Skip to content

Commit e7d7d75

Browse files
authored
Update date and role requirements in article
Updated the date for the article and added role requirements for the entity analyzer tool.
1 parent b859473 commit e7d7d75

1 file changed

Lines changed: 9 additions & 6 deletions

File tree

articles/sentinel/datalake/sentinel-mcp-data-exploration-tool.md

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ titleSuffix: Microsoft Security
44
description: Learn about the different tools available in the Data exploration collection in Microsoft Sentinel
55
author: poliveria
66
ms.topic: how-to
7-
ms.date: 04/08/2026
7+
ms.date: 04/14/2026
88
ms.author: pauloliveria
99
ms.service: microsoft-sentinel
1010
ms.subservice: sentinel-platform
@@ -35,11 +35,6 @@ To access the data exploration tool collection, you need the following prerequis
3535
> - Security Contributor
3636
> - Security Operator
3737
> - Security Reader
38-
>
39-
> To use the entity analyzer tool, you also need the following roles:
40-
> - **Security Copilot Contributor** – This role is required to use the tool, which consumes Security Compute Units (SCUs) to deliver reasoned entity risk analysis.
41-
> - **Security Copilot Owner** (optional) – This role is only required to view and monitor SCU usage.
42-
> For more information, see [Understand authentication in Microsoft Security Copilot](/copilot/security/authentication).
4338
4439
## Add the data exploration collection
4540

@@ -90,6 +85,14 @@ For example, `analyze_user_entity` reasons over the user's authentication patter
9085

9186
Entity analysis tools might require a few minutes to generate results, so there are tools to start analysis for each entity and another one that polls for the analysis results.
9287

88+
> [!IMPORTANT]
89+
> To use the entity analyzer tool, you also need the following roles:
90+
> - **Security Copilot Contributor** – This role is required to use the tool, which consumes Security Compute Units (SCUs) to deliver reasoned entity risk analysis.
91+
> - **Security Copilot Owner** (optional) – This role is only required to view and monitor SCU usage.
92+
>
93+
> For more information, see [Understand authentication in Microsoft Security Copilot](/copilot/security/authentication).
94+
95+
9396
#### Start analysis (`analyze_user_entity` and `analyze_url_entity`)
9497

9598
| Parameters | Required? | Description |

0 commit comments

Comments
 (0)