Migrate to Innovate Summit:
Learn how migrating and modernizing to Azure can boost your business's performance, resilience, and security, enabling you to fully embrace AI.Register now
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Complete the following steps to remove Microsoft Sentinel from your Log Analytics workspace.
Before removing Sentinel, note that you will no longer have visibility to manage Sentinel tables, such as setting extended data retention, in the Log Analytics Tables UI. Please consider per-table retention to 90 days or less to avoid data retention charges for the Sentinel data that Log Analytics will store, but which you can no longer access after Sentinel is removed.
For Microsoft Sentinel in the Azure portal, under Configuration, select Settings. On the Settings page, select the Settings tab.
For Microsoft Sentinel in the Defender portal, select System > Settings > Microsoft Sentinel.
Review the Know before you go... section and the rest of this document carefully. Take all the necessary actions before proceeding.
Select the appropriate checkboxes to let us know why you're removing Microsoft Sentinel. Enter any other details in the space provided, and indicate whether you want Microsoft to email you in response to your feedback.
Select Remove Microsoft Sentinel from your workspace.
Clean up resources in the Azure portal (optional)
If you don't want to keep the workspace and the data collected for Microsoft Sentinel, delete the resources associated with the workspace in the Azure portal.
Delete just the individual resources within the associated resource group that you no longer need. For more information, see Delete resource.
Or, if you don't need any of the resources in the associated resource group, delete the resource group. For more information, see Delete resource group.