Forum Discussion
Defender XDR: Tables not supported for table management
I am trying to extend the table retention of specific tables to allow them to flow to Sentinel Analytics but keep getting the message "This table is not supported for table management" in the Sentinel > Configuration > Tables page.
The Sentinel workspace is connected in System > Settings > Microsoft Sentinel.
I can see the table type is XDR in the list which seems to be the reason why it can't be managed.
Any ideas why this table is not able to be managed.
1 Reply
The screenshot confirms DeviceEvents is currently the built-in XDR-default table: it has 30 days' retention and no Sentinel workspace association, so the disabled control is expected, not a portal error. Connecting a Sentinel workspace in Defender settings does not itself stream every advanced-hunting table. Open the Microsoft Defender XDR data connector for the intended Sentinel workspace, expand Connect events, select DeviceEvents under Defender for Endpoint, and apply the change. After data arrives, verify it in that workspace with a DeviceEvents query and confirm the table is shown as Microsoft Sentinel, not XDR default. Then configure analytics retention from Sentinel > Configuration > Tables. Extending supported XDR data beyond 30 days incurs ingestion charges, with additional storage charges after the included period. If it remains unmanaged, confirm the correct workspace is selected and that your account has Data manage or Log Analytics Contributor permissions.