Successor to the deprecated platform connector: a TIP or your own app pushes STIX objects straight into Sentinel over REST, with no data connector, signing in as an Entra app that holds Microsoft Sentinel Contributor. The endpoint is per workspace, and the API is still in preview.
Also called threat intelligence upload API.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Upload API in context, with comparison tables and the common traps.
Terms in this definition
- TIP
Gathers threat intel feeds, curates them and hands them on to security tools. Sentinel's dedicated connector for these products only handled indicators; deprecated, it stopped collecting in June 2026, with the upload API as its successor.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- STIX
A standard language for threat intelligence, covering indicators, attack patterns, threat actors and how they relate. Sentinel can take it in by file import, the upload API or TAXII.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- REST
Short for representational state transfer, the style of HTTP API that Azure services expose.
- Data connector
Brings data into the Microsoft Sentinel workspace from Azure resources, Microsoft services or third-party sources; ingestion is its only job, with no detection or response.
- Microsoft Sentinel Contributor
Built-in Azure role that includes everything Responder can do and can also create and modify workbooks, analytics rules and content hub solutions.
- Workspace
Teams in Power BI and Microsoft Fabric collaborate in this folder-style container, which groups items such as reports, semantic models and lakehouses, controls who can access them and is assigned a capacity.
Related terms
- TLP
Labels threat intelligence with how sensitive it is and how far it may be passed on. In the upload API it goes in object_marking_refs; in the portal you just pick it.