انتقل إلى المحتوى الرئيسي

AI related data connectors enabled on Microsoft Sentinel/SIEM workspace

Implementation Effort: Medium – Requires enabling and configuring multiple data connectors in an existing Microsoft Sentinel workspace, validating that AI-relevant log tables are ingesting correctly, and confirming alert flow end-to-end from each source into Sentinel incidents.
User Impact: Low – Infrastructure configuration; end users are not affected.

Overview

A Microsoft Sentinel workspace without the right data connectors provides no visibility into AI threats. The connectors determine which telemetry is available for analytics rules, workbooks, hunting queries, and incident investigation — and for AI security, those sources span identity, cloud posture, data governance, and AI-native signals. Enabling the correct set of AI-related connectors is the prerequisite for every downstream detection and response capability in this pillar.

  • The Microsoft Defender XDR connector is the highest-priority integration. It streams correlated incidents and raw alerts from across the Defender portfolio — endpoint, identity, cloud apps, and AI services — into Sentinel as unified incidents. This is what enables cross-domain attack chain visibility: a phishing campaign leading to identity compromise, followed by agent abuse, surfaces as a single correlated incident rather than isolated alerts across separate consoles.

  • The Microsoft Entra ID and Microsoft Entra ID Protection connectors provide identity telemetry for agent workload identities. Sign-in logs, audit logs, and risk detections for service principals, managed identities, and app registrations are essential for detecting anomalous authentication patterns — unexpected token issuances, unauthorized changes to agent app permissions, or risk events on identities that should exhibit consistent, predictable behavior. Without these connectors, identity-based threats to agent infrastructure generate no signal in Sentinel.

  • Defender for AI Services alerts via Microsoft Defender for Cloud (MDC) delivers platform-level AI threat signals: prompt injection detections, jailbreak attempts, credential harvesting patterns, and data exfiltration indicators from Azure OpenAI and Azure AI Foundry endpoints. This connector is the primary source of AI-native security alerts and must be validated to confirm alerts flow from Defender for Cloud into Sentinel before analytics rules that depend on SecurityAlert are authored.

  • The Microsoft Purview Information Protection connector surfaces data sensitivity events — DLP policy violations and high-sensitivity label activity triggered by AI-generated content — enabling detection of data oversharing through Copilot and agent interfaces. These events are frequently the earliest observable signal of an AI workload accessing or emitting data beyond its intended scope.

  • The Microsoft 365 Copilot connector (via Microsoft Purview Audit) ingests Copilot interaction logs: user prompts, Copilot responses, plugin and connector activity, and grounding data access events. This data is required for investigating Copilot-specific incidents such as prompt injection through document grounding or unintended exposure of sensitive data in Copilot responses.

  • The Agent 365 connector provides agent lifecycle and activity telemetry from the Agent 365 Registry, enabling detection of unauthorized agent deployments, access control modifications, and anomalous runtime behavior across the organization's agent population. Together, these seven connectors establish the complete telemetry surface needed to detect, investigate, and respond to threats across the full AI workload lifecycle — from identity compromise and network interception to data exfiltration and agent runtime abuse.

This supports Assume breach by ensuring that every layer of the AI stack — identity, platform, data, and application — contributes security telemetry to a centralized detection surface. It supports Verify explicitly by enabling continuous correlation of AI workload activity against known-bad patterns and organization-specific behavioral baselines. Without these connectors enabled and validated, analytics rules produce no results, investigations have no evidence, and threat actors targeting AI infrastructure operate without generating a single Sentinel alert.

Reference