Vendor-published
Microsoft Sentinel Data Exploration MCP server
Find relevant security data from Sentinel data lake for building effective agents. More:aka.ms/s/de
Identity and maintenance
| Registry name | com.microsoft/sentinel-data-exploration |
|---|---|
| Publisher domain | microsoft.com |
| Maintainer type | Vendor-published namespace com.microsoft -> microsoft.com; host sentinel.microsoft.com is within microsoft.com |
| Latest version seen | 1.0.1 |
| Last checked | |
| Last changed | Separate from “last checked”: we check far more often than anything changes. |
Enterprise evaluation
Every row below exists whether or not we found an answer. Expand any row to see the exact source and the date. Unknown means undocumented, never unsupported.
| Access and authentication | |
|---|---|
| Authentication required Whether the hosted endpoint accepted a connection with no credentials when we checked. | Yes We checked checkedPOST initialize without credentials -> HTTP 401 Unauthenticated connection attempt — https://sentinel.microsoft.com/mcp/data-exploration |
| OAuth 2.1 authorization Whether the server publishes OAuth discovery metadata a client can follow automatically. | Yes We checked checkedhttps://sentinel.microsoft.com/mcp/.well-known/oauth-protected-resource/data-exploration -> 200 OAuth discovery metadata — https://sentinel.microsoft.com/mcp/data-exploration |
| Dynamic client registration Without it, an IdP administrator must register a client by hand before anyone can connect. | Could not reach source We checked checkedno authorization-server metadata document found Authorization server metadata — https://sentinel.microsoft.com/mcp/data-exploration |
| Documented scopes | Yes 4500ebfb-89b6-4b14-a480-7f749797bfcd/.default We checked checked"scopes_supported": ["4500ebfb-89b6-4b14-a480-7f749797bfcd/.default"] Protected Resource Metadata — https://sentinel.microsoft.com/mcp/data-exploration |
| Read and write are separate scopes A single opaque scope means read-only access cannot be granted: approving access approves everything. | No We checked checkedscopes_supported is ["4500ebfb-89b6-4b14-a480-7f749797bfcd/.default"] -- no separate read-only scope is offered Protected Resource Metadata — https://sentinel.microsoft.com/mcp/data-exploration |
| Deployment and transport | |
| Streamable HTTP transport | Yes Registry checked"type": "streamable-http", "url": "https://sentinel.microsoft.com/mcp/data-exploration" |
| SSE transport | No Registry checkedno sse remote declared |
| Vendor-hosted endpoint Data leaves your network. Where it goes is a question for the vendor's documentation. | Yes Registry checked1 remote endpoint(s) declared |
| Self-hostable package A published npm, PyPI, container or bundle artifact you can run inside your own perimeter. | No Registry checkedno installable package declared |
| Supply chain | |
| Public source repository | Yes Registry checkedhttps://github.com/microsoft/sentinel-data-exploration-mcp |
| Open-source license | Yes MIT Vendor checkedlicense: MIT GitHub repository — https://github.com/microsoft/sentinel-data-exploration-mcp |
| Repository actively maintained | No Vendor checkedlast push 248 days ago GitHub repository — https://github.com/microsoft/sentinel-data-exploration-mcp |
| Package deprecated | Not checked |
| Secret inputs marked as secret Credential-shaped inputs the publisher did not flag as secret may be logged by a client. | Not checked |
| Documented controls | |
| Audit logging documented | Not documented |
| Access controls documented | Not documented |
| Data residency documented | Not documented |
| Data retention documented | Not documented |
What remains unknown
7 of 18 criteria are undocumented. These are the questions to put to the vendor — not conclusions about the product.
- Dynamic client registration — no authorization-server metadata document found
- Package deprecated — no source found
- Secret inputs marked as secret — no source found
- Audit logging documented — no source found
- Access controls documented — no source found
- Data residency documented — no source found
- Data retention documented — no source found
How we checked
One unauthenticated initialize request, plus the two OAuth discovery documents. Nothing was installed or executed. The exact request headers are below so you can reproduce the result — endpoint behaviour can depend on them.
POST https://sentinel.microsoft.com/mcp/data-exploration user-agent: mcpcompare.ai/1.0 (+https://mcpcompare.ai/methodology/probe; probe@mcpcompare.ai) content-type: application/json accept: application/json, text/event-stream mcp-protocol-version: 2025-06-18 -> HTTP 401 (auth-required) checked 2026-09-19T17:17:14.108Z
Questions people ask
- Does the Microsoft Sentinel Data Exploration MCP server require authentication?
- Yes. When we connected to https://sentinel.microsoft.com/mcp/data-exploration without credentials on 2026-09-19, it returned HTTP 401.
- Can I grant read-only access to the Microsoft Sentinel Data Exploration MCP server?
- No. It publishes ["4500ebfb-89b6-4b14-a480-7f749797bfcd/.default"], which does not separate reading from writing, so granting access grants both.
- Can the Microsoft Sentinel Data Exploration MCP server be self-hosted?
- Not from the registry record. No installable package is declared, so the vendor-hosted endpoint is the only documented option.