You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/datalake/sentinel-mcp-create-custom-tool.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ titleSuffix: Microsoft Security
4
4
description: Learn how to set up and use custom Microsoft Sentinel Model Context Protocol (MCP) tools using saved KQL queries in advanced hunting
5
5
author: poliveria
6
6
ms.topic: get-started
7
-
ms.date: 11/18/2025
7
+
ms.date: 11/24/2025
8
8
ms.author: pauloliveria
9
9
ms.service: microsoft-sentinel
10
10
@@ -78,7 +78,7 @@ Use consistent naming, avoid ambiguous terms, and ensure descriptions help AI mo
78
78
For more information on how to use your custom tool collection in your security agents, see the articles for the following AI-powered code editors and agent-building platforms:
Copy file name to clipboardExpand all lines: articles/sentinel/datalake/sentinel-mcp-get-started.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ titleSuffix: Microsoft Security
4
4
description: Learn how to set up and use Microsoft Sentinel's Model Context Protocol (MCP) collection of security tools to enable natural language queries and AI-powered security investigations
5
5
author: poliveria
6
6
ms.topic: get-started
7
-
ms.date: 11/18/2025
7
+
ms.date: 11/24/2025
8
8
ms.author: pauloliveria
9
9
ms.service: microsoft-sentinel
10
10
@@ -32,7 +32,7 @@ You also need the **Security reader** role to list and invoke Sentinel's collect
32
32
For more information on how to add Microsoft Sentinel's collection of MCP tools, see the articles for the following AI-powered code editors and agent-building platforms:
Copy file name to clipboardExpand all lines: articles/sentinel/datalake/sentinel-mcp-use-tool-azure-ai-foundry.md
+22-22Lines changed: 22 additions & 22 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,46 +1,46 @@
1
1
---
2
-
title: Use a Microsoft Sentinel MCP tool in Azure AI Foundry
2
+
title: Use a Microsoft Sentinel MCP tool in Microsoft Foundry
3
3
titleSuffix: Microsoft Security
4
-
description: Learn how to use Microsoft Sentinel's Model Context Protocol (MCP) collection of security tools or your own custom tool in Azure AI Foundry
4
+
description: Learn how to use Microsoft Sentinel's Model Context Protocol (MCP) collection of security tools or your own custom tool in Microsoft Foundry
5
5
author: poliveria
6
6
ms.topic: how-to
7
-
ms.date: 11/18/2025
7
+
ms.date: 11/24/2025
8
8
ms.author: pauloliveria
9
9
ms.service: microsoft-sentinel
10
10
11
-
#customer intent: As a security analyst, I want to add Sentinel MCP tools in Azure AI Foundry.
11
+
#customer intent: As a security analyst, I want to add Sentinel MCP tools in Microsoft Foundry.
12
12
---
13
13
14
-
# Use an MCP tool in Azure AI Foundry (preview)
14
+
# Use an MCP tool in Microsoft Foundry (preview)
15
15
16
16
> [!IMPORTANT]
17
17
> This information relates to a prerelease product that may be substantially modified before it's released. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
18
18
19
-
This article shows you how to add Microsoft Sentinel's Model Context Protocol (MCP) [collection of security tools](sentinel-mcp-tools-overview.md#available-collections) or your own custom tools to your AI agents in [Azure AI Foundry](/azure/ai-foundry/what-is-azure-ai-foundry).
19
+
This article shows you how to add Microsoft Sentinel's Model Context Protocol (MCP) [collection of security tools](sentinel-mcp-tools-overview.md#available-collections) or your own custom tools to your AI agents in [Microsoft Foundry](/azure/ai-foundry/what-is-azure-ai-foundry).
20
20
21
21
For information about how to get started with MCP tools, see the following articles:
22
22
-[Get started with Microsoft Sentinel MCP server](sentinel-mcp-get-started.md)
23
23
-[Create and use custom Microsoft Sentinel MCP tools](sentinel-mcp-create-custom-tool.md)
24
24
25
25
## Add a Microsoft Sentinel tool collection
26
26
27
-
To add a Microsoft Sentinel tool collection in Azure AI Foundry, follow these steps:
27
+
To add a Microsoft Sentinel tool collection in Microsoft Foundry, follow these steps:
28
28
29
-
1. Go to [Azure AI Foundry's agent builder](https://go.microsoft.com/fwlink/?linkid=2340185) then select **Build** > **Agent**.
