Skillquality 0.70

azure-sentinel

Expert knowledge for Azure Sentinel development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when configuring Sentinel connectors, KQL anal

Price
free
Protocol
skill
Verified
no

What it does

Azure Sentinel Skill

This skill provides expert guidance for Azure Sentinel. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.

How to Use This Skill

IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g., L35-L120), use read_file with the specified lines. For categories with file links (e.g., [security.md](security.md)), use read_file on the linked reference file

IMPORTANT for Agent: If metadata.generated_at is more than 3 months old, suggest the user pull the latest version from the repository. If mcp_microsoftdocs tools are not available, suggest the user install it: Installation Guide

This skill requires network access to fetch documentation content:

  • Preferred: Use mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.
  • Fallback: Use fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.

Category Index

CategoryLinesDescription
TroubleshootingL37-L48Diagnosing and fixing Microsoft Sentinel ingestion, connector, KQL/data lake, analytics rule (auto-disable), MCP tools, and SAP/AWS/Blob/CEF/Syslog integration issues.
Best PracticesL49-L75Best practices for SOC operations in Microsoft Sentinel: rule tuning, automation/playbooks, incident tasks/metrics, watchlists, data collection, solution lifecycle, and monitoring/health.
Decision MakingL76-L112Guides for planning and decision-making: SIEM/SOAR migration to Sentinel, pricing and cost optimization, data tiers and retention, connector and platform choices, and deployment/geo strategy.
Architecture & Design PatternsL113-L126Architecting Sentinel deployments: multi-workspace/tenant patterns, MSSP setups, SOAR automation, BCDR/resiliency, cross-workspace data/incident ops, SAP, ML models, and Jupyter-based hunting.
Limits & QuotasL127-L138Limits, quotas, pricing, and retention tiers for Sentinel data, search jobs, watchlists, MCP servers, ASIM, and workspace removal impacts
SecurityL139-L154Security configuration for Microsoft Sentinel: RBAC and roles, row-level/resource-context access, playbook auth/restrictions, encryption keys, audit logs, SAP roles/params, and network/attack protections.
ConfigurationL155-L283Configuring Microsoft Sentinel and data lake: connectors, ingestion, retention, analytics/automation rules, ASIM schemas, UEBA, SAP, MCP/AI integrations, monitoring, and workspace management.
Integrations & Coding PatternsL284-L335Integrating Microsoft Sentinel with external data, threat intel, MCP/LLM tools, and collaboration apps, plus APIs, codeless connectors, KQL/graph queries, automation, and solution packaging.
DeploymentL336-L359Deploying and managing Microsoft Sentinel solutions and content (CI/CD, ARM, content hub, marketplace) and specialized connectors/agents for SAP, Power Platform, Dynamics, Azure Stack Hub, and hunting notebooks.

Troubleshooting

TopicURL
Troubleshoot Microsoft Sentinel AWS S3 connector problemshttps://learn.microsoft.com/en-us/azure/sentinel/aws-s3-troubleshoot
Troubleshoot Microsoft Sentinel Azure Storage Blob connectorhttps://learn.microsoft.com/en-us/azure/sentinel/azure-storage-blob-connector-troubleshoot
Troubleshoot Sentinel CEF and Syslog AMA ingestion issueshttps://learn.microsoft.com/en-us/azure/sentinel/cef-syslog-ama-troubleshooting
Troubleshoot KQL queries and jobs in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-troubleshoot
Best practices and troubleshooting for Sentinel MCP toolshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/troubleshoot-sentinel-mcp
Troubleshoot Sentinel SAP data connector agenthttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-deploy-troubleshoot
Troubleshoot Sentinel analytics rules and AUTO DISABLEDhttps://learn.microsoft.com/en-us/azure/sentinel/troubleshoot-analytics-rules
Troubleshoot Microsoft Sentinel solution ingestion issueshttps://learn.microsoft.com/en-us/azure/sentinel/troubleshoot-sentinel-solutions

