Skip to content

Commit 6edb703

Browse files
Merge pull request #310947 from sbreingold-ms/wi-547153-sunset-sentinel-date
wi-547153-sunset-sentinel-date-change
2 parents 8799a1f + 832024e commit 6edb703

4 files changed

Lines changed: 23 additions & 8 deletions

File tree

articles/sentinel/includes/sentinel-azure-deprecation.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,15 +4,15 @@ description: Provides an include file for reuse of the Microsoft Sentinel in the
44
services: microsoft-sentinel
55
author: batamig
66
ms.topic: "include"
7-
ms.date: 07/01/2025
7+
ms.date: 01/28/2026
88
ms.author: bagol
99
ms.custom: "include file"
1010
---
1111

1212

1313
Microsoft Sentinel is [generally available in the Microsoft Defender portal](../microsoft-sentinel-defender-portal.md), including for customers without Microsoft Defender XDR or an E5 license. This means that you can use Microsoft Sentinel in the Defender portal even if you aren't using other Microsoft Defender services.
1414

15-
Starting in **July 2026**, Microsoft Sentinel will be supported in the Defender portal only, and any remaining customers using the Azure portal will be automatically redirected.
15+
After **March 31, 2027**, Microsoft Sentinel will no longer be supported in the Azure portal and will be available only in the Microsoft Defender portal.
1616

1717
If you're currently using Microsoft Sentinel in the Azure portal, we recommend that you start planning your transition to the Defender portal now to ensure a smooth transition and take full advantage of the [unified security operations experience offered by Microsoft Defender](/unified-secops-platform/overview-unified-security).
1818

articles/sentinel/includes/unified-soc-preview.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,15 +4,15 @@ description: Provides an include file for the general Microsoft Sentinel Azure p
44
services: microsoft-sentinel
55
author: batamig
66
ms.topic: "include"
7-
ms.date: 07/16/2025
7+
ms.date: 01/28/2026
88
ms.author: bagol
99
ms.custom: "include file"
1010
---
1111

1212
> [!IMPORTANT]
1313
> [Microsoft Sentinel is generally available in the Microsoft Defender portal](../microsoft-sentinel-defender-portal.md), including for customers without Microsoft Defender XDR or an E5 license.
1414
>
15-
> Starting in **July 2026**, all customers using Microsoft Sentinel in the Azure portal will be [redirected to the Defender portal and will use Microsoft Sentinel in the Defender portal only](../overview.md#microsoft-sentinel-in-the-azure-portal-retirement-timeline). Starting in **July 2025**, many new customers are [automatically onboarded and redirected to the Defender portal](../overview.md#changes-for-new-customers-starting-july-2025).
15+
> After **March 31, 2027**, Microsoft Sentinel will no longer be supported in the Azure portal and will be available only in the Microsoft Defender portal. All customers using Microsoft Sentinel in the Azure portal will be [redirected to the Defender portal and will use Microsoft Sentinel in the Defender portal only](../overview.md#microsoft-sentinel-in-the-azure-portal-retirement-timeline). Starting in **July 2025**, many new customers are [automatically onboarded and redirected to the Defender portal](../overview.md#changes-for-new-customers-starting-july-2025).
1616
>
1717
> If you're still using Microsoft Sentinel in the Azure portal, we recommend that you start planning your [transition to the Defender portal](../move-to-defender.md) to ensure a smooth transition and take full advantage of the [unified security operations experience offered by Microsoft Defender](/unified-secops-platform/overview-unified-security). For more information, see [It’s Time to Move: Retiring Microsoft Sentinel’s Azure portal for greater security](https://techcommunity.microsoft.com/blog/microsoft-security-blog/planning-your-move-to-microsoft-defender-portal-for-all-microsoft-sentinel-custo/4428613).
1818

articles/sentinel/overview.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ author: guywi-ms
55
ms.author: guywild
66
ms.topic: overview
77
ms.service: microsoft-sentinel
8-
ms.date: 09/14/2025
8+
ms.date: 01/28/2026
99
ms.custom: sfi-image-nochange
1010

