{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-agen-for-work/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["Notification","LightboxImage"]},"type":"markdown"},"seo":{"title":"Microsoft Sentinel integration","siteUrl":"https://developers.frontegg.com/","llmstxt":{"title":"Frontegg Developer Documentation","description":"Authentication, authorization, and user management for Customer Identity, plus Agen for SaaS and Agen for Work. Guides, SDKs, and API references.","sections":[{"title":"Customer Identity (CIAM)","description":"Auth, SSO, SCIM, entitlements, and user management — guides, SDKs, and APIs.","includeFiles":["ciam/**/*.md"],"excludeFiles":[]},{"title":"Agen for SaaS","description":"Agentic access and authorization for SaaS products.","includeFiles":["agen-for-saas/**/*.md"],"excludeFiles":[]},{"title":"Agen for Work","description":"Agentic access and authorization for internal and workforce use.","includeFiles":["agen-for-work/**/*.md"],"excludeFiles":[]},{"title":"Platform","description":"Shared platform overview.","includeFiles":["platform/**/*.md"],"excludeFiles":[]}],"excludeFiles":["internal-docs/**","ciam/guides/env-settings/inject-client-ip.md","CLAUDE.md",".claude/**","**/images/**"],"hide":false}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"microsoft-sentinel-integration","__idx":0},"children":["Microsoft Sentinel integration"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Integrating Microsoft Sentinel with Frontegg allows your application to work with your cloud-native SIEM through the Azure Resource Manager ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Microsoft.SecurityInsights"]}," API — listing and updating incidents, managing alert and automation rules, bookmarks, watchlists, data connectors, and threat intelligence indicators on your behalf."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Microsoft Sentinel does not use an interactive OAuth redirect. Instead, Frontegg authenticates as a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Microsoft Entra ID service principal"]}," using the client-credentials grant. You register an application in Entra ID, create a client secret, grant that application access to your Sentinel workspace, and provide the workspace coordinates (subscription, resource group, and workspace name)."]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Notification","attributes":{"title":"Prerequisites","type":"attention"},"children":[{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A Microsoft account with access to the ",{"$$mdtype":"Tag","name":"a","attributes":{"href":"https://portal.azure.com/"},"children":["Azure portal"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A Log Analytics workspace onboarded to Microsoft Sentinel"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Permission to register applications in Microsoft Entra ID and to assign Azure RBAC roles on the workspace"]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"register-a-service-principal-in-microsoft-entra-id","__idx":1},"children":["Register a service principal in Microsoft Entra ID"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"step-1-open-app-registrations","__idx":2},"children":["Step 1: Open App registrations"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Sign in to the ",{"$$mdtype":"Tag","name":"a","attributes":{"href":"https://portal.azure.com/"},"children":["Azure portal"]}," and open ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["App registrations"]}," (search for it in the top bar, or go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Microsoft Entra ID → App registrations"]},"). Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["New registration"]},"."]},{"$$mdtype":"Tag","name":"LightboxImage","attributes":{"isLightbox":true},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/microsoft-sentinel-1.f5775648e5cf5912d2d9c0053c9f992f48e4666840266a1dc382e91b650565e5.1ce25488.png","alt":"Azure App registrations page"},"children":[]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"step-2-register-the-application","__idx":3},"children":["Step 2: Register the application"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Fill in the registration form:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter a name for your application (for example, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Frontegg Integration"]},")."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Supported account types"]},", keep ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Accounts in this organizational directory only (Single tenant)"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Leave ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Redirect URI"]}," empty — Sentinel uses the client-credentials flow, so no redirect URI is required."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Register"]},"."]}]},{"$$mdtype":"Tag","name":"LightboxImage","attributes":{"isLightbox":true},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/microsoft-sentinel-2.2b330f5d146dba1d6ea1a580241dcb2528918c1aa911984484d571c1d365f421.1ce25488.png","alt":"Register an application form"},"children":[]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"step-3-copy-the-application-client-id-and-directory-tenant-id","__idx":4},"children":["Step 3: Copy the Application (client) ID and Directory (tenant) ID"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["After registration, you land on the application ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Overview"]}," page. Copy the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Application (client) ID"]}," and the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Directory (tenant) ID"]}," — you will need both when configuring the Frontegg portal."]},{"$$mdtype":"Tag","name":"LightboxImage","attributes":{"isLightbox":true},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/microsoft-sentinel-3.913cd924ddf31fbef43409652a83423f678b66f850cebbcfa7966b24abe3658c.1ce25488.png","alt":"Application overview with client ID and tenant ID"},"children":[]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"step-4-open-certificates--secrets","__idx":5},"children":["Step 4: Open Certificates & secrets"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the left sidebar, under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Manage"]},", click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Certificates & secrets"]},". On the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client secrets"]}," tab, click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["New client secret"]},"."]},{"$$mdtype":"Tag","name":"LightboxImage","attributes":{"isLightbox":true},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/microsoft-sentinel-4.00eb8a9989d24af2ea3049f68c0d750c55d846b90769d06ca10d201efd5f1e01.1ce25488.png","alt":"Certificates and secrets page"},"children":[]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"step-5-add-a-client-secret","__idx":6},"children":["Step 5: Add a client secret"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add a client secret"]}," panel, enter a description (for example, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Frontegg Integration"]},"), choose an expiry period, and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add"]},"."]