Best Practices

TopicURL
Audit and track Sentinel incident task changeshttps://learn.microsoft.com/en-us/azure/sentinel/audit-track-tasks
Implement Sentinel automation rules for SOAR operationshttps://learn.microsoft.com/en-us/azure/sentinel/automate-incident-handling-with-automation-rules
Automate Sentinel response to compromised users with playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/tutorial-respond-threats-playbook
Apply operational best practices for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/best-practices
Apply data collection best practices in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/best-practices-data
Apply fine-tuning recommendations to Sentinel ruleshttps://learn.microsoft.com/en-us/azure/sentinel/detection-tuning
Use ASIM-based essential domain solutions in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/domain-based-essential-solutions
Reduce false positives in Microsoft Sentinel analyticshttps://learn.microsoft.com/en-us/azure/sentinel/false-positives
Standardize Sentinel incident handling with taskshttps://learn.microsoft.com/en-us/azure/sentinel/incident-tasks
Handle data ingestion delay in Sentinel ruleshttps://learn.microsoft.com/en-us/azure/sentinel/ingestion-delay
Use Sentinel incident metrics to manage SOC performancehttps://learn.microsoft.com/en-us/azure/sentinel/manage-soc-with-incident-metrics
Update SOC and analyst processes for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-security-operations-center-processes
Monitor health and integrity of Microsoft Sentinel analytics ruleshttps://learn.microsoft.com/en-us/azure/sentinel/monitor-analytics-rule-integrity
Monitor and optimize Sentinel scheduled analytics rule executionhttps://learn.microsoft.com/en-us/azure/sentinel/monitor-optimize-analytics-rule-execution
Protect MSSP intellectual property in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/mssp-protect-intellectual-property
Apply operational recommendations for Microsoft Sentinel SOCshttps://learn.microsoft.com/en-us/azure/sentinel/ops-guide
Configure Sentinel SAP detections and threat protectionhttps://learn.microsoft.com/en-us/azure/sentinel/sap/deployment-solution-configuration
Monitor Zero Trust TIC 3.0 with Sentinel solutionhttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solution
Manage lifecycle of deprecated Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solution-deprecation
Apply quality guidelines to Microsoft Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solution-quality-guidance
Use Sentinel watchlists to enrich and correlate eventshttps://learn.microsoft.com/en-us/azure/sentinel/watchlists
Maintain and edit Microsoft Sentinel watchlists safelyhttps://learn.microsoft.com/en-us/azure/sentinel/watchlists-manage
Use Sentinel incident tasks in analyst workflowshttps://learn.microsoft.com/en-us/azure/sentinel/work-with-tasks

