logo
search
Account Security Problems

How to Find Who Activated Microsoft Sentinel and Defender XDR Integration

Chanuka GeekiyanageChanuka Geekiyanage Sep 28, 2026 869 views

Question details

An administrator needs to determine who enabled the integration between Microsoft Sentinel and Microsoft Defender XDR, and when it occurred.

How to Find Who Activated Microsoft Sentinel and Defender XDR Integration
Product
Microsoft Sentinel and Defender XDR
Device & OS
not provided
Scenario
Auditing system configuration changes to identify the user and timestamp for a security integration activation.
Observed behavior
The integration between Microsoft Sentinel and Microsoft Defender XDR is active, but the administrator lacks the information or KQL queries required to determine who performed the action and when.
Before you start

Ensure you have global administrator or security administrator privileges in your Microsoft tenant to view audit logs and access the Microsoft Defender portal.

Solution 1Recommended

Request Guidance in the Microsoft Defender Community

Because auditing integration enablement requires specialized knowledge of Microsoft Defender's logging architecture, consulting Microsoft experts is the most effective approach.

Finding the exact user and timestamp for the Microsoft Sentinel and Defender XDR unification often requires querying specific tables in advanced hunting or the unified audit log. The Microsoft Tech Community provides direct access to security experts who can share the exact Kusto Query Language (KQL) scripts needed.

1
Access the Tech Community

Open your web browser and navigate to the official Microsoft Defender for Endpoint Community at https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/bd-p/MicrosoftDefenderATP.

2
Sign In to Your Account

Click the Sign In button at the top right of the page and log in using your Microsoft administrative account.

3
Post Your Query

Click on 'Start a new conversation'. Detail your need to find who unified Sentinel with Defender XDR, and ask the community for the specific audit sources or KQL queries.

Request Guidance in the Microsoft Defender Community
English Only Support: The Microsoft Defender for Endpoint Community primarily operates in English, so ensure your query is written in English for the best response rate.
Free Microsoft Office alternative

Looking for a Reliable and Free Alternative to Microsoft Office?

While enterprise security management requires specialized Microsoft tools like Defender XDR, your daily documentation and reporting don't have to rely on expensive software. WPS Office provides a lightweight, comprehensive, and highly compatible alternative for handling your documents, spreadsheets, and presentations effortlessly.

  1. 1. Visit the Official Website: Go to the WPS Office official website to access the latest secure installation files.
  2. 2. Download the Installer: Click the 'Free Download' button to download the setup file for your operating system.
  3. 3. Install and Launch: Run the downloaded installer, follow the on-screen prompts, and launch WPS Office to start managing your reports.
Seamlessly compatible with Microsoft Word, Excel, and PowerPoint file formats (.docx, .xlsx, .pptx) for easy reporting.Completely free to download and use for all your essential documentation needs.Lightweight design ensures fast launch times and minimal system resource usage on your workstation.Familiar tabbed user interface makes transitioning smooth and easy without a learning curve.
QA img-9

Frequently Asked Questions

Can I use KQL in the Defender XDR console to find configuration changes?

Yes, Kusto Query Language (KQL) can be used in the 'Advanced hunting' section of the Microsoft Defender XDR portal to query logs. However, locating specific integration activation events usually requires querying the CloudAppEvents table for specific administrative actions.

Do I need special permissions to view Sentinel integration logs?

Yes, you must have the appropriate administrative roles assigned in your tenant, such as Security Administrator, Global Administrator, or specific read access to Microsoft Sentinel and the unified audit logs.

How long are audit logs retained in Microsoft Defender?

By default, Microsoft Purview and Defender retain audit logs for 180 days for standard licenses. This retention period can be extended up to 1 year or more depending on your organization's specific Microsoft 365 licensing and customized audit retention policies.