{"id":2702,"date":"2026-03-26T16:08:19","date_gmt":"2026-03-26T16:08:19","guid":{"rendered":"https:\/\/clouddirect.net\/learning-hub\/?p=2702"},"modified":"2026-03-26T16:08:20","modified_gmt":"2026-03-26T16:08:20","slug":"microsoft-sentinel-move-to-defender-portal","status":"publish","type":"post","link":"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/","title":{"rendered":"Microsoft Sentinel Is Moving to the Defender Portal: Everything IT Teams Need to Know\u00a0"},"content":{"rendered":"\n<p><strong><em>Written by&nbsp;<a href=\"https:\/\/www.linkedin.com\/in\/robindadswell\/\">Robin Dadswell<\/a>,&nbsp;Principal Consultant<\/em><\/strong>&nbsp;<\/p>\n\n<p><strong>When&nbsp;I\u2019m&nbsp;talking to customers&nbsp;one&nbsp;subject&nbsp;is coming up&nbsp;repeatedly.&nbsp;Microsoft Sentinel&nbsp;\u2013 and&nbsp;there\u2019s&nbsp;a&nbsp;lot of confusion.&nbsp;Is&nbsp;it&nbsp;being retired?&nbsp;Is&nbsp;it being absorbed into&nbsp;Defender? Do we need new licenses?&nbsp;I&nbsp;want to explain&nbsp;what\u2019s&nbsp;happening, when,&nbsp;and what it means for you.&nbsp;<\/strong>&nbsp;<\/p>\n\n<p>But before&nbsp;we get into the detail&nbsp;let\u2019s&nbsp;start with some clarity.&nbsp;Microsoft Sentinel is not being retired. Its&nbsp;Security Information and Event Management&nbsp;(SIEM)&nbsp;and&nbsp;Security Orchestration, Automation, and Response (SOAR)&nbsp;capabilities&nbsp;remain&nbsp;fully supported. What&nbsp;<em>is<\/em>&nbsp;changing is where and how it is managed: Sentinel is moving from the Azure portal into the Microsoft Defender portal as part of Microsoft\u2019s broader&nbsp;\u2018unified security operations\u2019&nbsp;strategy.&nbsp;<\/p>\n\n<p>For IT teams, SOC analysts, architects and governance leads,&nbsp;here\u2019s&nbsp;what that&nbsp;means&nbsp;both&nbsp;operationally and technically.&nbsp;<\/p>\n\n<h2 class=\"wp-block-heading\" id=\"h-microsoft-sentinel-and-defender-in-a-nutshell\"><strong>Microsoft Sentinel and Defender: in a nutshell<\/strong><\/h2>\n\n<p>First a&nbsp;quick&nbsp;explanation&nbsp;\u2013 please skip ahead to&nbsp;What is and&nbsp;isn\u2019t&nbsp;changing&nbsp;if&nbsp;you\u2019re&nbsp;already familiar with&nbsp;Sentinel and Defender.&nbsp;&nbsp;<\/p>\n\n<p>Microsoft Defender is Microsoft\u2019s broad threat protection platform.&nbsp;It\u2019s&nbsp;a&nbsp;family of&nbsp;products with each focusing on&nbsp;different&nbsp;aspects&nbsp;of your environment.&nbsp;Such as&nbsp;Defender for Endpoint (laptops, servers),&nbsp;Identity (Active Directory),&nbsp;Cloud (cloud workloads),&nbsp;Office 365 (email&nbsp;and&nbsp;collaboration), and&nbsp;Cloud Apps (SaaS).&nbsp;&nbsp;<\/p>\n\n<p>Defender sits close to the asset and actively&nbsp;flags or&nbsp;blocks threats.&nbsp;It\u2019s&nbsp;protective and preventative.&nbsp;&nbsp;<\/p>\n\n<p>Whereas&nbsp;Microsoft Sentinel is&nbsp;a&nbsp;Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platform.&nbsp;It&nbsp;works across your environment&nbsp;taking data&nbsp;from&nbsp;Microsoft Defender, firewalls,&nbsp;identity providers, third-party security tools,&nbsp;and cloud platforms&nbsp;(e.g.&nbsp;Azure,&nbsp;and&nbsp;AWS).&nbsp;It&nbsp;collects&nbsp;security logs, correlates&nbsp;signals,&nbsp;detects&nbsp;suspicious patterns, generates&nbsp;incidents for investigation, and automates&nbsp;response workflows.&nbsp;&nbsp;<\/p>\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-and-nbsp-isn-t-nbsp-changing-nbsp-in-the-sentinel-nbsp-move-nbsp\"><strong>What is and&nbsp;isn\u2019t&nbsp;changing&nbsp;in the Sentinel&nbsp;move<\/strong>&nbsp;<\/h2>\n\n<p>The major change&nbsp;is the management experience.&nbsp;Sentinel&nbsp;will&nbsp;be&nbsp;exclusively managed through&nbsp;the Microsoft Defender portal&nbsp;\u2013 with the Azure Portal&nbsp;being retired.