Decision Making

TopicURL
Plan and execute migration from MMA to AMA for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/ama-migrate
Decide and migrate Sentinel alert-trigger playbooks to automation ruleshttps://learn.microsoft.com/en-us/azure/sentinel/automation/migrate-playbooks-to-automation-rules
Choose when to use Microsoft Sentinel data lake tierhttps://learn.microsoft.com/en-us/azure/sentinel/basic-logs-use-cases
Plan and estimate Microsoft Sentinel pricing and billinghttps://learn.microsoft.com/en-us/azure/sentinel/billing
Analyze and optimize Microsoft Sentinel cost and billinghttps://learn.microsoft.com/en-us/azure/sentinel/billing-monitor-costs
Use Microsoft Sentinel prepurchase plans to save costshttps://learn.microsoft.com/en-us/azure/sentinel/billing-pre-purchase-plan
Reduce Microsoft Sentinel costs with product featureshttps://learn.microsoft.com/en-us/azure/sentinel/billing-reduce-costs
Choose and configure Sentinel connectors for Cisco ASA/FTDhttps://learn.microsoft.com/en-us/azure/sentinel/cisco-ftd-firewall
Compare Sentinel analytics rules vs Defender custom detectionshttps://learn.microsoft.com/en-us/azure/sentinel/compare-analytics-rules-custom-detections
Assess Sentinel connector data type support by cloudhttps://learn.microsoft.com/en-us/azure/sentinel/data-type-cloud-support
Choose between KQL jobs, summary rules, and search jobshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-jobs-summary-rules-search-jobs
Plan side-by-side deployment with existing SIEMhttps://learn.microsoft.com/en-us/azure/sentinel/deploy-side-by-side
Enroll Sentinel workspaces in simplified pricing tiershttps://learn.microsoft.com/en-us/azure/sentinel/enroll-simplified-pricing-tier
Check Microsoft Sentinel feature availability by Azure cloudhttps://learn.microsoft.com/en-us/azure/sentinel/feature-availability
Plan Sentinel deployment for geography and data residencyhttps://learn.microsoft.com/en-us/azure/sentinel/geographical-availability-data-residency
Choose data tiers and retention for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/manage-data-overview
Use Microsoft Sentinel within the Defender portalhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-sentinel-defender-portal
Plan migration from legacy SIEMs to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration
Migrate ArcSight SOAR automation to Sentinel rules and playbookshttps://learn.microsoft.com/en-us/azure/sentinel/migration-arcsight-automation
Map and migrate ArcSight detection rules to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-arcsight-detection-rules
Export ArcSight historical data for Sentinel migrationhttps://learn.microsoft.com/en-us/azure/sentinel/migration-arcsight-historical-data
Choose an Azure target platform for Sentinel historical datahttps://learn.microsoft.com/en-us/azure/sentinel/migration-ingestion-target-platform
Select a data ingestion tool for Sentinel historical logshttps://learn.microsoft.com/en-us/azure/sentinel/migration-ingestion-tool
Migrate QRadar SOAR automation to Sentinel automation ruleshttps://learn.microsoft.com/en-us/azure/sentinel/migration-qradar-automation
Migrate QRadar detection rules to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-qradar-detection-rules
Export QRadar historical data for Sentinel migrationhttps://learn.microsoft.com/en-us/azure/sentinel/migration-qradar-historical-data
Migrate Splunk SOAR automation to Sentinel automation ruleshttps://learn.microsoft.com/en-us/azure/sentinel/migration-splunk-automation
Migrate Splunk detection rules to Microsoft Sentinel analyticshttps://learn.microsoft.com/en-us/azure/sentinel/migration-splunk-detection-rules
Export Splunk historical data for Sentinel migrationhttps://learn.microsoft.com/en-us/azure/sentinel/migration-splunk-historical-data
Choose between Sentinel standalone and XDR alert connectorshttps://learn.microsoft.com/en-us/azure/sentinel/security-alert-schema-differences
Select Sentinel content hub solutions by domainhttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solutions-catalog
Use Sentinel SIEM migration experience for rule mappinghttps://learn.microsoft.com/en-us/azure/sentinel/siem-migration
Apply SOC optimization recommendations in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/soc-optimization/soc-optimization-access

Architecture & Design Patterns

TopicURL
Design Sentinel SOAR with automation rules and playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/automation
Bring custom machine learning models into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/bring-your-own-ml
Design BCDR and resiliency architecture for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/business-continuity-disaster-recovery
Query and manage Sentinel data across workspaces and tenantshttps://learn.microsoft.com/en-us/azure/sentinel/extend-sentinel-across-workspaces-tenants
Investigate Sentinel incidents using large dataset searchhttps://learn.microsoft.com/en-us/azure/sentinel/investigate-large-datasets
Work with Sentinel incidents across multiple workspaceshttps://learn.microsoft.com/en-us/azure/sentinel/multiple-workspace-view
Use Jupyter notebooks for Sentinel threat huntinghttps://learn.microsoft.com/en-us/azure/sentinel/notebooks
Design Microsoft Sentinel solution components and patternshttps://learn.microsoft.com/en-us/azure/sentinel/partner-integrations
Design multi-workspace architecture for Sentinel SAPhttps://learn.microsoft.com/en-us/azure/sentinel/sap/cross-workspace
Use workspace manager to operate multiple Sentinel workspaceshttps://learn.microsoft.com/en-us/azure/sentinel/workspace-manager

Limits & Quotas

TopicURL
Service limits and quotas for Microsoft Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-service-limits
Sentinel MCP server pricing, limits, and availabilityhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-billing
Select Microsoft Sentinel log retention tiers and limitshttps://learn.microsoft.com/en-us/azure/sentinel/log-plans
Review ASIM known issues and limitations in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-known-issues
Understand removal impact of Microsoft Sentinel workspaceshttps://learn.microsoft.com/en-us/azure/sentinel/offboard-implications
Run Sentinel search jobs for large datasets and archiveshttps://learn.microsoft.com/en-us/azure/sentinel/search-jobs
Review Microsoft Sentinel service limits and quotashttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-service-limits
Create Sentinel watchlists and manage file size limitshttps://learn.microsoft.com/en-us/azure/sentinel/watchlists-create

