How to Find Who Activated Microsoft Sentinel and Defender XDR Integration
Question details
An administrator needs to determine who enabled the integration between Microsoft Sentinel and Microsoft Defender XDR, and when it occurred.

- Product
- Microsoft Sentinel and Defender XDR
- Device & OS
- not provided
- Scenario
- Auditing system configuration changes to identify the user and timestamp for a security integration activation.
- Observed behavior
- The integration between Microsoft Sentinel and Microsoft Defender XDR is active, but the administrator lacks the information or KQL queries required to determine who performed the action and when.
Ensure you have global administrator or security administrator privileges in your Microsoft tenant to view audit logs and access the Microsoft Defender portal.
Request Guidance in the Microsoft Defender Community
Because auditing integration enablement requires specialized knowledge of Microsoft Defender's logging architecture, consulting Microsoft experts is the most effective approach.
Finding the exact user and timestamp for the Microsoft Sentinel and Defender XDR unification often requires querying specific tables in advanced hunting or the unified audit log. The Microsoft Tech Community provides direct access to security experts who can share the exact Kusto Query Language (KQL) scripts needed.
Open your web browser and navigate to the official Microsoft Defender for Endpoint Community at https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/bd-p/MicrosoftDefenderATP.
Click the Sign In button at the top right of the page and log in using your Microsoft administrative account.
Click on 'Start a new conversation'. Detail your need to find who unified Sentinel with Defender XDR, and ask the community for the specific audit sources or KQL queries.

Search the Unified Audit Logs in Microsoft Purview
You can manually search for configuration changes within your tenant's unified audit logs.
Looking for a Reliable and Free Alternative to Microsoft Office?
While enterprise security management requires specialized Microsoft tools like Defender XDR, your daily documentation and reporting don't have to rely on expensive software. WPS Office provides a lightweight, comprehensive, and highly compatible alternative for handling your documents, spreadsheets, and presentations effortlessly.
- 1. Visit the Official Website: Go to the WPS Office official website to access the latest secure installation files.
- 2. Download the Installer: Click the 'Free Download' button to download the setup file for your operating system.
- 3. Install and Launch: Run the downloaded installer, follow the on-screen prompts, and launch WPS Office to start managing your reports.

Frequently Asked Questions
Can I use KQL in the Defender XDR console to find configuration changes?
Yes, Kusto Query Language (KQL) can be used in the 'Advanced hunting' section of the Microsoft Defender XDR portal to query logs. However, locating specific integration activation events usually requires querying the CloudAppEvents table for specific administrative actions.
Do I need special permissions to view Sentinel integration logs?
Yes, you must have the appropriate administrative roles assigned in your tenant, such as Security Administrator, Global Administrator, or specific read access to Microsoft Sentinel and the unified audit logs.
How long are audit logs retained in Microsoft Defender?
By default, Microsoft Purview and Defender retain audit logs for 180 days for standard licenses. This retention period can be extended up to 1 year or more depending on your organization's specific Microsoft 365 licensing and customized audit retention policies.




