Prerequisites include a Sentinel-enabled Log Analytics workspace, the Microsoft Defender XDR solution and connector with incidents and alerts enabled, Defender XDR access in the same Entra tenant, and suitable Azure roles.
- Open the Defender portal and select Connect a workspace.
- Select the Sentinel workspace and review product changes.
- Confirm that Sentinel tables and functions become available to advanced hunting.
- Connect and verify unified metrics, incidents, connectors, and automation.
Owner, or User Access Administrator plus Sentinel Contributor, is required to connect or disconnect at the documented scopes. Reader supports viewing and querying; Contributor supports incident actions. Azure RBAC continues to be managed in Azure.
Exam takeaway: onboarding can deactivate Microsoft-security incident creation rules to prevent duplicates while streaming Defender alerts through the primary XDR connector.
Official lessonPrerequisites, roles, connect, and disconnect