Can I please check that you are using the Microsoft 365 Defender connector from content Hub?
There are other prerequisites, you also need:
source: https://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-365-defender?tabs=MDE
You must have a valid license for Microsoft 365 Defender, as described in Microsoft 365 Defender prerequisites.
Your user must be assigned the Global Administrator or Security Administrator roles on the tenant you want to stream the logs from.
- Your user must have read and write permissions on your Microsoft Sentinel workspace.
To make any changes to the connector settings, your user must be a member of the same Microsoft Entra tenant with which your Microsoft Sentinel workspace is associated.
Install the solution for Microsoft 365 Defender from the Content Hub in Microsoft Sentinel. For more information, see Discover and manage Microsoft Sentinel out-of-the-box content.