Agent skill · Security

azure-sentinel

Expert knowledge for Azure Sentinel development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when configuring data connectors, KQL analytics, playbooks/Logic Apps, UEBA/Fusion, or multi-tenant Sentinel setups, and other Azure Sentinel related development tasks. Not for Azure Defender For Cloud (use azure-defender-for-cloud), Azure Security (use azure-security), Azure Monitor (use azure-monitor), Azure Network Watcher (use azure-network-watcher).

MicrosoftDocsgithub.com/MicrosoftDocsGitHub ↗
claude-codecopilotcodexCC-BY-4.0
Install
npx skills add MicrosoftDocs/Agent-Skills --skill azure-sentinel --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 1
SKILL.md size: 45 KB
Bundled scripts: none
Requires: Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation.
Path: skills/azure-sentinel/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 682 · +8 this week
Read our review of the source →

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

Review
written from the skill's own SKILL.md · Aug 5, 2026

What it does

The skill offers expert guidance for Azure Sentinel development tasks, including troubleshooting, best practices, decision making, architecture and design patterns, limits and quotas, security, configuration, integrations and coding patterns, and deployment. It is intended for tasks such as configuring data connectors, KQL analytics, playbooks/Logic Apps, UEBA/Fusion, or multi-tenant Sentinel setups, and other Azure Sentinel related development tasks.

How it works

The skill uses a category-index approach to locate relevant sections. For categories with line ranges, the agent should read the specified lines via read_file with the given range. For categories with file links, the agent should read_file on the linked file. It fetches documentation via mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage, as a network-enabled operation. If the metadata timestamp is older than 3 months, suggest updating from the repository; if the required tools are unavailable, suggest installing them. The skill requires network access to retrieve documentation content.

When to use it

Use when working on Azure Sentinel development tasks such as configuring data connectors, KQL analytics, playbooks/Logic Apps, UEBA/Fusion, or multi-tenant Sentinel setups.

What it can touch

The skill references external documentation content accessed through tools: mcp_microsoftdocs:microsoft_docs_fetch and fetch_webpage. It relies on network access to retrieve Markdown content and does not specify local file mutations beyond read_file operations for category access.

Caveats

Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation. Metadata timestamp should be checked for freshness; if over 3 months, user should pull latest version from the repository. No further licensing or risk disclosures are provided beyond those in the description.

From the SKILL.md

# Azure Sentinel Skill This skill provides expert guidance for Azure Sentinel. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities. ## How to Use This Skill > **IMPORTANT for Agent**: Use the **Category Index** below to locate relevant sections. For categories with line ranges (e.g., `L35-L120`), use `read_file` with the specified lines. For categories with file links (e.g., `[security.md](security.md)`), use `read_file` on the linked reference file > **IMPORTANT for Agent**: If `metadata.generated_at` is more than 3 months old, suggest the user pull the latest version from the repository. If `mcp_microsoftdocs` tools are not available, suggest the user install it: [Installation Guide](https://github.com/MicrosoftDocs/mcp/blob/main/README.md) This skill requires **network access** to fetch documentation content: - **Preferred**: Use `mcp_microsoftdocs:microsoft_docs_fetch` with query string `from=learn-agent-skill`. Returns Markdown. - **Fallback**: Use `fetch_webpage`

What's inside
Steps it walks through
  1. How to Use This Skill
  2. Category Index
  3. Troubleshooting
  4. Best Practices
  5. Decision Making
  6. Architecture & Design Patterns
  7. Limits & Quotas
  8. Security
  9. Configuration
  10. Integrations & Coding Patterns
  11. Deployment
More from Agent-Skills
All skills →
About this skill
What does the azure-sentinel skill do?

Expert knowledge for Azure Sentinel development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when configuring data connectors, KQL analytics, playbooks/Logic Apps, UEBA/Fusion, or multi-tenant Sentinel setups, and other Azure Sentinel related development tasks. Not for Azure Defender For Cloud (use azure-defender-for-cloud), Azure Security (use azure-security), Azure Monitor (use azure-monitor), Azure Network Watcher (use azure-network-watcher).

How do I install it?

Run `npx skills add MicrosoftDocs/Agent-Skills --skill azure-sentinel --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From MicrosoftDocs/Agent-Skills, a repository with 682 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going