Skip to content
MCPCompare

Vendor-published

Microsoft Sentinel Data Exploration MCP server

Find relevant security data from Sentinel data lake for building effective agents. More:aka.ms/s/de

Microsoft Sentinel Data Exploration (`com.microsoft/sentinel-data-exploration`, v1.0.1) is published by the vendor. It exposes a hosted endpoint over streamable-http, and no self-hostable package. It requires authentication and publishes 1 scope — but they do not separate reading from writing, so read-only access cannot be granted. 4 of 4 enterprise control criteria are undocumented. Last checked 2026-09-19.
Add to comparisonVendor documentationSource repository

Identity and maintenance

Publisher and version information
Registry namecom.microsoft/sentinel-data-exploration
Publisher domainmicrosoft.com
Maintainer typeVendor-published

namespace com.microsoft -> microsoft.com; host sentinel.microsoft.com is within microsoft.com

Latest version seen1.0.1
Last checked
Last changed

Separate from “last checked”: we check far more often than anything changes.

Enterprise evaluation

Every row below exists whether or not we found an answer. Expand any row to see the exact source and the date. Unknown means undocumented, never unsupported.

Enterprise evaluation criteria for Microsoft Sentinel Data Exploration
Access and authentication
Authentication required

Whether the hosted endpoint accepted a connection with no credentials when we checked.

Yes
We checked checked
POST initialize without credentials -> HTTP 401
Unauthenticated connection attempthttps://sentinel.microsoft.com/mcp/data-exploration
OAuth 2.1 authorization

Whether the server publishes OAuth discovery metadata a client can follow automatically.

Yes
We checked checked
https://sentinel.microsoft.com/mcp/.well-known/oauth-protected-resource/data-exploration -> 200
Dynamic client registration

Without it, an IdP administrator must register a client by hand before anyone can connect.

Could not reach source
We checked checked
no authorization-server metadata document found
Authorization server metadatahttps://sentinel.microsoft.com/mcp/data-exploration
Documented scopes
Yes
4500ebfb-89b6-4b14-a480-7f749797bfcd/.default
We checked checked
"scopes_supported": ["4500ebfb-89b6-4b14-a480-7f749797bfcd/.default"]
Read and write are separate scopes

A single opaque scope means read-only access cannot be granted: approving access approves everything.

No
We checked checked
scopes_supported is ["4500ebfb-89b6-4b14-a480-7f749797bfcd/.default"] -- no separate read-only scope is offered
Deployment and transport
Streamable HTTP transport
Yes
Registry checked
"type": "streamable-http", "url": "https://sentinel.microsoft.com/mcp/data-exploration"
SSE transport
Vendor-hosted endpoint

Data leaves your network. Where it goes is a question for the vendor's documentation.

Self-hostable package

A published npm, PyPI, container or bundle artifact you can run inside your own perimeter.

Supply chain
Public source repository
Yes
Registry checked
https://github.com/microsoft/sentinel-data-exploration-mcp
Open-source license
Yes
MIT
Vendor checked
Repository actively maintained
No
Vendor checked
last push 248 days ago
Package deprecated
Not checked
Secret inputs marked as secret

Credential-shaped inputs the publisher did not flag as secret may be logged by a client.

Not checked
Documented controls
Audit logging documented
Not documented
Access controls documented
Not documented
Data residency documented
Not documented
Data retention documented
Not documented

What remains unknown

7 of 18 criteria are undocumented. These are the questions to put to the vendor — not conclusions about the product.

Turn these into a vendor questionnaire

How we checked

One unauthenticated initialize request, plus the two OAuth discovery documents. Nothing was installed or executed. The exact request headers are below so you can reproduce the result — endpoint behaviour can depend on them.

POST https://sentinel.microsoft.com/mcp/data-exploration
user-agent: mcpcompare.ai/1.0 (+https://mcpcompare.ai/methodology/probe; probe@mcpcompare.ai)
content-type: application/json
accept: application/json, text/event-stream
mcp-protocol-version: 2025-06-18

-> HTTP 401  (auth-required)
   checked 2026-09-19T17:17:14.108Z

Questions people ask

Does the Microsoft Sentinel Data Exploration MCP server require authentication?
Yes. When we connected to https://sentinel.microsoft.com/mcp/data-exploration without credentials on 2026-09-19, it returned HTTP 401.
Can I grant read-only access to the Microsoft Sentinel Data Exploration MCP server?
No. It publishes ["4500ebfb-89b6-4b14-a480-7f749797bfcd/.default"], which does not separate reading from writing, so granting access grants both.
Can the Microsoft Sentinel Data Exploration MCP server be self-hosted?
Not from the registry record. No installable package is declared, so the vendor-hosted endpoint is the only documented option.