Sentinel: Creating Alerts for Windows Update Compliance in GCC Environment — No Data Ingestion

Adam Ring JIT 0 Reputation points
2026-09-11T18:15:32.3266667+00:00

Problem description

I am trying to create an alert in Microsoft Sentinel for Windows Update compliance below 90%, but no data is being ingested into Sentinel despite enabling Windows Update for Business reports over a week ago.

Environment

Microsoft Sentinel in a GCC cloud environment, with Windows Update for Business reports / Update Compliance as the data source.

What I've already tried

I have enabled Windows Update for Business reports in my Log Analytics workspace and waited over a week, but no ingested data appears in Sentinel. I reviewed support documentation and the initial support reply indicated 'No data found.' The case history shows no additional diagnostic output or troubleshooting steps taken by support.

Current status

Currently, I am seeking guidance on whether Windows Update for Business reports can support data ingestion in a GCC environment for compliance alerts, and what alternative supported options exist for monitoring Windows Update compliance in my environment.

Microsoft Security | Microsoft Sentinel
0 comments No comments

2 answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Konstantinos Lianos 830 Reputation points Student Ambassador
    2026-09-15T08:59:31.8833333+00:00

    Hello @Adam Ring JIT

    If your Sentinel workspace is in GCC High or DoD / Azure Government, this is most likely expected behavior.

    Windows Update for Business reports aren't currently supported in GCC High/DoD, so the related UC* tables won't populate in Log Analytics. In that case, waiting longer won't resolve the issue.

    For Windows Update compliance monitoring, you can consider alternatives such as Configuration Manager (SCCM/MECM), Azure Update Manager for supported server workloads, or a **custom compliance collection into Log Analytics and then create a Sentinel analytics rule to alert when compliance drops below 90%.

    If you're using standard GCC rather than GCC High/DoD, it's worth confirming the exact cloud environment first, as support differs between them.

    If this answer helps, please mark it as Answered.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.