Security

TopicURL
Audit Microsoft Sentinel queries and user activitieshttps://learn.microsoft.com/en-us/azure/sentinel/audit-sentinel-data
Configure authentication for Microsoft Sentinel playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/authenticate-playbooks-to-sentinel
Define access restriction policies for Sentinel Standard playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/define-playbook-access-restrictions
Enable automated attack disruption actions on AWS identitieshttps://learn.microsoft.com/en-us/azure/sentinel/aws-disruption
Set up customer-managed keys for Microsoft Sentinel encryptionhttps://learn.microsoft.com/en-us/azure/sentinel/customer-managed-keys
Use audit log for Sentinel data lake and graph activitieshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/auditing-lake-activities
Enable network security for Sentinel Azure Storage connectorhttps://learn.microsoft.com/en-us/azure/sentinel/enable-storage-network-security
Configure resource-context RBAC for Microsoft Sentinel data accesshttps://learn.microsoft.com/en-us/azure/sentinel/resource-context-rbac
Configure Microsoft Sentinel roles and permissionshttps://learn.microsoft.com/en-us/azure/sentinel/roles
ABAP roles and authorizations for Sentinel SAP logshttps://learn.microsoft.com/en-us/azure/sentinel/sap/required-abap-authorizations
SAP security parameters monitored by Sentinel analyticshttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-suspicious-configuration-security-parameters
Configure row-level RBAC scoping in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/scoping

