Microsoft Sentinel
Cloud and workloads

Build Azure Logic Apps with Microsoft Sentinel MCP tools

In brief

The page now focuses on using the entity analyzer MCP tool in Azure Logic Apps to enrich entities and automate verdicts. It also clarifies supported authentication options and the Security Reader requirement, and updates page metadata.

What Defender admins need to know

Review the clarified authentication and role requirements when configuring the Logic App.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

For more information about the specific input and output in the Connector, see Microsoft Sentinel MCP.

Authenticate to the connector

Every logic app connector requires an authentication connection. This new action type supports Microsoft Entra ID, service principals, and managed identities. As is the case with the MCP server, theThe logic app's identity requires the Security reader role to operate.

Additional information