A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Hello @Abdulrhman Abbad
This doesn't look like an ingestion issue, since the Sentinel tables are available and query successfully from Log Analytics.
According to Microsoft documentation, once a Sentinel workspace is connected to the Defender portal, its tables should appear in Advanced Hunting > Schema and should be queryable there. The current documented Advanced Hunting known issues don't list missing Sentinel workspace tables or the “Failed to load workspace data” error as an expected limitation.
One thing to verify is permissions. Global Administrator by itself doesn't automatically provide access to Sentinel workspace data. Microsoft requires Security Administrator or higher together with either an unconditional Subscription Owner assignment, or User Access Administrator + Microsoft Sentinel Contributor.
If those permissions are already correct, especially if the Owner assignment is unconditional, and disconnect/reconnect plus workspace recreation didn't resolve it, I would treat this as a Defender portal workspace onboarding / RBAC synchronization issue rather than recreate the workspace again.
There isn't currently a documented self-service fix for this specific behavior. I would open a Microsoft support case for Microsoft Defender XDR / Microsoft Sentinel and ask them to validate the backend Sentinel workspace registration and Unified RBAC synchronization. Include the tenant ID, workspace ID, UTC timestamp, and screenshot of the “Failed to load workspace data” error.
If this answer helps, please mark it as Answered.