Configuration

TopicURL
Add advanced OR condition groups to Sentinel automation ruleshttps://learn.microsoft.com/en-us/azure/sentinel/add-advanced-conditions-to-automation-rules
Use Microsoft Sentinel audit tables for monitoringhttps://learn.microsoft.com/en-us/azure/sentinel/audit-table-reference
Configure Microsoft Sentinel automation rules and conditionshttps://learn.microsoft.com/en-us/azure/sentinel/automation-rule-reference
Security content reference for Power Platform and CEhttps://learn.microsoft.com/en-us/azure/sentinel/business-applications/power-platform-solution-security-content
Map CEF keys to Sentinel CommonSecurityLog fieldshttps://learn.microsoft.com/en-us/azure/sentinel/cef-name-mapping
Configure Syslog and CEF connectors via Azure Monitor Agenthttps://learn.microsoft.com/en-us/azure/sentinel/cef-syslog-ama-overview
Configure Security Events connector for anomalous RDP detectionhttps://learn.microsoft.com/en-us/azure/sentinel/configure-connector-login-detection
Configure interactive and long-term Sentinel data retentionhttps://learn.microsoft.com/en-us/azure/sentinel/configure-data-retention-archive
Configure ingestion-time data transformation and custom log ingestionhttps://learn.microsoft.com/en-us/azure/sentinel/configure-data-transformation
Configure Fusion multistage attack detection ruleshttps://learn.microsoft.com/en-us/azure/sentinel/configure-fusion-rules
Configure AWS service log connector for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-aws
Prepare AWS environment to send logs to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-aws-configure-environment
Configure AWS WAF S3 connector to ingest logs to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-aws-s3-waf
Configure Microsoft Entra ID connector to send logs to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-active-directory
Connect Azure Virtual Desktop telemetry to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-virtual-desktop
Configure Sentinel connections to Azure and Microsoft serviceshttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-windows-microsoft-services
Configure AMA-based syslog and CEF ingestion to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-cef-syslog-ama
Configure Custom Logs via AMA to ingest text-file logshttps://learn.microsoft.com/en-us/azure/sentinel/connect-custom-logs-ama
Connect Microsoft Defender for Cloud alerts to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-defender-for-cloud
Configure AMA connector for Windows DNS log streaminghttps://learn.microsoft.com/en-us/azure/sentinel/connect-dns-ama
Configure GCP Pub/Sub connectors to ingest logs into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-google-cloud-platform
Configure Microsoft Defender XDR connector in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-365-defender
Stream Microsoft Purview Information Protection data to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-purview
Configure API-based data connectors for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-services-api-based
Configure diagnostic settings-based connectors for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-services-diagnostic-setting-based
Configure Windows agent-based data connectors for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-services-windows-based
Create scheduled analytics rules from Sentinel templateshttps://learn.microsoft.com/en-us/azure/sentinel/create-analytics-rule-from-template
Create custom scheduled analytics rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/create-analytics-rules
Configure incident creation from alerts in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/create-incidents-from-alerts
Configure Sentinel automation rules for incident responsehttps://learn.microsoft.com/en-us/azure/sentinel/create-manage-use-automation-rules
Create and manage NRT detection rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/create-nrt-rules
Create Sentinel incident task lists via automation ruleshttps://learn.microsoft.com/en-us/azure/sentinel/create-tasks-automation-rule
Customize Sentinel alert names, severity, and tacticshttps://learn.microsoft.com/en-us/azure/sentinel/customize-alert-details
Customize activities on Sentinel entity timelineshttps://learn.microsoft.com/en-us/azure/sentinel/customize-entity-activities
Configure CCF JSON for Azure Storage Blob connectorhttps://learn.microsoft.com/en-us/azure/sentinel/data-connection-rules-reference-azure-storage
Configure RestApiPoller connector JSON for Sentinel CCFhttps://learn.microsoft.com/en-us/azure/sentinel/data-connector-connection-rules-reference
Reference Sentinel-supported data source schemashttps://learn.microsoft.com/en-us/azure/sentinel/data-source-schema-reference
Use asset data tables in Microsoft Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/asset-data-tables
Configure federated data connectors in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/data-federation-setup
Configure and schedule KQL jobs in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-jobs
Configure and schedule KQL jobs in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-jobs
Manage Microsoft Sentinel data lake KQL jobshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-manage-jobs
Run and manage KQL queries in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-queries
Create and schedule Sentinel Spark notebook jobshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/notebook-jobs
Configure connectors and retention for Sentinel data lake tiershttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-connectors
Onboard Sentinel data lake from Defender portalhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-onboard-defender
Onboard tenants to Microsoft Sentinel data lake and graphhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-onboarding
Use Sentinel MCP data exploration toolshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-data-exploration-tool
Configure and use the Microsoft Sentinel MCP serverhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-get-started
Use Sentinel MCP tools with Microsoft Foundry AI agentshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-azure-ai-foundry
Configure Sentinel MCP tools in Microsoft Copilot Studiohttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-copilot-studio
Add Sentinel MCP tools to Microsoft Security Copilothttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-security-copilot
Build Sentinel workbooks using data lake as sourcehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/workbooks-for-data-lake
Configure DNS over AMA connector fields and schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/dns-ama-fields
Security content reference for Dynamics 365 F&Ohttps://learn.microsoft.com/en-us/azure/sentinel/dynamics-365/dynamics-365-finance-operations-security-content
Enable and configure Sentinel UEBA data sourceshttps://learn.microsoft.com/en-us/azure/sentinel/enable-entity-behavior-analytics
Enable Sentinel auditing and health monitoring and query logshttps://learn.microsoft.com/en-us/azure/sentinel/enable-monitoring
Use Sentinel entity types and identifiers correctlyhttps://learn.microsoft.com/en-us/azure/sentinel/entities-reference
Configure auditing and health monitoring in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/health-audit
Query and interpret Microsoft Sentinel health tableshttps://learn.microsoft.com/en-us/azure/sentinel/health-table-reference
Bulk import threat indicators from files into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/indicators-bulk-file-import
