Blog Post

Microsoft Sentinel Blog
4 MIN READ

Public Preview: Nested API Support Comes to Microsoft Sentinel CCF

Robert_Moriarty's avatar
Aug 05, 2026

Microsoft Sentinel continues to evolve its capabilities to support an expanding ecosystem of partners and data integrations. Recent innovations include the Codeless Connector Framework (CCF) Push feature, the new Sentinel connector builder agent, and the CCF expansion to pull data from Azure Storage Blob. Each of these reflects our ongoing investment in making it easier for ISVs and developers to build scalable, high-fidelity data connectors that bring telemetry into Sentinel data lake.

Today, we are excited to announce another advancement in this journey – the public preview for Nested API support in CCF.

What is Nested API support and Why it Matters

Nested API support enables a pattern common across many ISV log sources, where a single polling cycle spans multiple dependent API calls: an initial call returns a list of records (such as alert IDs or case references), and one or more follow-up calls fetch the full detail for each record in that list.

This support allows CCF to accommodate the list-then-detail API pattern as it exists in many API designs, so that partners don’t need to restructure or adapt their endpoints. The result is broader integration coverage that allows partners to connect data sources whose APIs are naturally paginated across multiple calls, and then to ingest complete records into Microsoft Sentinel without building custom middleware.

Support for Nested API in the Microsoft Sentinel VS Code extension

This pattern is also available through the Visual Studio Code (VS Code) extension for Microsoft Sentinel connectors. The extension is an agentic tool that helps ISVs and partners build, test, and package data connectors more efficiently, providing a guided experience for bringing data into Microsoft Sentinel.

As part of its design, the extension enables developers to implement Nested API workflows, allowing connectors to orchestrate multi-step API calls and support APIs that require chained or dependent requests. To learn more, see the Sentinel connector builder agent blog and the Microsoft Learn documentation for implementation guidance.

Real-world adoption: Early ISV implementations

A growing set of solutions are already leveraging Nested API support to enable multi-step data retrieval scenarios. These early implementations demonstrate how partners are using this capability to structure connector workflows around their existing APIs. Some of the early adopters and their solutions are listed below.

 

 

 BigID


BigID integrates with Microsoft Sentinel to extend data security posture management (DSPM) insights into security operations workflows. The solution brings visibility into sensitive, regulated, and critical data across cloud, SaaS, and on‑premises environments, helping security teams understand data‑related risk and exposure. Built on the Codeless Connector Framework (CCF), the integration can leverage capabilities such as Nested API retrieval to ingest more detailed, context‑rich records through multi‑step API calls, supporting more informed investigation and prioritization.

 

 

Cisco Email Threat Defense

Cisco Email Threat Defense integrates with Microsoft Sentinel to bring email‑borne threat detections into centralized security operations. The connector ingests all information that can be used as security signals, such as phishing and malware indicators, enabling teams to correlate email activity with broader incidents and improve investigation and response. Built on the Codeless Connector Framework (CCF), the integration supports advanced patterns like Nested API retrieval, allowing more detailed event context to be ingested through multi‑step API calls without requiring changes to the underlying data source.

 

 

 

Idera Audit

Idira® Audit by Palo Alto Networks integrates with Microsoft Sentinel to centralize visibility into privileged identity and access activity. By streaming detailed audit logs—covering system events, user actions, and administrative activity—into Sentinel, security teams can correlate identity‑driven risks with broader security telemetry. Built on the Codeless Connector Framework (CCF), the integration can leverage capabilities such as Nested Application Programming Interface retrieval to ingest more detailed, context‑rich records, supporting faster investigation and more effective response. 

 

 

In addition to these early third-party adopters, some Microsoft-built connectors that also leverage this pattern are listed below:

Build with Nested APIs in Microsoft Sentinel

Developers and partners can begin leveraging Nested API support today as part of the Codeless Connector Framework. To get started, review the Microsoft Learn documentation for implementation guidance and explore existing connector configurations that demonstrate this pattern. You can also jump right in and explore building with mock data using our Nested API Lab.

As Microsoft Sentinel continues to expand its ecosystem, App Assure works closely with partners to help onboard and optimize integrations. If you are building or extending a connector and would like support, the App Assure team is available to help you get started. Reach out to us via our intake form.

Additional Sentinel Feature Public Preview Announcements

Updated Aug 03, 2026
Version 1.0