A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Hello,
Go to Microsoft Defender portal > System > Settings > Microsoft Sentinel > Data lake and confirm the data lake onboarding is complete. Microsoft notes that onboarding can take up to 60 minutes, and newly enabled or moved tables can take 90–120 minutes before data is available.
Confirm you have the right permissions. For data lake read/query access, Microsoft Sentinel supports Microsoft Entra roles such as Security Reader / Security Operator / Security Administrator, or workspace-level Azure RBAC roles such as Log Analytics Reader, Microsoft Sentinel Reader, Microsoft Sentinel Contributor, etc.
For table management, viewing table settings requires permissions such as Security data basics (read) or Microsoft.OperationalInsights/workspaces/tables/read. Configuring table settings requires Data (manage) or Log Analytics write/table write permissions, such as those provided by Log Analytics Contributor.
In Data lake exploration > KQL queries, check the Selected workspaces dropdown. If a workspace is empty or still onboarding, the schema browser may not show tables