29
+
1. Go to [Microsoft Foundry's agent builder](https://go.microsoft.com/fwlink/?linkid=2340185) then select **Build** > **Agent**.
30
30
31
-
:::image type="content" source="media/sentinel-mcp/get-started-foundry-build-agent.png" alt-text="Screenshot of Azure AI Foundry agent builder page with the build agent option highlighted." lightbox="media/sentinel-mcp/get-started-foundry-build-agent.png":::
31
+
:::image type="content" source="media/sentinel-mcp/get-started-foundry-build-agent.png" alt-text="Screenshot of Microsoft Foundry agent builder page with the build agent option highlighted." lightbox="media/sentinel-mcp/get-started-foundry-build-agent.png":::
32
32
33
33
1. Enter a name for your agent.
34
34
35
-
:::image type="content" source="media/sentinel-mcp/get-started-foundry-create-agent.png" alt-text="Screenshot of the Create new agent pop-up window in Azure AI Foundry agent builder page." lightbox="media/sentinel-mcp/get-started-foundry-create-agent.png":::
35
+
:::image type="content" source="media/sentinel-mcp/get-started-foundry-create-agent.png" alt-text="Screenshot of the Create new agent pop-up window in Microsoft Foundry agent builder page." lightbox="media/sentinel-mcp/get-started-foundry-create-agent.png":::
36
36
37
37
1. On the **Tools** panel, select **Add a new tool** to ground your agent instructions with relevant security data from Microsoft Sentinel.
38
38
39
-
:::image type="content" source="media/sentinel-mcp/get-started-foundry-add-tool.png" alt-text="Screenshot of an agent's page in Azure AI Foundry with add tool option highlighted." lightbox="media/sentinel-mcp/get-started-foundry-add-tool.png":::
39
+
:::image type="content" source="media/sentinel-mcp/get-started-foundry-add-tool.png" alt-text="Screenshot of an agent's page in Microsoft Foundry with add tool option highlighted." lightbox="media/sentinel-mcp/get-started-foundry-add-tool.png":::
40
40
41
41
1. On the **Select a tool** pop-up window, search for `Sentinel` and choose any [available collection](sentinel-mcp-tools-overview.md) (for example, `Microsoft Sentinel – Data exploration`).
42
42
43
-
:::image type="content" source="media/sentinel-mcp/get-started-foundry-select-tool.png" alt-text="Screenshot of the Select a tool pop-up window in Azure AI Foundry agent builder page with a Sentinel tool collection highlighted." lightbox="media/sentinel-mcp/get-started-foundry-select-tool.png":::
43
+
:::image type="content" source="media/sentinel-mcp/get-started-foundry-select-tool.png" alt-text="Screenshot of the Select a tool pop-up window in Microsoft Foundry agent builder page with a Sentinel tool collection highlighted." lightbox="media/sentinel-mcp/get-started-foundry-select-tool.png":::
44
44
45
45
46
46
1. Select **Connect**.
@@ -50,7 +50,7 @@ Your agent is now connected with Sentinel's available collection of tools. You c
50
50
51
51
## Add a custom tool collection
52
52
53
-
Custom tools let you build deterministic workflows by prescribing exactly what data agents can reason over. To add your custom tool collection in Azure AI Foundry, follow these steps:
53
+
Custom tools let you build deterministic workflows by prescribing exactly what data agents can reason over. To add your custom tool collection in Microsoft Foundry, follow these steps:
54
54
55
55
### Step 1: Register an app in Azure portal
56
56
1. Open your tenant's [Azure portal](https://portal.azure.com) then go to **App registrations** > **New registration**.
@@ -93,15 +93,15 @@ Custom tools let you build deterministic workflows by prescribing exactly what d
93
93
94
94
### Step 2: Add your custom MCP tool
95
95
96
-
1. Go to Azure AI Foundry and select an existing agent or a newly created agent.
96
+
1. Go to Microsoft Foundry and select an existing agent or a newly created agent.
97
97
98
98
1. On the agent's page, go to the **Tools** section then select **Add** > **+ Add a new tool**.
99
99
100
-
:::image type="content" source="media/sentinel-mcp/custom-foundry-add-tool.png" alt-text="Screenshot of an agent's page in Azure AI Foundry with Add a new tool highlighted." lightbox="media/sentinel-mcp/custom-foundry-add-tool.png":::
100
+
:::image type="content" source="media/sentinel-mcp/custom-foundry-add-tool.png" alt-text="Screenshot of an agent's page in Microsoft Foundry with Add a new tool highlighted." lightbox="media/sentinel-mcp/custom-foundry-add-tool.png":::
