{
 "categories": [
  "enterprise",
  "observability"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-09-11",
   "fact": "homepage",
   "note": "Microsoft presents Microsoft Sentinel as a cloud-native SIEM for detection, investigation, hunting, and response, now generally available in the Microsoft Defender portal.",
   "source": "https://learn.microsoft.com/en-us/azure/sentinel/overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "license",
   "note": "Sentinel is a commercial Microsoft Security product sold with Azure and Defender portal onboarding. This pass did not open a public price list.",
   "source": "https://learn.microsoft.com/en-us/azure/sentinel/overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "platforms",
   "note": "Microsoft documents Sentinel in the Microsoft Defender portal and, until 31 March 2027, in the Azure portal. Both are web consoles.",
   "source": "https://learn.microsoft.com/en-us/azure/sentinel/overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.api.exists",
   "note": "Microsoft publishes Microsoft Sentinel REST APIs to create and manage data connectors, analytic rules, incidents, bookmarks, and entity information.",
   "source": "https://learn.microsoft.com/en-us/rest/api/securityinsights/",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.api.kinds[0]",
   "note": "The documented management surface is a REST API. Incident operations and the data-lake KQL API are HTTP JSON endpoints.",
   "source": "https://learn.microsoft.com/en-us/rest/api/securityinsights/",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.api.auth[0]",
   "note": "The data-lake KQL API requires an OAuth 2.0 bearer token in the Authorization header. Microsoft documents authentication with a user access token.",
   "source": "https://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-queries-api",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.api.auth[1]",
   "note": "Microsoft also documents service-principal authentication to the Sentinel data lake KQL API. Entra ID roles and Defender XDR unified RBAC are noted as currently unsupported for that service-principal path.",
   "source": "https://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-queries-api",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.api.coverage",
   "note": "REST coverage includes connectors, analytic rules, incidents, and bookmarks. The separate data-lake KQL API queries lake workspaces. Neither page claims the entire Sentinel UI.",
   "source": "https://learn.microsoft.com/en-us/rest/api/securityinsights/",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.api.docs",
   "note": "Opened Microsoft's current Sentinel REST API landing page for Security Insights management operations.",
   "source": "https://learn.microsoft.com/en-us/rest/api/securityinsights/",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.mcp.first_party",
   "note": "Microsoft documents Sentinel support for MCP as a unified hosted server that uses Microsoft Entra and scenario-focused tool collections.",
   "source": "https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.mcp.verdict",
   "note": "The Learn overview is vendor documentation for Microsoft Sentinel's hosted MCP server, including data-lake exploration, entity analysis, Security Copilot agent creation, and incident triage.",
   "source": "https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.cli.exists",
   "note": "Microsoft documents the Azure CLI sentinel extension (az sentinel) to manage alert rules, automation rules, incidents, data connectors, watchlists, and related Sentinel resources.",
   "source": "https://learn.microsoft.com/en-us/cli/azure/sentinel",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.extensibility.scripting",
   "note": "Microsoft documents automation rules, Logic Apps playbooks, and KQL hunting queries as first-party Sentinel automation surfaces.",
   "source": "https://learn.microsoft.com/en-us/azure/sentinel/overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.data_access.export[0]",
   "note": "The KQL query API returns results in structured JSON for automation workflows. Incident REST operations also return JSON resource documents.",
   "source": "https://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-queries-api",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "verdict.scores.api",
   "note": "Sentinel REST plus the data-lake KQL API are documented, Entra-authenticated, and cover incidents, connectors, rules, and lake queries. Portal transition and lake-specific auth notes keep the path below unusual completeness.",
   "source": "https://learn.microsoft.com/en-us/rest/api/securityinsights/",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "verdict.scores.mcp",
