move itself, see consulting.

Sources