# Microsoft Sentinel Data Exploration MCP server

> Search for relevant tables and retrieve security data from the Microsoft Sentinel data lake using natural language.

- Listing: https://mcp.tc/i/microsoft-sentinel
- Connect: use the server's own URL `https://sentinel.microsoft.com/mcp/data-exploration` (OAuth sign-in at the server); clients connect to it directly. The listing link is a page, not an MCP endpoint.
- Type: remote (Streamable HTTP)
- Auth: OAuth sign-in
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: Microsoft
- Verified: yes, mcp.tc checked that this is the official server (https://mcp.tc/verify). It says who runs the server, not that it is safe.
- Homepage: <https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-overview>
- Repository: <https://github.com/microsoft/sentinel-data-exploration-mcp>

## About

Connects to the Microsoft Sentinel data lake and lets an assistant find relevant tables and retrieve security data using natural language. It is aimed at building security agents, for example hunts for password spray, impossible travel, multi-factor authentication failures and dormant accounts that become active again.

It runs as a hosted remote endpoint over streamable HTTP at https://sentinel.microsoft.com/mcp/data-exploration. Users sign in with Microsoft Entra ID through OAuth 2.0, and a Microsoft Sentinel data lake is required. Nothing needs to be installed locally.

## What it can do

- Search for relevant tables in the Sentinel data lake
- Retrieve data from the Sentinel data lake in natural language
- Build agents that hunt for password-spray patterns
- Check sign-in events for impossible travel
- Analyze multi-factor authentication failure spikes
- Find dormant accounts that become active again

## Example prompts

- "Which Sentinel tables hold sign-in logs?"
- "Look for password-spray patterns in sign-in data over the last 90 days."
- "Flag users with impossible travel between logins this week."
- "Find dormant accounts that recently became active."

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport http microsoft-sentinel https://sentinel.microsoft.com/mcp/data-exploration
```

2. Start Claude Code, type `/mcp`, pick **microsoft-sentinel** and choose **Authenticate**. A browser window opens for the Microsoft sign-in.

Add `--scope user` to make it available in every project, not just this one.

### Claude Desktop

1. Open **Settings → Connectors** and click **Add custom connector**.

2. Name it **Microsoft Sentinel Data Exploration** and paste this URL:

```url
https://sentinel.microsoft.com/mcp/data-exploration
```

3. Click **Add**, then **Connect**, and sign in when Microsoft asks.

Claude Desktop’s JSON config file only starts local servers. Remote servers go through Connectors, and connectors you add on claude.ai show up here too.

### claude.ai

1. Open the connector form on claude.ai. This button fills in the name and URL for you:

[Add to claude.ai](<https://claude.ai/customize/connectors?modal=add-custom-connector&connectorName=Microsoft%20Sentinel%20Data%20Exploration&connectorUrl=https%3A%2F%2Fsentinel.microsoft.com%2Fmcp%2Fdata-exploration>) (opens connector settings)

2. Check that the URL reads `https://sentinel.microsoft.com/mcp/data-exploration` and click **Add**.

3. Click **Connect** and sign in when Microsoft asks.

Free plans allow one custom connector. On Team and Enterprise plans an owner adds it under **Organization settings → Connectors**.

### ChatGPT

1. On chatgpt.com, open **Settings → Security and login** and turn on **Developer mode**.

2. Go to `chatgpt.com/plugins` and click **+** to create an app for a remote MCP server.

3. Paste `https://sentinel.microsoft.com/mcp/data-exploration` as the server URL and choose **OAuth**. ChatGPT sends you to Microsoft to sign in.

Developer mode is available on the web for Plus, Pro, Business, Enterprise and Education accounts.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=microsoft-sentinel&config=eyJ1cmwiOiJodHRwczovL3NlbnRpbmVsLm1pY3Jvc29mdC5jb20vbWNwL2RhdGEtZXhwbG9yYXRpb24ifQ%3D%3D>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "microsoft-sentinel": {
      "url": "https://sentinel.microsoft.com/mcp/data-exploration"
    }
  }
}
```

Cursor shows **Needs login** next to the server. Click it to sign in.

### VS Code

[Install in VS Code](<https://vscode.dev/redirect/mcp/install?name=microsoft-sentinel&config=%7B%22type%22%3A%22http%22%2C%22url%22%3A%22https%3A%2F%2Fsentinel.microsoft.com%2Fmcp%2Fdata-exploration%22%7D>) (opens VS Code)

Or from a terminal:

```bash
code --add-mcp '{"name":"microsoft-sentinel","type":"http","url":"https://sentinel.microsoft.com/mcp/data-exploration"}'
```

Or commit it to the repo in `.vscode/mcp.json`:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "microsoft-sentinel": {
      "type": "http",
      "url": "https://sentinel.microsoft.com/mcp/data-exploration"
    }
  }
}
```

VS Code asks you to sign in the first time the server starts.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "microsoft-sentinel": {
      "serverUrl": "https://sentinel.microsoft.com/mcp/data-exploration"
    }
  }
}
```

2. Refresh the MCP server list in Cascade and sign in when asked.

Devin Desktop is the new name for Windsurf. It reads `serverUrl` (or `url`) for remote servers.

### Codex

```bash
codex mcp add microsoft-sentinel --url https://sentinel.microsoft.com/mcp/data-exploration
codex mcp login microsoft-sentinel
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.microsoft-sentinel]
url = "https://sentinel.microsoft.com/mcp/data-exploration"
```

### Gemini CLI

```bash
gemini mcp add --transport http microsoft-sentinel https://sentinel.microsoft.com/mcp/data-exploration
```

Then, inside Gemini CLI, run `/mcp auth microsoft-sentinel` to sign in.

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients accept this shape. Some name the URL field differently: `serverUrl` in Devin Desktop, `httpUrl` in Gemini CLI’s settings file.

```json
{
  "mcpServers": {
    "microsoft-sentinel": {
      "type": "http",
      "url": "https://sentinel.microsoft.com/mcp/data-exploration"
    }
  }
}
```

Zed puts servers under `context_servers` in its settings. Cline needs `"type": "streamableHttp"`, or it assumes SSE.

Client only starts local servers? Bridge it with `npx -y mcp-remote https://sentinel.microsoft.com/mcp/data-exploration`.

## Details

- Server version: 1.0.1
- Last checked: 2026-10-03 (reachable, asks for credentials)
- Listed: 2026-10-03
- Updated: 2026-10-03

---
Source: https://mcp.tc/i/microsoft-sentinel (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
