Microsoft Graph Security

Connect your AI agents to Microsoft Graph Security.

Authentication: OAuth. See Magic Link for the runtime auth flow, or Application credentials to bring your own OAuth app.

Sample use cases

  • List high-severity alerts from the last 24 hours and group them by incident
  • Run an advanced hunting query for sign-ins from a suspicious IP address
  • Report the current Secure Score and the controls with the largest score impact

Available Tools

list_alerts

List security alerts (alerts_v2), correlated into incidents. Filter by status, classification, determination…

get_alert

Get a single security alert by ID, including its full evidence. Use list_alerts to find valid alert IDs.

update_alert

Update a security alert’s status, classification, determination, assignment, or custom details. Only fields you…

run_hunting_query

Run a KQL advanced hunting query against the Microsoft 365 Defender schema (device, email, identity, cloud app…

list_incidents

List security incidents; groups of correlated alerts from the same attack. Filter by…

get_incident

Get a single security incident by ID. Set expand_alerts=true to include its correlated alerts inline. Use…

update_incident

Update a security incident’s status, classification, determination, severity, name, description, summary, custom…

list_secure_scores

List Microsoft Secure Score snapshots for the tenant over time. Items omit the per-control breakdown…

get_secure_score

Get a single Secure Score snapshot by ID, including its per-control score breakdown. Use list_secure_scores to find…

list_secure_score_control_profiles

List Secure Score control profiles; the security controls behind the tenant’s Secure Score, with current state…

get_secure_score_control_profile

Get a single Secure Score control profile by ID. Use list_secure_score_control_profiles to find valid profile IDs…

update_secure_score_control_profile

Update a Secure Score control profile, typically to mark it Ignored/ThirdParty/Reviewed via control_state_updates…