# Microsoft Sentinel

**Canonical:** https://apis.io/providers/microsoft-sentinel/  
**Website:** https://azure.microsoft.com/en-us/products/microsoft-sentinel/  
**APIs profiled:** 5

Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution. It provides REST APIs for managing incidents, analytics rules, threat intelligence, and automation playbooks.

## Kin Score — 42.2 / 100 (developing)

Scored 2026-08-25 under rubric 0.14.0. Trend: flat (+0.0 from 42.2).

| Facet | Score |
|---|---|
| Discoverability | 74.1 |
| Contract Quality | 47.6 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 50.0 |
| Commercial Clarity | 47.4 |
| Access Clarity | 47.4 |

## Agent readiness — 19.8 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (5)

- **Microsoft Sentinel AlertRules API** — The AlertRules API from Microsoft Sentinel — 2 operation(s) for alertrules.
- **Microsoft Sentinel Bookmarks API** — The Bookmarks API from Microsoft Sentinel — 1 operation(s) for bookmarks.
- **Microsoft Sentinel DataConnectors API** — The DataConnectors API from Microsoft Sentinel — 1 operation(s) for dataconnectors.
- **Microsoft Sentinel Incidents API** — The Incidents API from Microsoft Sentinel — 2 operation(s) for incidents.
- **Microsoft Sentinel ThreatIntelligence API** — The ThreatIntelligence API from Microsoft Sentinel — 1 operation(s) for threatintelligence.

## Agentic access (1)

- **Microsoft Sentinel Agentic Access** — 11 operations · 4 acting

## Security (2)

- **Microsoft Sentinel Authentication** — http · 1 scheme
- **Microsoft Sentinel Domain Security** — TLSv1.3 · HSTS · DMARC

## Plans (1)

- **Microsoft Sentinel Plans Pricing**

## Tags

Microsoft, Security, SIEM, SOAR, Threat Detection

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/microsoft-sentinel/). Scores are computed from the provider's own public artifacts under a published rubric.
