Microsoft Sentinel Threat Intelligence
Uploads STIX 2.0/2.1 threat-intelligence objects to a Microsoft Sentinel workspace via the Threat Intelligence Upload API.
The Sentinel Threat Intelligence Upload API is in Preview upstream. It's a different endpoint from the Microsoft Sentinel log ingestion output — different host, different auth scope, different payload shape (STIX). Use this output for threat intel; use the Sentinel v2 output for logs.
Overview
Records are wrapped into the STIX upload envelope and sent to Sentinel Threat Intelligence.
Supported STIX object types: indicator, attack-pattern, threat-actor, identity, relationship. Records should already be in STIX 2.0/2.1 shape — map upstream inputs (Mandiant, AlienVault OTX, etc.) to STIX with a transform node before this output.
Requirements
- A Microsoft Sentinel–enabled Log Analytics workspace, and its workspace ID (GUID).
- A Microsoft Entra (Azure AD) application registration with a client secret.
- The application must be assigned the Microsoft Sentinel Contributor role at the workspace scope. See Microsoft's prerequisites.
Setup
- In the Azure portal, register an application in Microsoft Entra ID and create a client secret. Note the Tenant ID, Client ID, and Client Secret.
- In your Log Analytics workspace → Access control (IAM) → Add role assignment, assign Microsoft Sentinel Contributor to the application.
- Copy the workspace GUID from the workspace overview page.
Configuration
Settings
| Setting | Type | Required | Description |
|---|---|---|---|
| Workspace ID | string (UUID) | Yes | The Log Analytics workspace ID (GUID) that will store the STIX objects. |
| Source System | string | Yes | Free-form label identifying the source system in Sentinel. Must not be the literal string Microsoft Sentinel — that value is restricted by the API. |
| Tenant ID | string | Yes | The Microsoft Entra tenant (directory) ID. |
| Client ID | string | Yes | The application (client) ID registered in Microsoft Entra. |
Secrets
| Secret | Type | Required | Description |
|---|---|---|---|
| Client Secret | string | Yes | The client secret for the registered Microsoft Entra application. |
Record shape
Each record forwarded to this output must be a valid STIX 2.0/2.1 domain object. For example, an indicator record:
Code
See the STIX 2.1 Indicator spec for required fields and pattern syntax.
Limits
The Sentinel Threat Intelligence Upload API enforces these caps (see throttling limits):
- 100 STIX objects per request — Monad batches to this size automatically.
- 100 requests per minute per user.
- Practical ceiling of roughly 10,000 objects per minute before requests are throttled.
Troubleshooting
source_system "Microsoft Sentinel" is restricted: pick any other label — the literalMicrosoft Sentinelis reserved by the API.- 401 Unauthorized: verify the client secret is current and the app has the Microsoft Sentinel Contributor role at the workspace scope.
- 404 Workspace not found: confirm the workspace ID is the GUID of a Sentinel-enabled Log Analytics workspace.
- Records rejected with per-record errors: the response reports a
recordIndexand validation message per bad record. Successful records in the same batch are already published; fix the offending records upstream (usually a missing STIX required field or malformedpattern). - 429 Rate limit exceeded: reduce upstream throughput; Monad honors the API's retry hint automatically.
- Indicators don't appear in Sentinel: Sentinel's Threat Intelligence blade can take a few minutes to reflect newly uploaded objects.
Related Articles
- Connect your TIP with the upload API
- Import threat intelligence with the upload API
- STIX 2.1 specification