Clarification on Microsoft Sentinel availability, Log Analytics role, and Defender XDR integration after Azure Portal retirement

Yash Kamone 0 Reputation points
2025-12-16T11:19:38.2966667+00:00

After Microsoft’s announcement that the Microsoft Sentinel Azure Portal experience will be retired by July 2026 and management will move to the Microsoft Defender portal, I would like confirmation on the following points:

Will Microsoft Sentinel continue to exist as a service with full SIEM functionality, with only the Azure Portal UI being retired and all operations available via the Microsoft Defender portal?

Will Azure Log Analytics workspaces continue to be the primary data store for Sentinel log ingestion, KQL queries, analytics rules, retention, and billing after the transition?

Will the Defender XDR data lake remain Microsoft-managed with no direct customer access, except through Advanced Hunting and supported APIs?

After enabling the Microsoft Defender XDR connector, is it the recommended approach to disable individual Defender product connectors (Defender for Endpoint, Identity, Office 365, Cloud Apps) to avoid duplicate ingestion and reduce Sentinel costs?

Will non-Defender log sources (Syslog, CEF, Windows Security Events, Azure Activity, firewalls, etc.) continue to ingest directly into Sentinel Log Analytics and not into Defender XDR?

This clarification will help us validate architecture, cost impact, and operational design for Sentinel going forward.

Microsoft Security | Microsoft Sentinel

2 answers

Sort by: Most helpful
  1. Shubham Sharma 17,925 Reputation points Microsoft External Staff Moderator
    2025-12-16T11:35:51.5266667+00:00

    Hey Yash! It looks like you have some detailed questions about the future of Microsoft Sentinel, especially concerning its integration into the Microsoft Defender portal after the Azure Portal retirement. Here’s a breakdown of the answers you’re seeking:

    1. Existence of Microsoft Sentinel: Yes, Microsoft Sentinel will continue to exist as a service with full SIEM functionality. The operations will transition to the Microsoft Defender portal, meaning you’ll be able to perform all tasks via that interface.
    2. Azure Log Analytics Workspaces: Yes, Azure Log Analytics workspaces will continue to serve as the primary data store for log ingestion, KQL queries, analytics rules, retention, and billing after the transition.
    3. Defender XDR Data Lake Access: The Defender XDR data lake will remain Microsoft-managed, with no direct customer access except through Advanced Hunting and supported APIs.
    4. Disabling Individual Defender Product Connectors: To avoid duplicate ingestion and reduce Sentinel costs, it is generally recommended to disable individual Defender product connectors after enabling the Microsoft Defender XDR connector.
    5. Non-Defender Log Sources: Yes, non-Defender log sources such as Syslog, CEF, Windows Security Events, Azure Activity, and firewalls will still be able to ingest logs directly into Sentinel's Log Analytics and not just into Defender XDR.

    These clarifications are key in validating your architecture and understanding potential cost impacts moving forward.

    Hope this helps clarify everything! If you have any more questions or need further assistance, feel free to ask.

    Note: This content was drafted with the help of an AI system. Please verify the information before relying on it for decision-making.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

  2. AI answer

    2025-12-16T11:21:18.33+00:00

    Microsoft Sentinel will continue to exist as a service with full SIEM functionality after the retirement of the Azure Portal UI in July 2026. All operations will be available via the Microsoft Defender portal, ensuring that users can still access the necessary features and capabilities of Microsoft Sentinel.

    Azure Log Analytics workspaces will remain the primary data store for Sentinel log ingestion, KQL queries, analytics rules, retention, and billing after the transition to the Defender portal. This means that users can continue to utilize Log Analytics in conjunction with Microsoft Sentinel.

    The Defender XDR data lake will remain Microsoft-managed, with no direct customer access, except through Advanced Hunting and supported APIs. This ensures that data management and security remain under Microsoft's control while still providing some access for advanced querying.

    After enabling the Microsoft Defender XDR connector, it is recommended to disable individual Defender product connectors (such as Defender for Endpoint, Identity, Office 365, Cloud Apps) to avoid duplicate ingestion and reduce costs associated with Sentinel.

    Non-Defender log sources, including Syslog, CEF, Windows Security Events, Azure Activity, and firewalls, will continue to ingest directly into Sentinel Log Analytics and not into Defender XDR. This allows for a broader range of data sources to be utilized within Microsoft Sentinel without being routed through Defender XDR.

    This information should help validate your architecture, cost impact, and operational design for Sentinel going forward.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.