Azure Sentinel Query Pane Not Taking input/broken

Kellen Connolly 0 Reputation points
2026-06-24T04:21:11.33+00:00

All of our Sentinel Workspaces Logs Query Panes in our Lighthouse instances have now become non-editable, to the point where the query box will not take cursor input or any keyboard input from the users. Using our GDAP technician accounts also doesn't seem to work even though they worked prior.

azure-error

We haven't had any issues prior to this as our permissions were setup properly for our analysts to query the respective workspaces and their resources. We've noticed a lot of browser console erroring is occuring within the Logs Query pane related to session state checking within their reactviews.

Has anyone had any trouble with this as of recently?

Microsoft Security | Microsoft Sentinel
0 comments No comments

1 answer

Sort by: Oldest
  1. Konstantinos Lianos 835 Reputation points Student Ambassador
    2026-10-06T10:11:09.2966667+00:00

    Hi @Kellen Connolly

    Since this started across multiple Lighthouse-managed workspaces and the browser console shows a JavaScript error, this looks more like an Azure Portal/Sentinel UI issue than an RBAC problem.

    As a workaround, try opening the workspace directly through Log Analytics Workspace > Logs or through the Defender portal. Also test an InPrivate session to exclude cached portal components.

    For cross-tenant Sentinel access, make sure the account has the required Azure Lighthouse/RBAC permissions, such as Log Analytics Reader, since GDAP alone does not provide Log Analytics workspace query access. Microsoft Learn

    If the issue persists across browsers/users, I would recommend opening a Microsoft Support case and including the console error.

    If this answer helps, please mark it as Accepted/Resolved so it can help others as well.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.