Microsoft Security Agent Toolkit
Verified IntegrationClient Configuration
— Connect Microsoft Security Agent Toolkit to Claude Desktop or Cursor in seconds{
"mcpServers": {
"microsoft-security-agent-toolkit": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-microsoft-security-agent-toolkit"
],
"env": {}
}
}
}~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows).System Overview
Provides the action layer for Microsoft Security AI agents with MCP servers, KQL snippets, Logic Apps templates, and end-to-end demos.
7/23/2026
Open Source
stdio / SSE RPC
Frequently Asked Questions
Architecture and operational details for Microsoft Security Agent Toolkit
It's the action layer for Microsoft Security AI agents, providing access to live tenant data (e.g., from Defender, Sentinel, Entra, Purview), KQL snippets, and SOAR templates to enable agents to perform real Security Operations Center (SOC) work.
Related MCP Servers
Browse all servers →Empower AI assistants to generate and convert documents, manage templates, and automate document workflows efficiently.
Provides a multi-tenant, AI-native Content Delivery Network deployable on Cloudflare, featuring sub-100ms TTFB, AI agent controllability, and comprehensive accessibility.
Deploy a Model Context Protocol server on Cloudflare Workers without requiring authentication.