Share via

AMA Data Connectors Showing Disconnected While Legacy Shows Connected – How to Fix?

Muhammad Ali 0 Reputation points
2026-02-13T12:11:12.8266667+00:00

We have Windows Security Events configured via AMA and the DCR is properly in place. We are not using MMA.

However, on the Data Connectors page, the legacy Windows Security Events connector shows as Connected, while Windows Security Events via AMA shows as Disconnected.

We are seeing the same issue with the FortiGate Data Connector. AMA is configured and MMA is not in use, but the connector status does not appear correctly.

Can anyone please advise how to fix this issue?

Microsoft Security | Microsoft Sentinel
{count} votes

1 answer

Sort by: Most helpful
  1. Shubham Sharma 10,725 Reputation points Microsoft External Staff Moderator
    2026-02-13T16:11:44.5833333+00:00

    Hey Muhammad! It looks like you’re having some trouble with your Windows Security Events connector showing as disconnected via AMA, despite being configured correctly. The same issue seems to be happening with your FortiGate Data Connector. Here's a few things you can try to fix the issue:

    1. Verify Data Collection Rule (DCR):
      • Ensure that the Data Collection Rule (DCR) for the AMA is correctly set up and associated with the right resources. The DCR and the workspace should be in the same region.
      • You can check the DCR settings in the Azure portal to confirm they haven’t been inadvertently modified.
    2. Health Monitoring:
      • If you haven't already, consider enabling the Microsoft Sentinel health feature for your workspace. This can help you monitor the health of your data connectors, including identifying issues with the AMA.
      • Refer to the Microsoft Sentinel health monitoring documentation for detailed steps.
    3. Check Agent Logs:
      • Look into the Azure Monitor Agent logs for any error messages or warnings that may indicate why the connection is showing as disconnected. You may find it useful to follow the troubleshooting guidance for the Azure Monitor agent on Windows VMs here.
    4. Firewall Configuration:
      • Make sure that any firewall rules allow the necessary ports for the AMA to communicate with Azure services. Check the list of network requirements to ensure everything is set correctly.
    5. Inspect for Data Updates:
      • As a rule of thumb, ensure that the connectors are set to receive logs. The connector will show as connected only if it has received any data in the last seven days. If there hasn’t been activity, it might show as disconnected even if configured correctly.
    6. Reinstalling or Updating the Agent:
      • If the above steps don’t work, consider reinstalling the Azure Monitor Agent or updating it to the latest version to eradicate any potential issues from an outdated installation.

    If these steps don't resolve the issue, could you provide a bit more information?

    • Have there been any recent changes to your environment that might have impacted the configuration?
    • Are there any specific error messages appearing in the logs or Azure portal that could give more context?
    • Which region is your workspace and DCR located in?

    Hope this helps to get things up and running again! Let me know if you need further assistance.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.