},{"$$mdtype":"Tag","name":"Notification","attributes":{"title":"Save your Client Secret now","type":"attention"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Copy the secret ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Value"]}," immediately after it is created — it is shown only once. After you leave the page you can no longer retrieve it, only the Secret ID."]}]},{"$$mdtype":"Tag","name":"LightboxImage","attributes":{"isLightbox":true},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/microsoft-sentinel-5.dd9ba49b0bcd8a75ca037837b5786ec146fbf876f35fc524bc6616c12991ebac.1ce25488.png","alt":"Add a client secret panel"},"children":[]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"connect-the-sentinel-workspace","__idx":7},"children":["Connect the Sentinel workspace"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"step-6-note-your-subscription-resource-group-and-workspace","__idx":8},"children":["Step 6: Note your subscription, resource group, and workspace"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Open your Log Analytics workspace (search for it, or go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Log Analytics workspaces"]}," and select the one onboarded to Sentinel). On the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Overview"]}," page, note the following values from the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Essentials"]}," panel:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Value"},"children":["Value"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Example"},"children":["Example"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Subscription ID"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Resource group"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["my-sentinel-rg"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Workspace Name"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["my-sentinel-workspace"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"LightboxImage","attributes":{"isLightbox":true},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/microsoft-sentinel-6.f520c310c080e13ed21425f05fb0be08499c4e99129360d64a9d0e0cf8a4f1b6.1ce25488.png","alt":"Log Analytics workspace overview essentials"},"children":[]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"step-7-grant-the-application-access-to-the-workspace","__idx":9},"children":["Step 7: Grant the application access to the workspace"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the same workspace, open ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Access control (IAM)"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add role assignment"]},". On the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Role"]}," tab, search for and select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Microsoft Sentinel Contributor"]}," (use ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Microsoft Sentinel Reader"]}," if you only need read access). Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Next"]},", assign it to the application you registered in Step 1, and complete the assignment."]},{"$$mdtype":"Tag","name":"LightboxImage","attributes":{"isLightbox":true},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/microsoft-sentinel-7.54c7a2eef818e2049ea6ede1b5ffd2f437f657b08545315e6934856eb180e3e4.1ce25488.png","alt":"Add role assignment with Microsoft Sentinel Contributor selected"},"children":[]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"configure-the-frontegg-portal","__idx":10},"children":["Configure the Frontegg portal"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Once you have your ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client ID"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client Secret"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Directory (tenant) ID"]},", and the workspace coordinates, configure the integration in the Frontegg portal:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Open the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Frontegg portal"]}," and navigate to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["[ENVIRONMENT]"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Integrations"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Microsoft Sentinel"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client ID"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client Secret"]}," in the corresponding fields."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Directory (tenant) ID"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Azure subscription ID"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Resource group"]},", and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Log Analytics workspace"]}," name."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]},"."]}]},{"$$mdtype":"Tag","name":"Notification","attributes":{"title":"Keep your credentials secure","type":"attention"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Never share or commit your Client Secret to version control."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"additional-resources","__idx":11},"children":["Additional resources"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"a","attributes":{"href":"https://learn.microsoft.com/en-us/rest/api/securityinsights/"},"children":["Microsoft Sentinel REST API reference"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"a","attributes":{"href":"https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-client-creds-grant-flow"},"children":["Microsoft identity platform and the OAuth 2.0 client credentials flow"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"a","attributes":{"href":"https://portal.azure.com/"},"children":["Azure portal"]}]}]}]},"headings":[{"value":"Microsoft Sentinel integration","id":"microsoft-sentinel-integration","depth":2},{"value":"Register a service principal in Microsoft Entra ID","id":"register-a-service-principal-in-microsoft-entra-id","depth":3},{"value":"Step 1: Open App registrations","id":"step-1-open-app-registrations","depth":4},{"value":"Step 2: Register the application","id":"step-2-register-the-application","depth":4},{"value":"Step 3: Copy the Application (client) ID and Directory (tenant) ID","id":"step-3-copy-the-application-client-id-and-directory-tenant-id","depth":4},{"value":"Step 4: Open Certificates & secrets","id":"step-4-open-certificates--secrets","depth":4},{"value":"Step 5: Add a client secret","id":"step-5-add-a-client-secret","depth":4},{"value":"Connect the Sentinel workspace","id":"connect-the-sentinel-workspace","depth":3},{"value":"Step 6: Note your subscription, resource group, and workspace","id":"step-6-note-your-subscription-resource-group-and-workspace","depth":4},{"value":"Step 7: Grant the application access to the workspace","id":"step-7-grant-the-application-access-to-the-workspace","depth":4},{"value":"Configure the Frontegg portal","id":"configure-the-frontegg-portal","depth":3},{"value":"Additional resources","id":"additional-resources","depth":3}],"frontmatter":{"category":"Monitoring","displayName":"Microsoft Sentinel","seo":{"title":"Microsoft Sentinel integration"}},"lastModified":"2026-07-21T14:46:50.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/agen-for-work/connectors/marketplace/microsoft-sentinel","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}