Manage Sentinel analytics rule template versionshttps://learn.microsoft.com/en-us/azure/sentinel/manage-analytics-rule-templates
Configure and manage installed Microsoft Sentinel platform solutionshttps://learn.microsoft.com/en-us/azure/sentinel/manage-platform-solutions
Configure table retention and tier settings for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/manage-table-tiers-retention
Map analytics rule fields to Sentinel entitieshttps://learn.microsoft.com/en-us/azure/sentinel/map-data-fields-to-entities
Use Purview Information Protection connector record types in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-purview-record-types-activities
Monitor Sentinel automation rules and playbook healthhttps://learn.microsoft.com/en-us/azure/sentinel/monitor-automation-health
Monitor Microsoft Sentinel data connector health and ingestionhttps://learn.microsoft.com/en-us/azure/sentinel/monitor-data-connector-health
Monitor SAP–Sentinel connection health and alertshttps://learn.microsoft.com/en-us/azure/sentinel/monitor-sap-system-health
Configure multi-tenant management for Microsoft Sentinel MSSPshttps://learn.microsoft.com/en-us/azure/sentinel/multiple-tenants-service-providers
Configure near-real-time analytics rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/near-real-time-rules
Manage workspace-deployed ASIM parsers in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-about-workspace-parsers
Apply ASIM common schema fields in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-common-fields
Develop and deploy custom ASIM parsers for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-develop-parsers
Implement ASIM Application Entity schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-entity-application
Implement ASIM Device Entity schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-entity-device
Implement ASIM User Entity schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-entity-user
Manage and customize ASIM parsers in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-manage-parsers
Convert Sentinel content to use ASIM normalized datahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-modify-content
Use ASIM Alert Events normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-alert
Use ASIM Audit Events normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-audit
Use ASIM Authentication normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-authentication
Use ASIM DHCP normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-dhcp
Use ASIM DNS normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-dns
Use ASIM File Event normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-file-event
Use ASIM Network Session normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-network
Use ASIM Process Event normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-process-event
Use ASIM Registry Event normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-registry-event
Use Sentinel user management normalization schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-user-management
Use legacy Sentinel network normalization schema v0.1https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-v1
Use ASIM Web Session normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-web
Configure Sentinel notebooks and MSTICPy basicshttps://learn.microsoft.com/en-us/azure/sentinel/notebook-get-started
Apply advanced MSTICPy and notebook settings in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/notebooks-msticpy-advanced
Remove Microsoft Sentinel from a Log Analytics workspacehttps://learn.microsoft.com/en-us/azure/sentinel/offboard
Integrate Microsoft Purview solution with Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/purview-solution
Restore archived Sentinel logs for high-performance querieshttps://learn.microsoft.com/en-us/azure/sentinel/restore
Configure SAP HANA audit log collection in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/collect-sap-hana-audit-logs
Prepare SAP systems for Sentinel SAP connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/preparing-sap
Review prerequisites for Sentinel SAP solution deploymenthttps://learn.microsoft.com/en-us/azure/sentinel/sap/prerequisites-for-deploying-sap-continuous-threat-monitoring
Kickstart script parameters for SAP connector deploymenthttps://learn.microsoft.com/en-us/azure/sentinel/sap/reference-kickstart
Legacy systemconfig.ini settings for Sentinel SAP agenthttps://learn.microsoft.com/en-us/azure/sentinel/sap/reference-systemconfig
systemconfig.json settings for Sentinel SAP agenthttps://learn.microsoft.com/en-us/azure/sentinel/sap/reference-systemconfig-json
Update script parameters for Sentinel SAP connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/reference-update
Use SAP Security Audit Controls workbook in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-audit-controls-workbook
Use SAP Security Audit log workbook in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-audit-log-workbook
Security content reference for Sentinel SAP BTP solutionhttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-btp-security-content
Function reference for Sentinel SAP solution workspacehttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-function-reference
Log and table schema reference for Sentinel SAP solutionhttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-log-reference
Reference for Sentinel SAP security content and ruleshttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-security-content
Stop SAP log collection and disable Sentinel connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/stop-collection
Configure scheduled analytics rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/scheduled-rules-overview
Use Microsoft Sentinel security alert schemahttps://learn.microsoft.com/en-us/azure/sentinel/security-alert-schema
Map Sentinel tables to their data connectorshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-tables-connectors-reference
Use customizable anomaly detection in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/soc-ml-anomalies
Prepare prerequisites for Microsoft Sentinel SIEM solutionshttps://learn.microsoft.com/en-us/azure/sentinel/solution-setup-essentials
Configure and use summary rules to aggregate Sentinel datahttps://learn.microsoft.com/en-us/azure/sentinel/summary-rules
Surface custom event details in Sentinel alertshttps://learn.microsoft.com/en-us/azure/sentinel/surface-custom-details-in-alerts
Configure threat intelligence integrations in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/threat-intelligence-integration
Configure filter and split transformations in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/transformation-filter-split
Reference for Sentinel UEBA entity enrichmentshttps://learn.microsoft.com/en-us/azure/sentinel/ueba-reference
Configure unified connectors to integrate with Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/unified-connector-integration
Apply built-in Sentinel watchlist template schemashttps://learn.microsoft.com/en-us/azure/sentinel/watchlist-schemas
Select Windows security event sets for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/windows-security-event-id-reference
Create and tune anomaly analytics rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/work-with-anomaly-rules
Configure multiple Microsoft Sentinel workspaces in Defender portalhttps://learn.microsoft.com/en-us/azure/sentinel/workspaces-defender-portal

