Sentinel restore refuses to delete forcing charges

Lee Fowler 0 Reputation points
2025-12-02T12:28:26.5066667+00:00

We have been asked by an auditor to prove we can restore data in sentinel but when we try and delete it, it refuses to delete and then shows a date issue along side the restore.

We are charged for this but cannot find a phone number or a single way to dispute this due to a failed service.

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. David Broggy 6,776 Reputation points MVP Volunteer Moderator
    2025-12-02T17:37:44.8166667+00:00

    Hi Lee,

    you may need to provide more details on how exactly you are deleting and restoring data.

    Sentinel uses a log analytics workspace.

    If an attacker deletes the workspace you should be able to restore it if you have soft delete enabled:

    Check for soft-deleted workspaces

    Get-AzOperationalInsightsDeletedWorkspace -ResourceGroupName "your-rg"

    Restore if within 14 days

    Restore-AzOperationalInsightsWorkspace -ResourceGroupName "your-rg" -Name "deleted-workspace-name" -Location "region"

    Note: data cannot be restored at the table level, just the workspace level.

    Recommendation: Use the Sentinel Data Lake mirroring feature to provide a copy of your data in the data lake for long retention periods. If your workspace is deleted you will still have a copy in the data lake! (per-table configuration).

    Reference:
    https://cybermohr.ghost.io/2025/05/28/protecting-your-microsoft-sentinel-solution-from-deletion-or-corruption/

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.