Microsoft Sentinel
Developer and API

Connect Services Api Based

In brief

The article now says table names are listed under each connector in the Data connectors reference and adds a Microsoft Entra ID Protection example. Documentation metadata was also updated.

What Defender admins need to know

No administrator action is required; the clarification may make querying connector data easier.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security engineer, I want to connect various Microsoft services to Microsoft Sentinel using API-based data connectors so that I can centralize and streamline security event monitoring and incident management.

  1. If on the connector page there is a section titled Create incidents - recommended!, select Enable if you want to automatically create incidents from alerts.

You can find and query the data for each service using the table names that appearlisted under each connector's section on the Data connectors reference page. For example, Microsoft Entra ID Protection data appears in the Microsoft Entra ID Protection connector section for the service's connector in the Data connectors reference page.of that reference.

Related content