&nbsp;&nbsp;<\/p>\n\n<p>The aim is to provide a unified security operations&nbsp;experience&nbsp;with a single&nbsp;pane&nbsp;of glass for&nbsp;both SIEM and&nbsp;Extended Detection and Response&nbsp;(XDR).&nbsp;It&nbsp;ensures a consistent user interface for SIEM and XDR&nbsp;with&nbsp;native, cross domain, correlation of&nbsp;incident&nbsp;timeline and&nbsp;evidence.&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n<h3 class=\"wp-block-heading\" id=\"h-what-is-not-changing-nbsp-nbsp-nbsp-nbsp\"><strong>What is NOT changing:&nbsp;&nbsp;&nbsp;<\/strong>&nbsp;<\/h3>\n\n<ul class=\"wp-block-list\">\n<li>Sentinel\u2019s core SIEM functionality&nbsp;remains&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>Azure Log Analytics&nbsp;will&nbsp;remain the underlying data platform&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>KQL&nbsp;(Kusto Query Language)&nbsp;analytics rules continue to operate&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>Sentinel and Defender Access Controls&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>Automation playbooks continue to function&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>Sentinel licensing&nbsp;remains&nbsp;separate from Defender&nbsp;(see later).&nbsp;<\/li>\n<\/ul>\n\n<h3 class=\"wp-block-heading\" id=\"h-timelines-nbsp\"><strong>Timelines<\/strong>&nbsp;<\/h3>\n\n<ul class=\"wp-block-list\">\n<li>New Sentinel workspaces are already, automatically onboarded to the Defender portal&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>July 2026 (a date you may have heard)&nbsp;was the target date for retiring the Azure portal&nbsp;&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>31 March 2027&nbsp;is the&nbsp;extended deadline&nbsp;for&nbsp;when&nbsp;Sentinel will&nbsp;cease to&nbsp;be supported in the Azure&nbsp;portal.&nbsp;<\/li>\n<\/ul>\n\n<h3 class=\"wp-block-heading\" id=\"h-what-nbsp-is-nbsp-changing-nbsp-nbsp\"><strong>What&nbsp;IS&nbsp;changing&nbsp;<\/strong>&nbsp;<\/h3>\n\n<p id=\"h-what-is-changing-underneath-the-surface-there-are-some-noteworthy-changes-affecting-correlation-alert-logic-and-data-schemas-let-s-look-at-each-of-these-in-a-bit-more-detail\">Underneath the surface&nbsp;there are some noteworthy changes affecting&nbsp;correlation,&nbsp;alert logic, and&nbsp;data schemas.&nbsp;Let\u2019s&nbsp;look at&nbsp;each of these&nbsp;in a bit more detail.&nbsp;&nbsp;<\/p>\n\n<p><strong>Correlation&nbsp;is more cohesive<\/strong>&nbsp;<br>Historically,&nbsp;Sentinel has&nbsp;relied on&nbsp;KQL-driven&nbsp;analytics&nbsp;rules, scheduled&nbsp;queries&nbsp;and&nbsp;Fusion detection. Whereas&nbsp;Defender performed its own&nbsp;correlation within Microsoft 365 security.&nbsp;&nbsp;&nbsp;<\/p>\n\n<p>In the unified Defender portal alerts from&nbsp;Sentinel and Defender XDR&nbsp;both feed into a&nbsp;shared incident model.&nbsp;Sentinel\u2019s legacy Fusion engine&nbsp;is disabled as part of the move to the Defender Portal&nbsp;at which point correlation is processed via the Defender XDR logic, this unifies&nbsp;incident creation in the same manner as other Defender Alerts enabling&nbsp;a single logic flow for all alert generations.&nbsp;&nbsp;<\/p>\n\n<p><strong>What does not change:&nbsp;<\/strong><\/p>\n\n<ul class=\"wp-block-list\">\n<li>Custom KQL detections&nbsp;will&nbsp;still run&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>Log-based analytics&nbsp;will&nbsp;remain intact&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>Workspace-level data architecture&nbsp;remains.&nbsp;<\/li>\n<\/ul>\n\n<p><strong>What does change:&nbsp;<\/strong><\/p>\n\n<ul class=\"wp-block-list\">\n<li>Incident grouping logic&nbsp;is expected to&nbsp;evolve&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>Alerts may appear more&nbsp;consolidated&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>Multi-signal correlation becomes more tightly integrated.