Microsoft Copilot security directory

Microsoft Sentinel

Published by Microsoft

High risk

Cloud-native SIEM with a built-in AI so you can focus on what matters most

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.

Available capabilities

This add-on exposes 38 tools or capabilities.

  • Add alert to incident
  • Add comment to incident (V2)
  • Add comment to incident (V3)
  • Add comment to incident [DEPRECATED]
  • Add labels to incident (deprecated) [DEPRECATED]
  • Add task to incident
  • Alert - Get incident
  • Alert - Get incident
  • ASI trigger unsubscribe [DEPRECATED]
  • Bookmarks (V2) - Create a new bookmark (json input) (Preview)
  • Bookmarks (V3) - Creates new bookmark with separate fields (Preview)
  • Bookmarks - Creates new bookmark [DEPRECATED]
  • Bookmarks - Delete a bookmark
  • Bookmarks - Get a bookmark
  • Bookmarks - Get all bookmarks
  • Change incident description (V2) (deprecated) [DEPRECATED]
  • Change incident description [DEPRECATED]
  • Change incident severity (deprecated) [DEPRECATED]
  • Change incident status (deprecated) [DEPRECATED]
  • Change incident title (V2) (deprecated) [DEPRECATED]
  • Change incident title [DEPRECATED]
  • Create incident
  • Entities - Get Accounts
  • Entities - Get DNS

The interactive security report will load automatically.