> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Sentinel

This guide walks through how to create a Microsoft Sentinel connection and the permissions it requires to be used in Blink's Automated Case Management, across **Ingestion**, **Enrichment**, and **Response** workflows.

<Note>
  Permission requirements can vary by workflow type. See [Required Permissions](#required-permissions) for the full breakdown by connection option.
</Note>

***

## Creating a Connection

You can authenticate to Microsoft Sentinel in one of two ways. Both are supported across every Microsoft integration in Blink's Automated Case Management, so the connection you choose here can be reused elsewhere.

<Tabs>
  <Tab title="Microsoft Graph">
    Recommended if this connection will be reused across other Microsoft integrations in your Automated Case Management setup.

    ### Creating a Connection

    <Card title="Microsoft Graph Connection Guide" icon="arrow-up-right-from-square" href="https://docs.blinkops.com/docs/integrations/microsoft-graph">
      Follow this guide to create a Microsoft Graph connection
    </Card>

    ### Required Permissions

    <Accordion title="Required Permissions for Microsoft Graph">
      | Permissions |
      | - |
      | AuditLog.Read.All |
      | Calendars.ReadBasic |
      | Calendars.ReadWrite |
      | Calendars.ReadWrite.Shared |
      | Channel.Create |
      | ChannelMember.ReadWrite.All |
      | ChannelMessage.ReadWrite |
      | ChannelMessage.Send |
      | ChannelSettings.ReadWrite.All |
      | Chat.Create |
      | Chat.ReadWrite |
      | Chat.ReadWrite.All |
      | ChatMember.ReadWrite |
      | Device.Command |
      | Device.Read.All |
      | DeviceManagementApps.ReadWrite.All |
      | DeviceManagementManagedDevices.PrivilegedOperations.All |
      | DeviceManagementManagedDevices.ReadWrite.All |
      | Directory.AccessAsUser.All |
      | Directory.ReadWrite.All |
      | eDiscovery.ReadWrite.All |
      | Files.ReadWrite |
      | Files.ReadWrite.All |
      | Group.ReadWrite.All |
      | GroupMember.ReadWrite.All |
      | IdentityRiskyUser.Read.All |
      | IdentityRiskyUser.ReadWrite.All |
      | Mail.Read |
      | Mail.ReadBasic |
      | Mail.ReadWrite |
      | Mail.ReadWrite.Shared |
      | Mail.Send |
      | MailboxSettings.ReadWrite |
      | Notes.ReadWrite.All |
      | offline\_access |
      | OnlineMeetings.ReadWrite |
      | SecurityAlert.Read.All |
      | SecurityAlert.ReadWrite.All |
      | SecurityIncident.ReadWrite.All |
      | Sites.Manage.All |
      | Sites.ReadWrite.All |
      | TeamMember.ReadWrite.All |
      | ThreatHunting.Read.All |
      | User.EnableDisableAccount.All |
      | User.ManageIdentities.All |
      | User.Read |
      | User.ReadWrite.All |
      | User.RevokeSessions.All |
      | DeviceLocalCredential.ReadBasic.All |
      | SecurityCopilotWorkspaces.ReadWrite.All |
    </Accordion>
  </Tab>

  <Tab title="Microsoft Sentinel">
    Recommended if this connection will be used for Sentinel only.

    ### Creating a Connection

    <Card title="Microsoft Sentinel Connection Guide" icon="arrow-up-right-from-square" href="https://docs.blinkops.com/docs/integrations/microsoft-sentinel">
      Follow this guide to create a Microsoft Sentinel connection
    </Card>

    ### Required Permissions

    | Permission |
    | - |
    | `SecurityActions.ReadWrite.All` |
    | `SecurityAlert.ReadWrite.All` |
    | `SecurityAnalyzedMessage.ReadWrite.All` |
    | `SecurityEvents.ReadWrite.All` |
    | `SecurityIncident.ReadWrite.All` |
  </Tab>
</Tabs>

<AccordionGroup>
  <Accordion title="Which stage of Alert Processing need this connection?" icon="table">
    | Source | Requires this connection? | Notes |
    | - | - | - |
    | Ingestion | ✓ Yes | Pulls alerts/incidents into Blink |
    | Enrichment | ✓ Yes | Adds Sentinel context to cases |
    | Response | ✗ No | Not applicable |
  </Accordion>
</AccordionGroup>

***


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.