&nbsp;<\/li>\n<\/ul>\n\n<p>For most,&nbsp;this will be an enhancement. But you should check alert tuning and&nbsp;correlation during transition.&nbsp;&nbsp;<\/p>\n\n<h2 class=\"wp-block-heading\" id=\"h-unified-dynamic-alerts-and-incidents\">Unified dynamic alerts and incidents<\/h2>\n\n<p>Previously&nbsp;Defender products generated alerts,&nbsp;which&nbsp;Sentinel&nbsp;grouped&nbsp;into incidents.&nbsp;Now,&nbsp;Defender XDR generates&nbsp;the&nbsp;incidents&nbsp;with&nbsp;Sentinel analytics alerts feeding&nbsp;into the same incident&nbsp;\u2013&nbsp;and correlation&nbsp;can&nbsp;occur before&nbsp;an&nbsp;analyst&nbsp;sees the case.&nbsp;<\/p>\n\n<p>In practice, this&nbsp;could mean that&nbsp;incidents&nbsp;are&nbsp;differently grouped,&nbsp;that alert-to-incident mapping shifts,&nbsp;and&nbsp;that&nbsp;there\u2019s&nbsp;less noise with&nbsp;better cross-product stitching.&nbsp;<\/p>\n\n<p>While these&nbsp;aren\u2019t&nbsp;disruptive changes,&nbsp;it\u2019s&nbsp;worth&nbsp;making some checks&nbsp;after transition:&nbsp;&nbsp;&nbsp;<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Validate incident population behaviour&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>Confirm escalation workflows still align&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>Review automation triggers.&nbsp;<\/li>\n<\/ul>\n\n<h3 class=\"wp-block-heading\" id=\"h-table-and-data-schema-evolution-not-revolution\"><strong>Table and data schema: evolution, not revolution<\/strong><\/h3>\n\n<p>For&nbsp;table and data schema&nbsp;it\u2019s&nbsp;more a case of&nbsp;incremental alignment,&nbsp;than&nbsp;structural&nbsp;change.&nbsp;&nbsp;<\/p>\n\n<p>Rest assured&nbsp;that&nbsp;Sentinel\u2019s&nbsp;data backbone&nbsp;remains&nbsp;Azure Log Analytics. Neither&nbsp;are&nbsp;tables, custom logs, and KQL queries disappearing.&nbsp;But&nbsp;Microsoft is gradually harmonising schemas between&nbsp;Sentinel log tables,&nbsp;Defender Advanced Hunting, and unified incident entities.&nbsp;This&nbsp;may&nbsp;produce greater normalisation of entity mapping, reduced duplication across alert tables, and closer alignment between hunting queries and SIEM queries.&nbsp;&nbsp;<\/p>\n\n<p>So, things may not&nbsp;be&nbsp;exactly as you expect.&nbsp;<strong>Pay&nbsp;close&nbsp;attention to what is happening&nbsp;and&nbsp;validate&nbsp;schema references during the transition.<\/strong>&nbsp;<\/p>\n\n<h2 class=\"wp-block-heading\" id=\"h-why-is-microsoft-doing-this-nbsp\"><strong>Why is Microsoft doing this?<\/strong>&nbsp;<\/h2>\n\n<p>The move reflects&nbsp;what\u2019s&nbsp;happening&nbsp;across the&nbsp;industry,&nbsp;with&nbsp;security vendors&nbsp;consolidating&nbsp;SIEM and XDR into unified SecOps platforms.&nbsp;<\/p>\n\n<p>Effective threat detection is increasingly&nbsp;reliant on&nbsp;visibility of&nbsp;identity signals, endpoint telemetry,&nbsp;cloud workloads, email, network logs, and behavioural analytics.&nbsp;<\/p>\n\n<p>Microsoft is aligning its&nbsp;security&nbsp;offerings&nbsp;to provide:&nbsp;&nbsp;<\/p>\n\n<ul class=\"wp-block-list\">\n<li>One portal&nbsp;&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>One incident queue&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>Integrated correlation&nbsp;and&nbsp;&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>Shared investigation workflows.&nbsp;&nbsp;<\/li>\n<\/ul>\n\n<p>Strategically,&nbsp;it&nbsp;strengthens Microsoft\u2019s position as a full-spectrum security&nbsp;provider, enabling organisations to&nbsp;utilise a single pane of glass for SecOps&nbsp;activities.