Configure Microsoft Sentinel

Once the Threat Intelligence - TAXII data connector is installed, you need to configure the TAXII server.

About this task

Microsoft Sentinel is a cloud-native security information and event management (SIEM) solution that provides intelligent security analytics. Microsoft Sentinel can interact with Trusted Automated Exchange of Indicator Information (TAXII) servers using the Threat Intelligence - TAXII data connector. For more details on Microsoft TAXII configuration, see the Microsoft documentation.


  1. Open Microsoft Sentinel.
  2. Select the Threat Intelligence - TAXII data connector for Microsoft Sentinel.
  3. In the bottom right section, select Open connector page.
    The connector settings for Microsoft Sentinel show.
  4. Use the /root/ endpoint to add each collection individually for Microsoft Sentinel.
    Make sure that you use the /root/ endpoint instead of the discovery endpoint /taxii/.
  5. To verify that the operation was successful, make sure that you can see a message on the right.
    You can now access the indicators from the Threat Intelligence page.


Microsoft Sentinel has now been configured.