Security teams are increasingly exploring how AI assistants support them in investigating incidents, asking questions, and exploring their data. At the same time, controlling how data is accessed remains critical. Today, we’re sharing how Sentinel can support a third-party AI assistant like Claude through a new integration approach using Sentinel’s Model Context Protocol (MCP) server, while continuing to rely on Microsoft Entra ID for enterprise grade authentication and access control. This approach uses Microsoft Sentinel with Entra ID to let third-party AI tools access Sentinel data.
Why this matters
Sentinel customers can explore security data using natural language to assist investigations, while preserving strict tenant isolation and access controls, without managing app registrations or shared secrets. AI third-party assistants like Claude can access Sentinel through Microsoft’s existing security infrastructure. When a query is made, the assistant calls the Sentinel MCP server, which enforces authentication via Entra ID before returning data. This third-party connector is now available. Click here for detailed guidance.
Resources
- Use the Microsoft Sentinel MCP connector in ChatGPT or Claude Code
Use the Microsoft Sentinel MCP connector in ChatGPT or Claude - Microsoft Security | Microsoft Learn
- Sentinel MCP overview
What is Microsoft Sentinel MCP server's tool collection? - Microsoft Security | Microsoft Learn - Get started with Sentinel MCP
Get started with Microsoft Sentinel MCP server - Microsoft Security | Microsoft Learn
Microsoft Sentinel is an industry-leading SIEM & AI-first platform powering agentic defense across the entire security ecosystem.