   "note": "The official hosted collections are useful for lake exploration, entity analysis, and triage. Learn states that most tools require Microsoft Sentinel data-lake onboarding and Security reader. That tenant gate keeps the score at official-useful rather than unusually complete.",
   "source": "https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-get-started",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "verdict.scores.cli",
   "note": "az sentinel is an official Azure CLI extension with broad Sentinel resource commands. Many create, update, and delete operations are marked Experimental, so the CLI path is useful rather than fully GA.",
   "source": "https://learn.microsoft.com/en-us/cli/azure/sentinel",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "freshness.watch[0].url",
   "note": "Opened Microsoft's current Sentinel MCP overview, including the hosted Entra-authenticated server and scenario collections for lake exploration, agents, and triage.",
   "source": "https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "freshness.watch[1].url",
   "note": "Opened Microsoft's current Sentinel MCP get-started page. It states that most tools require data-lake onboarding and the Security reader role.",
   "source": "https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-get-started",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "freshness.watch[2].url",
   "note": "Opened Microsoft's current Sentinel REST API landing page for connectors, analytic rules, incidents, and bookmarks.",
   "source": "https://learn.microsoft.com/en-us/rest/api/securityinsights/",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "freshness.watch[3].url",
   "note": "Opened Microsoft's current data-lake KQL REST page, including POST https://api.securityplatform.microsoft.com/lake/kql/v2/rest/query and OAuth bearer auth.",
   "source": "https://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-queries-api",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-11",
  "volatility": "high",
  "watch": [
   {
    "type": "mcp",
    "url": "https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-overview"
   },
   {
    "type": "mcp",
    "url": "https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-get-started"
   },
   {
    "type": "docs",
    "url": "https://learn.microsoft.com/en-us/rest/api/securityinsights/"
   },
   {
    "type": "docs",
    "url": "https://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-queries-api"
   }
  ]
 },
 "homepage": "https://learn.microsoft.com/en-us/azure/sentinel/overview",
 "id": "microsoft-sentinel",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": "unknown"
  },
  "api": {
   "auth": [
    "oauth2",
    "service-principal"
   ],
   "coverage": "partial",
   "docs": "https://learn.microsoft.com/en-us/rest/api/securityinsights/",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": true
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [
    "playbooks",
    "automation-rules",
    "kql"
   ],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Sentinel REST, the data-lake KQL API, Azure CLI az sentinel, and hosted MCP collections cover SIEM operations without browser control of the Defender or Azure portal. This record is not Microsoft Azure as a whole-cloud identity.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Microsoft Sentinel",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "crowdstrike-falcon",
   "wiz",
   "splunk"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Microsoft",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 8,
   "cli": 6,
   "computer_use": null,
   "integrations": null,
   "mcp": 7,
   "overall": 8,
   "rpa": null
  },
  "summary": "Microsoft Sentinel is automatable today through Azure Resource Manager Security Insights REST APIs and a data-lake KQL REST API. This record is Sentinel SIEM and data lake, not CrowdStrike Falcon, Wiz, Splunk, or Microsoft Azure as a whole-cloud identity. The Sentinel REST APIs create and manage data connectors, analytic rules, incidents, and bookmarks. Incident list, get, create-or-update, delete, and run playbook are documented on management.azure.com under Microsoft.SecurityInsights. Data-lake queries POST to https://api.securityplatform.microsoft.com/lake/kql/v2/rest/query with an OAuth 2.0 bearer token from a user or a service principal. Microsoft documents a hosted Sentinel MCP interface with scenario-focused collections. Most MCP tools require onboarding to the Microsoft Sentinel data lake and at least the Security reader role. The data-exploration collection is hosted at https://sentinel.microsoft.com/mcp/data-exploration. Azure CLI exposes az sentinel for incidents, alert rules, connectors, and watchlists; many of those commands are marked Experimental. Connector catalogs were not opened. Computer-use viability is unassessed. API scores 8 and is the best path because ARM and KQL REST do not depend on data-lake MCP onboarding. MCP scores 7: official and useful, with that onboarding gate.\n"
 }
}