Microsoft has announced significant enhancements to its Sentinel Security Information and Event Management (SIEM) platform, introducing agentic AI capabilities designed to improve threat detection, investigation, and response. At the annual Microsoft Secure virtual event, the company previewed the new Sentinel security graph and the Model Context Protocol (MCP) server, both of which are intended to transform Sentinel from a traditional SIEM into a comprehensive security operations and management platform. The agentic AI functionality will empower Security Copilot agents to conduct more precise and rapid investigations, enabling security teams to respond to threats with greater speed and accuracy. The Sentinel MCP server is a key component, allowing for the integration of both pre-defined and custom agents, which can leverage AI-powered reasoning across unified security data. This extensibility is expected to help organizations move from reactive to predictive security postures, automating threat anticipation and response at scale. Microsoft’s approach aligns with broader industry trends, as competitors like Cisco, CrowdStrike, and Palo Alto Networks also expand their SIEM offerings into full-featured security operations platforms. The new features build upon the July launch of Microsoft Sentinel Data Lake, which provides scalable storage for log files and security data, further enhancing the platform’s analytical capabilities. The integration of agentic AI is positioned as a solution to the growing challenge of overwhelmed security teams, offering automation and intelligence to streamline operations. Microsoft’s security leadership, including corporate VP Vasu Jakkal, has emphasized the importance of these advancements in shifting the security paradigm. The company is also promoting educational resources and sessions, such as those highlighted in the Microsoft Ignite sessions catalog, to help organizations understand and secure agentic AI implementations. These sessions are designed to guide security professionals through the new capabilities and best practices for leveraging AI in security operations. The overall strategy reflects Microsoft’s commitment to providing a unified, extensible, and intelligent security platform for enterprise customers. By integrating agentic AI and expanding the Sentinel ecosystem, Microsoft aims to address both current and emerging cyber threats more effectively. The enhancements are expected to facilitate better collaboration between human analysts and AI agents, improving incident response times and reducing manual workloads. Organizations adopting these new features will benefit from increased automation, deeper insights, and a more proactive security posture. The announcement underscores the rapid evolution of security operations platforms and the central role of AI in modern cybersecurity defense.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Dark Reading reported that Microsoft had added agentic AI capabilities to Microsoft Sentinel, indicating a product development or announcement around AI-driven security operations features. The reference does not provide a more specific event date than the article publication date.
Microsoft published a security blog post outlining its Microsoft Ignite sessions catalog focused on securing agentic AI. The post indicates Microsoft was formally presenting guidance and related session content on this topic.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.