Gene Library Courses Download Pricing Contact Sign in
microsoft-sentinel logo
security Official Website

Microsoft Sentinel MCP Server – Security Data Access

Microsoft Sentinel provides hosted Model Context Protocol tool collections for security operations. The MCP server lets compatible AI clients explore Sentinel data lake content, analyze entities, triage incidents, hunt threats, and build Security Copilot agents using Microsoft Entra-authenticated access.

#siem#threat-hunting#incident-triage

Overview

Microsoft Sentinel's MCP support is a hosted set of Model Context Protocol tool collections for security operations. Instead of deploying a local server, teams connect MCP-compatible clients to Microsoft-hosted Sentinel endpoints that expose scenario-focused security tools. The integration is designed for analysts, SOC engineers, threat hunters, and agent builders who need natural language access to security data and workflows.

What the MCP server enables

Microsoft documents three Sentinel MCP collections. The data exploration collection helps agents search for relevant tables, query Microsoft Sentinel data lake, retrieve security data, and analyze entities such as users, URLs, and devices. The Security Copilot agent creation collection helps create Security Copilot agents for complex security workflows. The triage collection supports incident triage and threat hunting over organization data.

These tools help an AI agent translate analyst intent into security operations such as finding risky users, summarizing recent sign-in failures, investigating suspicious network activity, enriching entities, or identifying indicators of compromise from threat analytics. Access depends on the connected user's Microsoft permissions and the product prerequisites for each collection.

When to use it

Use Microsoft Sentinel MCP when an AI assistant needs live SOC context from Microsoft Sentinel rather than general security knowledge. Practical use cases include exploring long-term security data without writing KQL manually, correlating user or device signals during investigations, triaging incidents, hunting for attacker activity, and building repeatable Security Copilot agents for internal workflows.

Connection and authentication

Microsoft Sentinel's MCP server is hosted by Microsoft and uses HTTP-based MCP connections from compatible clients such as Visual Studio Code, Microsoft Security Copilot, Copilot Studio, and Microsoft Foundry. Authentication is handled through Microsoft Entra ID. Microsoft states that most tools require onboarding to Microsoft Sentinel data lake, while some collections also require Microsoft Sentinel in the Defender portal, Microsoft Defender XDR or Defender for Endpoint, or Microsoft Security Copilot. Users need at least the Security reader role to list and invoke Sentinel MCP tools, while the triage collection follows the user's existing permissions.

Key considerations

The MCP collections are tied to Microsoft Sentinel product access, tenant permissions, and Microsoft Entra identity. They are not anonymous public endpoints and should be connected only from trusted MCP clients. Tool availability varies by collection and product prerequisite. Security teams should grant least-privilege roles, review access to sensitive security data, and remember that MCP-based write or automation workflows can affect incident response processes if exposed to overly broad users or agents.

Supported Transports

streamable_http

URL: https://sentinel.microsoft.com/mcp/data-exploration

streamable_http

URL: https://sentinel.microsoft.com/mcp/security-copilot-agent-creation

streamable_http

URL: https://sentinel.microsoft.com/mcp/triage

Frequently Asked Questions

When should an AI agent use this MCP server?
Use Microsoft Sentinel MCP when an agent needs to explore Sentinel data lake, analyze security entities, triage incidents, hunt threats, or assist with Security Copilot agent creation using live Microsoft security data.
What does this MCP server add to an AI agent's capabilities?
It gives the agent hosted, Microsoft Entra-authenticated access to scenario-focused security tools for Sentinel data exploration, entity analysis, incident triage, threat hunting, and Security Copilot agent creation instead of relying on static model knowledge.
What can the AI agent access or manage through this server?
Depending on the connected collection and user permissions, the agent can search for relevant security tables, retrieve data from Microsoft Sentinel data lake, analyze entities, support incident triage, hunt threats, and create Security Copilot agents for security workflows.
How is authentication configured for this MCP server?
Authentication is handled with Microsoft Entra ID through the compatible MCP client. Microsoft states that users need at least the Security reader role to list and invoke Sentinel MCP tools, and some collections require onboarding to Microsoft Sentinel data lake or related Microsoft security products.
Which transport should be used for this MCP server?
Use the hosted streamable HTTP endpoints for the specific Microsoft Sentinel collection you need: data exploration, Security Copilot agent creation, or triage. No local stdio server is documented for these hosted Sentinel MCP collections.