&nbsp;<\/p>\n\n<h3 class=\"wp-block-heading\" id=\"h-licensing-is-still-separate-nbsp\"><strong>Licensing is still separate<\/strong>&nbsp;<\/h3>\n\n<p>One of the biggest misconceptions is that Sentinel is being folded into a new Defender licence.&nbsp;This is not the case:&nbsp;<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Sentinel\u2019s (ingestion-based) licensing&nbsp;remains&nbsp;separate&nbsp;&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>Defender licensing&nbsp;remains&nbsp;separate&nbsp;&nbsp;<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>Portal consolidation&nbsp;does NOT mean&nbsp;licence consolidation.&nbsp;<\/li>\n<\/ul>\n\n<p>However,&nbsp;some threat intelligence features&nbsp;are being folded into Defender&nbsp;so&nbsp;it\u2019s&nbsp;worth reviewing&nbsp;licensing,&nbsp;especially&nbsp;for those&nbsp;with Microsoft E5\/A5 subscriptions.&nbsp;&nbsp;&nbsp;<\/p>\n\n<h2 class=\"wp-block-heading\" id=\"h-what-you-need-to-do-nbsp-to-migrate-sentinel-nbsp\"><strong>What you need to do&nbsp;to migrate Sentinel<\/strong>&nbsp;<\/h2>\n\n<p>While this&nbsp;isn\u2019t&nbsp;an emergency&nbsp;migration,&nbsp;it would be foolish to&nbsp;do nothing&nbsp;\u2013 these are&nbsp;changes that need&nbsp;managing properly.&nbsp;&nbsp;<\/p>\n\n<p>Recommended actions:&nbsp;<\/p>\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Plan to transition&nbsp;in&nbsp;good time&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li>Check your licensing (especially if on a E5\/A5&nbsp;subscription)&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li>Review RBAC alignment between Azure and Defender&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"4\" class=\"wp-block-list\">\n<li>Test incident grouping behaviour in the unified portal&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"5\" class=\"wp-block-list\">\n<li>Validate custom KQL queries and workbooks&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"6\" class=\"wp-block-list\">\n<li>Update documentation and runbooks.&nbsp;<\/li>\n<\/ol>\n\n<p>Handled&nbsp;correctly, you can have a smooth transition.&nbsp;&nbsp;&nbsp;<\/p>\n\n<p>Consider also, whether this is an opportunity to formally review your configuration and settings against best practice.&nbsp;<\/p>\n\n<p id=\"h-in-short\"><strong>In short&nbsp;<\/strong><\/p>\n\n<p>Sentinel&nbsp;isn\u2019t&nbsp;disappearing&nbsp;and&nbsp;Defender&nbsp;isn\u2019t&nbsp;\u2018taking over\u2019&nbsp;\u2013 Microsoft is unifying its security stack.&nbsp;&nbsp;<\/p>\n\n<p>If&nbsp;you\u2019re&nbsp;already invested in Microsoft security this&nbsp;is an evolution that&nbsp;will improve future operations.&nbsp;For others, it&nbsp;reflects both&nbsp;the&nbsp;SIEM market\u2019s&nbsp;consolidation around broader security platforms&nbsp;and Microsoft\u2019s commitment to&nbsp;remaining&nbsp;relevant to your&nbsp;SecOps&nbsp;needs.&nbsp;&nbsp;<\/p>\n\n<p>Find out how Cloud Direct can help you&nbsp;optimise Defender and Sentinel with a security assessment.&nbsp;Request a call with&nbsp;me&nbsp;through the form below.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Written by&nbsp;Robin Dadswell,&nbsp;Principal Consultant&nbsp; When&nbsp;I\u2019m&nbsp;talking to customers&nbsp;one&nbsp;subject&nbsp;is coming up&nbsp;repeatedly.&nbsp;Microsoft Sentinel&nbsp;\u2013 and&nbsp;there\u2019s&nbsp;a&nbsp;lot of confusion.&nbsp;Is&nbsp;it&nbsp;being retired?&nbsp;Is&nbsp;it being absorbed into&nbsp;Defender? Do we need new licenses?&nbsp;I&nbsp;want to explain&nbsp;what\u2019s&nbsp;happening, when,&nbsp;and what it means for you.&nbsp;&nbsp; But before&nbsp;we get into the detail&nbsp;let\u2019s&nbsp;start with some clarity.