Defender Unified RBAC also shows “Failed to load workspace data.”

Abdulrhman Abbad 0 Reputation points
2026-09-10T15:18:51.77+00:00

I have a Microsoft Sentinel workspace connected to Defender XDR as Primary, but Advanced Hunting does not show any Sentinel workspace tables in Schema.
workspace('<WorkspaceID>').<Table> is unavailable, while Azure Portal Sentinel/Log Analytics queries work normally.

The user is Global Administrator and Subscription Owner.

Defender Unified RBAC also shows “Failed to load workspace data.”

Disconnect/reconnect was already tried, and the workspace was recreated.

What is the current official fix or known issue for this Defender-Sentinel integration problem?

Microsoft Security | Microsoft Sentinel
0 comments No comments

1 answer

Sort by: Most helpful
  1. Konstantinos Lianos 830 Reputation points Student Ambassador
    2026-09-15T09:01:02.1166667+00:00

    Hello @Abdulrhman Abbad

    This doesn't look like an ingestion issue, since the Sentinel tables are available and query successfully from Log Analytics.

    According to Microsoft documentation, once a Sentinel workspace is connected to the Defender portal, its tables should appear in Advanced Hunting > Schema and should be queryable there. The current documented Advanced Hunting known issues don't list missing Sentinel workspace tables or the “Failed to load workspace data” error as an expected limitation.

    One thing to verify is permissions. Global Administrator by itself doesn't automatically provide access to Sentinel workspace data. Microsoft requires Security Administrator or higher together with either an unconditional Subscription Owner assignment, or User Access Administrator + Microsoft Sentinel Contributor.

    If those permissions are already correct, especially if the Owner assignment is unconditional, and disconnect/reconnect plus workspace recreation didn't resolve it, I would treat this as a Defender portal workspace onboarding / RBAC synchronization issue rather than recreate the workspace again.

    There isn't currently a documented self-service fix for this specific behavior. I would open a Microsoft support case for Microsoft Defender XDR / Microsoft Sentinel and ask them to validate the backend Sentinel workspace registration and Unified RBAC synchronization. Include the tenant ID, workspace ID, UTC timestamp, and screenshot of the “Failed to load workspace data” error.

    If this answer helps, please mark it as Answered.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.