Integrations & Coding Patterns

TopicURL
Create Sentinel Data Collection Rules via API exampleshttps://learn.microsoft.com/en-us/azure/sentinel/api-dcr-reference
Use Sentinel Logic Apps triggers and actions in playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/playbook-triggers-actions
Integrate Sentinel incidents with Microsoft Teams collaborationhttps://learn.microsoft.com/en-us/azure/sentinel/collaborate-in-microsoft-teams
Build Azure Functions-based connectors to ingest data into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-functions-template
Use Logstash with DCR-based API to stream logs to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-logstash-data-connection-rules
Enable Defender Threat Intelligence data connector in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-mdti-data-connector
Connect STIX/TAXII threat intel feeds to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-taxii
Connect threat intelligence platform to Sentinel (legacy connector)https://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-tip
Connect TIP to Sentinel using Threat Intel upload APIhttps://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-upload-api
Create codeless connectors for Microsoft Sentinel with CCFhttps://learn.microsoft.com/en-us/azure/sentinel/create-codeless-connector
Build push-based codeless connectors for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/create-push-codeless-connector
Configure GCP data connectors with Sentinel CCFhttps://learn.microsoft.com/en-us/azure/sentinel/data-connection-rules-reference-gcp
Define connector UIConfig JSON for Sentinel CCFhttps://learn.microsoft.com/en-us/azure/sentinel/data-connector-ui-definitions-reference
Build and manage custom security graphs with Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/create-custom-graphs
Use GQL syntax to query Sentinel custom graphshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/gql-reference-for-sentinel-custom-graph
Call Sentinel custom graph REST APIs programmaticallyhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/graph-rest-api
Run Sentinel data lake KQL queries via REST APIshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-queries-api
Notebook code examples for querying Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/notebook-examples
Use Jupyter notebooks with Sentinel data lake in VS Codehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/notebooks
Use Sentinel graph provider API in Spark notebookshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-graph-provider-reference
Leverage Sentinel MCP agent creation tool collectionhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-agent-creation-tool
Enable and use Microsoft Sentinel MCP connector with ChatGPT or Claudehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-chatgpt-claude-connector
Create custom Sentinel MCP tools from KQL querieshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-create-custom-tool
Integrate Sentinel MCP tools into Azure Logic Appshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-logic-apps
Use Sentinel MCP triage tools for incident huntinghttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-triage-tool
Use SentinelProvider class to access Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-provider-class-reference
Enrich Sentinel entities with geolocation REST APIhttps://learn.microsoft.com/en-us/azure/sentinel/geolocation-data-api
Manage Microsoft Sentinel hunting queries via REST APIhttps://learn.microsoft.com/en-us/azure/sentinel/hunting-with-rest-api
Author custom hunting KQL queries in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/hunts-custom-queries
Ingest Defender for Cloud incidents via Defender XDRhttps://learn.microsoft.com/en-us/azure/sentinel/ingest-defender-for-cloud-incidents
Integrate Microsoft Defender XDR with Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-365-defender-sentinel-integration
Use ASIM helper functions for normalized data in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-functions
Build Power BI reports from Sentinel log datahttps://learn.microsoft.com/en-us/azure/sentinel/powerbi
Trigger Sentinel playbooks from entities during huntshttps://learn.microsoft.com/en-us/azure/sentinel/respond-threats-during-investigation
Create analytics rules for Microsoft Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-analytic-rules-creation
Create hunting queries for Microsoft Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-hunting-rules-creation
Build and publish Microsoft Sentinel SIEM solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-integration-guide
Create and publish playbooks for Microsoft Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-playbook-creation
Create summary rules and tables for Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-summary-rules-creation
Create and publish workbooks for Microsoft Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-workbook-creation
Configure Azure Storage Blob connector for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/setup-azure-storage-connector
Call Microsoft Sentinel SOC optimization recommendations APIhttps://learn.microsoft.com/en-us/azure/sentinel/soc-optimization/soc-optimization-api
Import threat intelligence using Sentinel STIX upload APIhttps://learn.microsoft.com/en-us/azure/sentinel/stix-objects-api
Enrich Sentinel incidents with IP reputation automationhttps://learn.microsoft.com/en-us/azure/sentinel/tutorial-enrich-ip-information
Extract non-native Sentinel entities using playbook actionshttps://learn.microsoft.com/en-us/azure/sentinel/tutorial-extract-incident-entities
Use legacy Sentinel upload indicators APIhttps://learn.microsoft.com/en-us/azure/sentinel/upload-indicators-api
Use Sentinel watchlists in KQL queries and ruleshttps://learn.microsoft.com/en-us/azure/sentinel/watchlists-queries
Query STIX indicator and object tables in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/work-with-stix-objects-indicators