&nbsp;Microsoft Sentinel is not being retired. Its&nbsp;Security Information and Event Management&nbsp;(SIEM)&nbsp;and&nbsp;Security Orchestration, Automation, and Response (SOAR)&nbsp;capabilities&nbsp;remain&nbsp;fully supported. [&hellip;]<\/p>\n","protected":false},"author":44,"featured_media":2704,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[31],"tags":[86,66,85],"post_media_type":[24],"class_list":["post-2702","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-security","tag-defender","tag-microsoft-security","tag-sentinel","post_media_type-blog"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Microsoft Sentinel Moves to Defender Portal<\/title>\n<meta name=\"description\" content=\"Microsoft Sentinel is moving to the Microsoft Defender portal. Learn what\u2019s changing, what stays the same, timelines, and how you should prepare.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Microsoft Sentinel Is Moving to the Defender Portal: Everything IT Teams Need to Know\u00a0\" \/>\n<meta property=\"og:description\" content=\"Microsoft Sentinel is moving to the Microsoft Defender portal. Learn what\u2019s changing, what stays the same, timelines, and how you should prepare.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/\" \/>\n<meta property=\"og:site_name\" content=\"Learning Hub\" \/>\n<meta property=\"article:published_time\" content=\"2026-03-26T16:08:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-03-26T16:08:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/clouddirect.net\/learning-hub\/wp-content\/uploads\/sites\/2\/2026\/03\/Sentinel-to-Defender-Blog-Header-Image.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"abbieantoine\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"abbieantoine\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/microsoft-sentinel-move-to-defender-portal\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/microsoft-sentinel-move-to-defender-portal\\\/\"},\"author\":{\"name\":\"abbieantoine\",\"@id\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/#\\\/schema\\\/person\\\/74dbe97225c05374d42d142cdc1d2a28\"},\"headline\":\"Microsoft Sentinel Is Moving to the Defender Portal: Everything IT Teams Need to Know\u00a0\",\"datePublished\":\"2026-03-26T16:08:19+00:00\",\"dateModified\":\"2026-03-26T16:08:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/microsoft-sentinel-move-to-defender-portal\\\/\"},\"wordCount\":1615,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/microsoft-sentinel-move-to-defender-portal\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2026\\\/03\\\/Sentinel-to-Defender-Blog-Header-Image.png\",\"keywords\":[\"Defender\",\"Microsoft Security\",\"Sentinel\"],\"articleSection\":[\"Microsoft Security\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/microsoft-sentinel-move-to-defender-portal\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/microsoft-sentinel-move-to-defender-portal\\\/\",\"url\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/microsoft-sentinel-move-to-defender-portal\\\/\",\"name\":\"Microsoft Sentinel Moves to Defender Portal\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/microsoft-sentinel-move-to-defender-portal\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/microsoft-sentinel-move-to-defender-portal\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2026\\\/03\\\/Sentinel-to-Defender-Blog-Header-Image.png\",\"datePublished\":\"2026-03-26T16:08:19+00:00\",\"dateModified\":\"2026-03-26T16:08:20+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/#\\\/schema\\\/person\\\/74dbe97225c05374d42d142cdc1d2a28\"},\"description\":\"Microsoft Sentinel is moving to the Microsoft Defender portal. Learn what\u2019s changing, what stays the same, timelines, and how you should prepare.