101
101
102
102
1. On the pop-up window that appears, select **Custom** > **Model Context Protocol (MCP)** then select **Create**.
103
103
104
-
:::image type="content" source="media/sentinel-mcp/custom-foundry-mcp.png" alt-text="Screenshot of the add tool setup in Azure AI Foundry." lightbox="media/sentinel-mcp/custom-foundry-mcp.png":::
104
+
:::image type="content" source="media/sentinel-mcp/custom-foundry-mcp.png" alt-text="Screenshot of the add tool setup in Microsoft Foundry." lightbox="media/sentinel-mcp/custom-foundry-mcp.png":::
105
105
106
106
1. Add the following values:
107
107
-**Name:** Enter a friendly name for your tool
@@ -122,13 +122,13 @@ Custom tools let you build deterministic workflows by prescribing exactly what d
122
122
4500ebfb-89b6-4b14-a480-7f749797bfcd/.default
123
123
```
124
124
125
-
:::image type="content" source="media/sentinel-mcp/custom-foundry-mcp-details.png" alt-text="Screenshot of the MCP details in add tool setup in Azure AI Foundry." lightbox="media/sentinel-mcp/custom-foundry-mcp-details.png":::
125
+
:::image type="content" source="media/sentinel-mcp/custom-foundry-mcp-details.png" alt-text="Screenshot of the MCP details in add tool setup in Microsoft Foundry." lightbox="media/sentinel-mcp/custom-foundry-mcp-details.png":::
126
126
127
127
1. Select **Connect**. Your tool is created successfully and a redirect URL is generated. Copy and save this URL.
128
128
129
-
:::image type="content" source="media/sentinel-mcp/custom-foundry-redirect.png" alt-text="Screenshot of the credential provider or redirect URL details in add tool setup in Azure AI Foundry." lightbox="media/sentinel-mcp/custom-foundry-redirect.png":::
129
+
:::image type="content" source="media/sentinel-mcp/custom-foundry-redirect.png" alt-text="Screenshot of the credential provider or redirect URL details in add tool setup in Microsoft Foundry." lightbox="media/sentinel-mcp/custom-foundry-redirect.png":::
130
130
131
-
### Step 3: Authenticate Azure AI Foundry to use your custom tool
131
+
### Step 3: Authenticate Microsoft Foundry to use your custom tool
132
132
133
133
1. Go back to your tenant's Azure portal and into the app you just added then select **Add a redirect URI**.
134
134
@@ -139,15 +139,15 @@ Custom tools let you build deterministic workflows by prescribing exactly what d
139
139
140
140
1. In the **Redirect URIs** text box, add the redirect URL you copied then select **Configure**.
141
141
142
-
1. Go back to Azure AI Foundry and use a prompt that matches the tool you created. On your first attempt, select **Open consent** to give consent to your signed in user account.
142
+
1. Go back to Microsoft Foundry and use a prompt that matches the tool you created. On your first attempt, select **Open consent** to give consent to your signed in user account.
143
143
144
-
:::image type="content" source="media/sentinel-mcp/custom-foundry-open-consent.png" alt-text="Screenshot of chat details in Azure AI Foundry with Open consent window highlighted." lightbox="media/sentinel-mcp/custom-foundry-open-consent.png":::
144
+
:::image type="content" source="media/sentinel-mcp/custom-foundry-open-consent.png" alt-text="Screenshot of chat details in Microsoft Foundry with Open consent window highlighted." lightbox="media/sentinel-mcp/custom-foundry-open-consent.png":::
145
145
146
146
1. On the pop-up window that appears, select **Allow access**.
147
147
148
148
Once you give consent, your agent can reason over data returned by your custom MCP tool.
149
149
150
-
:::image type="content" source="media/sentinel-mcp/custom-foundry-prompt-result.png" alt-text="Screenshot of chat details in Azure AI Foundry that uses a custom tool." lightbox="media/sentinel-mcp/custom-foundry-prompt-result.png":::
150
+
:::image type="content" source="media/sentinel-mcp/custom-foundry-prompt-result.png" alt-text="Screenshot of chat details in Microsoft Foundry that uses a custom tool." lightbox="media/sentinel-mcp/custom-foundry-prompt-result.png":::
151
151
152
152
## Related content
153
153
- [Tool collection in Microsoft Sentinel MCP server](sentinel-mcp-tools-overview.md)
0 commit comments