Microsoft Sentinel
Developer and API

Connect your TIP with the upload API (Preview)

In brief

The article now identifies the upload API as a preview API, clarifies STIX-supported uploads and prerequisites, renames the configuration section, and updates related links and permission wording.

What Defender admins need to know

Administrators can more easily find configuration steps and understand the documented integration scope. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Many organizations use threat intelligence platform (TIP) solutions to aggregate threat intelligence feeds from various sources. From the aggregated feed, the data is curated to apply to security solutions such as network devices, EDR/XDR solutions, or security information and event management (SIEM) solutions such as Microsoft Sentinel. The industry standard for describing cyberthreat information is called, "Structured Threat Information Expression" or STIX. By using the upload API which supports STIX objects, you use a more expressive way to import threat intelligence into Microsoft Sentinel.

The upload API ingests threat intelligence into Microsoft Sentinel without the need for a data connector. This article describes what you need to connect.connect a TIP or custom solution to Microsoft Sentinel. For more information on the API details, see the reference document Microsoft Sentinel upload API.

:::image type="content" source="media/connect-threat-intelligence-upload-api/threat-intel-upload-api.png" alt-text="Screenshot that shows the threat intelligence import path.":::

  • You must be able to register a Microsoft Entra application.
  • Your Microsoft Entra application must be granted the Microsoft Sentinel Contributor role at the workspace level.

InstructionsSteps to configure the upload API connection

Follow these steps to import STIX objects from your TIP or custom solution into Microsoft Sentinel:

Register a Microsoft Entra application

The default user role permissions allow users to create application registrations. If this settingthe application registration permission was switched to No, you need permission to manage applications in Microsoft Entra. Any of the following Microsoft Entra roles include the required permissions:

  • Application administrator
  • Application developer

Related content

In this article, you learned how to connect your TIP to Microsoft Sentinel. To learnFor more about using threat intelligence in Microsoft Sentinel,information, see the followingthese articles: