Coming from a development and security product background, I know I am not the only person whose attention is split between what a platform does today and what teams will need from it next. This change is worth being aware of now—not when the deadline is close.
Microsoft Sentinel in the Azure portal will reach end of support on March 31, 2027. After that date, Sentinel will be available through the Microsoft Defender portal.
Microsoft has published its announcement and transition guidance. The headline is simple, but the operational work deserves an early start.
This is a transition, not a rebuild
Moving to the Defender portal does not mean rebuilding Sentinel. Existing investments in Log Analytics, KQL, analytics rules, and data ingestion remain.
The experience around those investments is changing, however. SOC and development teams should use the period when both portals are available to confirm that their existing environment behaves as expected in Defender.
Particular attention should go to the parts of the environment that are easiest to assume will simply continue working:
- Custom data connectors
- Scripts and APIs
- Automation rules
- Logic App playbooks
- Workbooks
- Other bespoke integrations and operational tooling

The screenshot above is from security.microsoft.com, where Microsoft Sentinel now sits alongside the wider Defender experience. Seeing the familiar Sentinel capabilities in their new operational home makes the direction of travel tangible—but presence in the navigation is not the same as validation of your particular implementation.
A simple transition plan
| Target | Action |
|---|---|
| Now | Start using Sentinel in the Defender portal alongside Azure |
| By October 2026 | Test connectors, KQL, analytics, scripts, automation, and playbooks |
| By December 2026 | Update SOC SOPs, documentation, and operational procedures |
| November–December 2026 | Train SOC and development teams and run incident scenarios |
| January 2027 | Make Defender the primary Sentinel experience |
| January–March 2027 | Use this as a contingency and remediation period |
| March 31, 2027 | Azure portal Sentinel reaches end of support |
Do not make March 31 your migration date
The overlap between Azure and Defender gives teams time to test rather than assume.
Start dual use now. Validate customizations by October. Update SOPs and train teams by December. Aim to transition operationally in January 2027.
That leaves three months to resolve the things you did not expect before the Azure portal experience reaches end of support. For teams operating security tooling, that margin is not wasted time. It is what turns a vendor deadline into a controlled product and operational transition.