1111
# Customer intent: As a business decision-maker evaluating SIEM/SOAR solutions, I want a summary of Microsoft Sentinel’s cloud-native capabilities so I can determine whether it meets my organization’s security, compliance, and operational requirements and plan adoption or migration.
@@ -124,7 +124,7 @@ This table highlights the key capabilities in Microsoft Sentinel for threat resp
124124

125125
For the sake of the changes described in this section, new Microsoft Sentinel customers are customers who are [onboarding the first workspace in their tenant to Microsoft Sentinel](quickstart-onboard.md).
126126

127-
Starting **July, 2025**, such new customers who also have the permissions of a subscription [Owner](/azure/role-based-access-control/built-in-roles#owner) or a [User access administrator](/azure/role-based-access-control/built-in-roles#user-access-administrator), and are not Azure Lighthouse-delegated users, have their workspaces automatically onboarded to the Defender portal together with onboarding to Microsoft Sentinel.
127+
Starting **July 2025**, such new customers who also have the permissions of a subscription [Owner](/azure/role-based-access-control/built-in-roles#owner) or a [User access administrator](/azure/role-based-access-control/built-in-roles#user-access-administrator), and are not Azure Lighthouse-delegated users, have their workspaces automatically onboarded to the Defender portal together with onboarding to Microsoft Sentinel.
128128

129129
Users of such workspaces, who also aren't Azure Lighthouse-delegated users, see links in Microsoft Sentinel in the Azure portal that redirect them to the Defender portal.
130130

articles/sentinel/whats-new.md

Lines changed: 17 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn about the latest new features and announcement in Microsoft S
44
author: guywi-ms
55
ms.author: guywild
66
ms.topic: concept-article
7-
ms.date: 01/22/2026
7+
ms.date: 01/28/2026
88
#Customer intent: As a security team member, I want to stay updated on the latest features and enhancements in Microsoft Sentinel so that I can effectively manage and optimize my organization's security posture.
99
ms.custom:
1010
- build-2025
@@ -20,6 +20,10 @@ The listed features were released in the last six months. For information about
2020

2121
## January 2026
2222

23+
### Updated date: Microsoft Sentinel in the Azure portal to be retired March 2027
24+
25+
[!INCLUDE [sentinel-azure-deprecation](includes/sentinel-azure-deprecation.md)]
26+
2327
### UEBA behaviors layer aggregates actionable insights from raw logs in near-real time (Preview)
2428

2529
Microsoft Sentinel introduces a UEBA behaviors layer that transforms high-volume, low-level security logs into clear, human-readable behavioral insights in the Defender portal. This AI-powered capability aggregates and sequences raw events from supported data sources into normalized behaviors that explain "who did what to whom" with MITRE ATT&CK context.
@@ -306,7 +310,18 @@ For more information, see:
306310

307311
### Microsoft Sentinel in the Azure portal to be retired July 2026
308312

309-
[!INCLUDE [sentinel-azure-deprecation](includes/sentinel-azure-deprecation.md)]
313+
Microsoft Sentinel is [generally available in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md), including for customers without Microsoft Defender XDR or an E5 license. This means that you can use Microsoft Sentinel in the Defender portal even if you aren't using other Microsoft Defender services.
314+
315+
Starting in **July 2026**, Microsoft Sentinel will be supported in the Defender portal only, and any remaining customers using the Azure portal will be automatically redirected.
316+
317+
If you're currently using Microsoft Sentinel in the Azure portal, we recommend that you start planning your transition to the Defender portal now to ensure a smooth transition and take full advantage of the [unified security operations experience offered by Microsoft Defender](/unified-secops-platform/overview-unified-security).
318+
319+
For more information, see:
320+
321+
- [Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md)
322+
- [Transition your Microsoft Sentinel environment to the Defender portal](move-to-defender.md)
323+
- [Planning your move to Microsoft Defender portal for all Microsoft Sentinel customers](https://techcommunity.microsoft.com/blog/microsoft-security-blog/planning-your-move-to-microsoft-defender-portal-for-all-microsoft-sentinel-custo/4428613) (blog)
324+
310325

311326
## June 2025
312327

0 commit comments

Comments
 (0)