Microsoft will begin automatically onboarding managed Microsoft Sentinel customers that have not yet moved to the unified Microsoft Sentinel experience in the Microsoft Defender portal. The rollout starts in September 2026 and is especially important for managed security service providers and partners responsible for Sentinel environments.
The key preparation area is customers with multiple Microsoft Sentinel workspaces. For most managed customers, Microsoft says no partner action is required. But where multiple workspaces exist, partners should review the environment before onboarding to avoid broken content, unexpected alert routing changes, or operational confusion.
What changed
Microsoft announced that it will manage automatic onboarding for customers that have not moved to the unified Sentinel experience in the Defender portal. Microsoft will handle scheduling, customer notifications, and the technical onboarding process. Tenant administrators are expected to receive an in-portal banner and an admin email approximately 30 days before their scheduled onboarding date.
Existing third-party connectors, content, and data are expected to remain in place. The announcement is dated September 9, 2026, appears in the General workspace, and affects managed security service providers and partners managing Microsoft Sentinel customers.
This update also reinforces a separate deadline: the Microsoft Sentinel experience in the Azure portal is scheduled to retire on March 31, 2027. Automatic onboarding is therefore part of a broader transition toward the Defender portal as the central operational experience.
Why this matters for MSSPs and security partners
For MSSPs, Sentinel is not just a customer tool. It is part of the managed detection and response operating model. Changes to where incidents appear, which workspace is primary, and which rules continue to operate can affect triage, service-level commitments, escalation paths, and customer reporting.
The good news is that Microsoft is reducing the burden of scheduling and executing the onboarding itself. The risk is that automatic onboarding may expose architecture decisions that were previously harmless or hidden. Multi-workspace deployments are common in real environments, especially where customers separate business units, geographies, regulated workloads, or historical deployments.
Once a primary workspace is established for Microsoft Defender XDR alerts and incidents, XDR-dependent content in secondary workspaces may stop functioning. That does not necessarily mean the entire Sentinel deployment is broken, but it does mean MSSPs need to know which rules, automations, playbooks, and workbooks depend on the XDR integration and where they should live after onboarding.
Default behavior and expected impact
Microsoft will select one primary workspace for Microsoft Defender XDR alerts and incidents. If the customer has only a straightforward Sentinel setup, this may require no intervention from the partner. If the customer has multiple workspaces, however, the automatically selected primary workspace may not match the MSSP’s operational preference.
The most important default behavior is that secondary workspaces may lose functionality for content that depends on XDR after the primary workspace is set. Partners should not assume that all analytics rules, automation rules, playbooks, and workbooks will continue working exactly as before in every workspace.
Microsoft also states that existing connectors, content, and data remain in place. That is reassuring, but it should not be confused with a guarantee that every detection or automation workflow will remain operational without review. The distinction matters: retained content is not always the same as functioning content.
Partner readiness checklist
Start by identifying managed customers that use Microsoft Sentinel and have not yet moved to the Defender portal experience. Prioritize customers with multiple Sentinel workspaces, complex automation, heavy XDR dependency, or strict security operations SLAs.
Next, document each customer’s workspace structure. For every workspace, identify its purpose, connected data sources, analytics rules, automation rules, playbooks, workbooks, incident management processes, and reporting dependencies. This inventory will make it easier to decide whether Microsoft’s selected primary workspace is appropriate.
Then, review XDR-dependent content. Any analytics or automation logic that depends on Microsoft Defender XDR alerts or incidents should be evaluated for migration to the primary workspace. Where content is duplicated across workspaces, partners should decide whether to consolidate, retire, or redesign it.
Partners should also prepare a primary workspace preference for customers where the choice matters. If special handling is required or a different primary workspace is needed, Microsoft directs partners to email MSSP-Sentinel-Support@microsoft.com with the tenant ID and preferred workspace resource ID. Because tenant administrators receive notice about 30 days before onboarding, MSSPs should not wait until the banner appears to determine their preferred architecture.
Finally, update customer communications. Customers should understand that Microsoft is managing the onboarding, that the Azure portal experience has a retirement date, and that the MSSP is reviewing any multi-workspace impact. This can reduce confusion when administrators receive Microsoft’s notification.
Bottom line
Automatic onboarding should simplify the move to the unified Microsoft Sentinel experience in the Defender portal, but MSSPs should not treat it as a passive background change for every customer. Multi-workspace environments need review, especially where XDR-dependent detections, automations, or dashboards live outside the future primary workspace.
Partners should inventory affected customers now, confirm primary workspace preferences, migrate dependent content where needed, and prepare customers for the Defender portal transition ahead of the March 31, 2027 Azure portal retirement. Microsoft’s original announcement is available here: Microsoft source.