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/microsoft-sentinel-move-to-defender-portal\\\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/microsoft-sentinel-move-to-defender-portal\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/microsoft-sentinel-move-to-defender-portal\\\/#primaryimage\",\"url\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2026\\\/03\\\/Sentinel-to-Defender-Blog-Header-Image.png\",\"contentUrl\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2026\\\/03\\\/Sentinel-to-Defender-Blog-Header-Image.png\",\"width\":1600,\"height\":900,\"caption\":\"Sentinel to Defender Header Image\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/microsoft-sentinel-move-to-defender-portal\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Microsoft Sentinel Is Moving to the Defender Portal: Everything IT Teams Need to Know\u00a0\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/#website\",\"url\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/\",\"name\":\"Learning Hub\",\"description\":\"Cloud Direct\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/#\\\/schema\\\/person\\\/74dbe97225c05374d42d142cdc1d2a28\",\"name\":\"abbieantoine\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fce602c3177d962945f4172c276ce0c8abbd01fc5fd47682808e33229e221c82?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fce602c3177d962945f4172c276ce0c8abbd01fc5fd47682808e33229e221c82?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fce602c3177d962945f4172c276ce0c8abbd01fc5fd47682808e33229e221c82?s=96&d=mm&r=g\",\"caption\":\"abbieantoine\"},\"url\":\"https:\\\/\\\/clouddirect.net\\\/learning-hub\\\/author\\\/abbiefawcett\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Microsoft Sentinel Moves to Defender Portal","description":"Microsoft Sentinel is moving to the Microsoft Defender portal. Learn what\u2019s changing, what stays the same, timelines, and how you should prepare.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/","og_locale":"en_GB","og_type":"article","og_title":"Microsoft Sentinel Is Moving to the Defender Portal: Everything IT Teams Need to Know\u00a0","og_description":"Microsoft Sentinel is moving to the Microsoft Defender portal. Learn what\u2019s changing, what stays the same, timelines, and how you should prepare.","og_url":"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/","og_site_name":"Learning Hub","article_published_time":"2026-03-26T16:08:19+00:00","article_modified_time":"2026-03-26T16:08:20+00:00","og_image":[{"width":1600,"height":900,"url":"https:\/\/clouddirect.net\/learning-hub\/wp-content\/uploads\/sites\/2\/2026\/03\/Sentinel-to-Defender-Blog-Header-Image.png","type":"image\/png"}],"author":"abbieantoine","twitter_card":"summary_large_image","twitter_misc":{"Written by":"abbieantoine","Estimated reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/#article","isPartOf":{"@id":"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/"},"author":{"name":"abbieantoine","@id":"https:\/\/clouddirect.net\/learning-hub\/#\/schema\/person\/74dbe97225c05374d42d142cdc1d2a28"},"headline":"Microsoft Sentinel Is Moving to the Defender Portal: Everything IT Teams Need to Know\u00a0","datePublished":"2026-03-26T16:08:19+00:00","dateModified":"2026-03-26T16:08:20+00:00","mainEntityOfPage":{"@id":"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/"},"wordCount":1615,"commentCount":0,"image":{"@id":"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/#primaryimage"},"thumbnailUrl":"https:\/\/clouddirect.net\/learning-hub\/wp-content\/uploads\/sites\/2\/2026\/03\/Sentinel-to-Defender-Blog-Header-Image.png","keywords":["Defender","Microsoft Security","Sentinel"],"articleSection":["Microsoft Security"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/","url":"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/","name":"Microsoft Sentinel Moves to Defender