Deployment

TopicURL
Deploy Sentinel solution for Power Platform and CEhttps://learn.microsoft.com/en-us/azure/sentinel/business-applications/deploy-power-platform-solution
Create repository connections to deploy Sentinel contenthttps://learn.microsoft.com/en-us/azure/sentinel/ci-cd
Use repositories and CI/CD for Microsoft Sentinel contenthttps://learn.microsoft.com/en-us/azure/sentinel/ci-cd-custom-content
Customize CI/CD repository deployments for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/ci-cd-custom-deploy
Onboard Azure Stack Hub VMs to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-stack
Deploy Sentinel solution for Dynamics 365 Finance and Operationshttps://learn.microsoft.com/en-us/azure/sentinel/dynamics-365/deploy-dynamics-365-finance-operations-solution
Import and export Sentinel analytics rules via ARMhttps://learn.microsoft.com/en-us/azure/sentinel/import-export-analytics-rules
Manage Sentinel automation rules as code with ARM templateshttps://learn.microsoft.com/en-us/azure/sentinel/import-export-automation-rules
Check Sentinel Defender XDR data support by cloudhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-365-defender-cloud-support
Run Sentinel hunting notebooks in Azure ML workspaceshttps://learn.microsoft.com/en-us/azure/sentinel/notebooks-hunt
Package and publish Microsoft Sentinel platform solutionshttps://learn.microsoft.com/en-us/azure/sentinel/package-platform-solution
Publish Microsoft Sentinel SIEM solutions to marketplacehttps://learn.microsoft.com/en-us/azure/sentinel/publish-sentinel-solutions
Deploy SAP connector container via command linehttps://learn.microsoft.com/en-us/azure/sentinel/sap/deploy-command-line
Deploy SAP data connector container to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/deploy-data-connector-agent-container
Deploy Sentinel solution for SAP BTP systemshttps://learn.microsoft.com/en-us/azure/sentinel/sap/deploy-sap-btp-solution
Install Microsoft Sentinel solution for SAP applicationshttps://learn.microsoft.com/en-us/azure/sentinel/sap/deploy-sap-security-content
Migrate Sentinel SAP container agent to agentless connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-agent-migrate
Expert deployment options for Sentinel SAP connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-deploy-alternate
Update Sentinel SAP data connector agent safelyhttps://learn.microsoft.com/en-us/azure/sentinel/sap/update-sap-data-connector
Discover and deploy Sentinel content hub solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solutions-deploy
Track Microsoft Sentinel solution status after publishinghttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solutions-post-publish-tracking

Capabilities

skillsource-microsoftdocsskill-azure-sentineltopic-agenttopic-agent-skillstopic-agentic-skillstopic-agentskilltopic-ai-agentstopic-ai-codingtopic-azuretopic-azure-functionstopic-azure-kubernetes-servicetopic-azure-openaitopic-azure-sql-databasetopic-azure-storage

Install

Installnpx skills add MicrosoftDocs/Agent-Skills
Transportskills-sh
Protocolskill

Quality

0.70/ 1.00

deterministic score 0.70 from registry signals: · indexed on github topic:agent-skills · 497 github stars · SKILL.md body (43,943 chars)

Provenance

Indexed fromgithub
Enriched2026-04-22 00:53:37Z · deterministic:skill-github:v1 · v1
First seen2026-04-18
Last seen2026-04-22

Agent access