M

Microsoft Security Agent Toolkit

Verified Integration
Author: @vinayaklattheCategory: ServerApplication
JSON-RPC 2.0
Protocol Standard
Sub-second
Execution Latency
Active
Operational Status

Client Configuration

— Connect Microsoft Security Agent Toolkit to Claude Desktop or Cursor in seconds
{
  "mcpServers": {
    "microsoft-security-agent-toolkit": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-microsoft-security-agent-toolkit"
      ],
      "env": {}
    }
  }
}
Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows).
Architecture & Capabilities

System Overview

Provides the action layer for Microsoft Security AI agents with MCP servers, KQL snippets, Logic Apps templates, and end-to-end demos.

Indexed Date

7/23/2026

License

Open Source

Protocol Layer

stdio / SSE RPC

Frequently Asked Questions

Architecture and operational details for Microsoft Security Agent Toolkit

It's the action layer for Microsoft Security AI agents, providing access to live tenant data (e.g., from Defender, Sentinel, Entra, Purview), KQL snippets, and SOAR templates to enable agents to perform real Security Operations Center (SOC) work.

Related MCP Servers

Browse all servers →
C
@carboneio
Carbone

Empower AI assistants to generate and convert documents, manage templates, and automate document workflows efficiently.

ClaudeSearchDatabase+65 FAQs
Learn more
C
@sebastienrousseau
CloudCDN

Provides a multi-tenant, AI-native Content Delivery Network deployable on Cloudflare, featuring sub-100ms TTFB, AI agent controllability, and comprehensive accessibility.

ClaudeSearchDatabase+65 FAQs
Learn more

Deploy a Model Context Protocol server on Cloudflare Workers without requiring authentication.

ClaudeSearchDatabase+55 FAQs
Learn more