← All integrations






Microsoft Sentinel
IT, security & developer toolsSecurity alerts, incidents, and logs.
You connect Microsoft Sentinel once, with your Microsoft Sentinel sign-in or an API key, and every workflow you build can use it.
Use it in a workflow
Tell the architect, the AI that builds your workflows, what you want done in your own words. For example:
When Microsoft Sentinel raises a high-severity incident, summarize it and alert the IT team.
Access and security
- With a sign-in, you grant access on Microsoft Sentinel's own consent screen, and Malleable stores the resulting token, never your password.
- An API key you enter never appears in chat and is hidden from the AI. A key saved as a reusable connection is stored with your Malleable account and only sent to Microsoft Sentinel.
- Every run uses the connection the workflow's owner set up, so anyone who can run the workflow acts with that account's access in Microsoft Sentinel. Connect an account or key with only the access the workflow needs.
- You can revoke access at any time in Microsoft Sentinel's settings.
Malleable is SOC 2 Type II certified and doesn't train AI models on your data. More in Security & data handling and our Trust Center.
Connection details for IT
Microsoft Sentinel publishes its own MCP server, which workflows connect to at https://sentinel.microsoft.com/mcp/data-exploration. Your Microsoft Sentinel admin may need to turn on API access first.
More in IT, security & developer tools
ServiceNow
Tickets, requests, approvals, and knowledge articles
Okta
Users, groups, and app access
Microsoft Entra ID
Users, groups, devices, and app access
Jamf
Apple devices, apps, and security settings
1Password
Sign-in attempts, item usage, and account activity
JumpCloud
Users, devices, and access across your company