Cannot enable UEBA feature on Microsoft Sentinel

Martin Grihangne 20 Reputation points
2023-10-31T03:26:30.3466667+00:00

I can't enable the UEBA feature on Microsoft Sentinel. When going through the form to enable it, on step 2 it shows the error message "Updating the Entity Providers failed."

I have the Security Administrator admin role in AAD/Entra and the Contributor RBAC role on the subscription.

User's image

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,122 questions
{count} votes

2 answers

Sort by: Most helpful
  1. JamesTran-MSFT 36,596 Reputation points Microsoft Employee
    2023-11-01T22:18:16.82+00:00

    @Martin Grihangne

    Thank you for your post and I apologize for the delayed response!

    I wasn't able to reproduce your issue, but it does look like you have the necessary permissions to enable UEBA in Microsoft Sentinel. However, the error message that you're receiving Updating the Entity Providers failed indicates that there might be an issue with the configuration of your entity providers.

    To help you troubleshoot this issue, can you try the following steps:

    1. Confirm you met all the pre-requisites to enable User and Entity Behavior Analytics
    2. Set up Data sources / connectors as needed per the Deployment guide for Microsoft Sentinel. From your screenshot, it looks like you don't have any Data sources / connectors set up, which could be causing your issue. For more info.

    I hope this helps!


    If you're still having issues, please let me know. Thank you for your time and patience throughout this issue.


  2. jay vk 0 Reputation points
    2024-01-23T08:34:03.94+00:00

    The Error is due to deployment of "Create new OMS solution" which is blocked by some default policy. You need global contributor access or User Access Administrator which provides permission to write policy. With global contributor you can resolve this error.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.