mcpbeat

Microsoft Sentinel Data Exploration MCP Server

com.microsoft/sentinel-data-exploration
answering

Microsoft Sentinel Data Exploration is answering right now. Last checked 14 min ago. Last commit 14 Jan 2026.

Find relevant security data from Sentinel data lake for building effective agents. More:aka.ms/s/de

Uptime history 39 hours of history
39 hours agonow
100.0%
Uptime 24h
91 of 91 checks
Tools
hidden behind auth
342 ms
Response time
average over 24h
2
Stars
last commit 14 Jan 2026

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 14 min ago.

run in your terminal
claude mcp add sentinel-data-exploration --transport http https://sentinel.microsoft.com/mcp/data-exploration
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "sentinel-data-exploration": {
      "url": "https://sentinel.microsoft.com/mcp/data-exploration"
    }
  }
}
~/.codex/config.toml
[mcp_servers.sentinel-data-exploration]
url = "https://sentinel.microsoft.com/mcp/data-exploration"
.cursor/mcp.json
{
  "mcpServers": {
    "sentinel-data-exploration": {
      "url": "https://sentinel.microsoft.com/mcp/data-exploration"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "sentinel-data-exploration": {
      "url": "https://sentinel.microsoft.com/mcp/data-exploration"
    }
  }
}

This endpoint answered with an authorization challenge — the server is running, but you need an API key or OAuth to use it.

Endpoints

URLTransportStateLatencyChecked
https://sentinel.microsoft.com/mcp/data-exploration streamable-http needs key 205 ms 14 min ago

Microsoft Sentinel Data Exploration — questions

Answers built from our own checks of this server.

Why is there no tool list for Microsoft Sentinel Data Exploration?
The server answered our handshake with an authorization challenge, so it is running — but it will not describe its tools to an anonymous client. To see them you need to connect with your own credentials. We record it as alive, not as broken: 100.0% of checks in the last 24 hours got a reply.
Is Microsoft Sentinel Data Exploration working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 342 ms. The bar chart above shows every period we have measured.
How do I connect Microsoft Sentinel Data Exploration?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address. You will need your own key or an OAuth login: it refuses anonymous clients.
Does Microsoft Sentinel Data Exploration need an API key?
Yes. Every time we knock, Microsoft Sentinel Data Exploration answers with an authorization challenge instead of its tool list — that is how we know it is running and gated rather than broken. Bring your own credentials and it will talk.
How fast is Microsoft Sentinel Data Exploration?
It answers our handshake in 342 ms on average, which is faster than 41% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.
Is Microsoft Sentinel Data Exploration open source?
Yes — it is published under the MIT licence and 2 stars on GitHub. The source link is on this page, so you can read exactly what it does with your data before you connect it.