Portal","isPartOf":{"@id":"https:\/\/clouddirect.net\/learning-hub\/#website"},"primaryImageOfPage":{"@id":"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/#primaryimage"},"image":{"@id":"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/#primaryimage"},"thumbnailUrl":"https:\/\/clouddirect.net\/learning-hub\/wp-content\/uploads\/sites\/2\/2026\/03\/Sentinel-to-Defender-Blog-Header-Image.png","datePublished":"2026-03-26T16:08:19+00:00","dateModified":"2026-03-26T16:08:20+00:00","author":{"@id":"https:\/\/clouddirect.net\/learning-hub\/#\/schema\/person\/74dbe97225c05374d42d142cdc1d2a28"},"description":"Microsoft Sentinel is moving to the Microsoft Defender portal. Learn what\u2019s changing, what stays the same, timelines, and how you should prepare.","breadcrumb":{"@id":"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/#primaryimage","url":"https:\/\/clouddirect.net\/learning-hub\/wp-content\/uploads\/sites\/2\/2026\/03\/Sentinel-to-Defender-Blog-Header-Image.png","contentUrl":"https:\/\/clouddirect.net\/learning-hub\/wp-content\/uploads\/sites\/2\/2026\/03\/Sentinel-to-Defender-Blog-Header-Image.png","width":1600,"height":900,"caption":"Sentinel to Defender Header Image"},{"@type":"BreadcrumbList","@id":"https:\/\/clouddirect.net\/learning-hub\/microsoft-sentinel-move-to-defender-portal\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/clouddirect.net\/learning-hub\/"},{"@type":"ListItem","position":2,"name":"Microsoft Sentinel Is Moving to the Defender Portal: Everything IT Teams Need to Know\u00a0"}]},{"@type":"WebSite","@id":"https:\/\/clouddirect.net\/learning-hub\/#website","url":"https:\/\/clouddirect.net\/learning-hub\/","name":"Learning Hub","description":"Cloud Direct","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/clouddirect.net\/learning-hub\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/clouddirect.net\/learning-hub\/#\/schema\/person\/74dbe97225c05374d42d142cdc1d2a28","name":"abbieantoine","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/secure.gravatar.com\/avatar\/fce602c3177d962945f4172c276ce0c8abbd01fc5fd47682808e33229e221c82?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/fce602c3177d962945f4172c276ce0c8abbd01fc5fd47682808e33229e221c82?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/fce602c3177d962945f4172c276ce0c8abbd01fc5fd47682808e33229e221c82?s=96&d=mm&r=g","caption":"abbieantoine"},"url":"https:\/\/clouddirect.net\/learning-hub\/author\/abbiefawcett\/"}]}},"_links":{"self":[{"href":"https:\/\/clouddirect.net\/learning-hub\/wp-json\/wp\/v2\/posts\/2702","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/clouddirect.net\/learning-hub\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/clouddirect.net\/learning-hub\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/clouddirect.net\/learning-hub\/wp-json\/wp\/v2\/users\/44"}],"replies":[{"embeddable":true,"href":"https:\/\/clouddirect.net\/learning-hub\/wp-json\/wp\/v2\/comments?post=2702"}],"version-history":[{"count":6,"href":"https:\/\/clouddirect.net\/learning-hub\/wp-json\/wp\/v2\/posts\/2702\/revisions"}],"predecessor-version":[{"id":2715,"href":"https:\/\/clouddirect.net\/learning-hub\/wp-json\/wp\/v2\/posts\/2702\/revisions\/2715"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/clouddirect.net\/learning-hub\/wp-json\/wp\/v2\/media\/2704"}],"wp:attachment":[{"href":"https:\/\/clouddirect.net\/learning-hub\/wp-json\/wp\/v2\/media?parent=2702"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/clouddirect.net\/learning-hub\/wp-json\/wp\/v2\/categories?post=2702"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/clouddirect.net\/learning-hub\/wp-json\/wp\/v2\/tags?post=2702"},{"taxonomy":"post_media_type","embeddable":true,"href":"https:\/\/clouddirect.net\/learning-hub\/wp-json\/wp\/v2\/post_media_type?post=2702"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}