Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Microsoft Sentinel integration

Threat Intelligence Security Center for Microsoft Sentinel offers several capabilities, including importing observables from TISC to Sentinel, enriching Sentinel incidents with details of related observables, and also allow exporting observables from Sentinel to TISC.

Note: On Microsoft Sentinel, observables are referred as entities.

Prerequisites

Dependencies

The Threat Intelligence solution from Microsoft Sentinel Content Hub must be installed.

ApplicationRoles and PermissionsDescription
Microsoft Sentinel-specific roles1. Logic App Contributor 2. Microsoft Sentinel Contributor1. To install the required playbooks on a Resource Group level. 2. Interact with Microsoft Sentinel playbooks. For more information, see Roles and Permissions in Microsoft Sentinel.
Threat Intelligence Security Centersn\_sec\_tisc.api\_azure\_sentinel\_solutionUser configured in the TISC Custom Connector should have this role to allow access to TISC APIs.
  • TISC playbook templates
    This section describes the playbook templates that are shipped with TISC Sentinel solution.

Parent Topic:TISC Security Tools integrations