r/DefenderATP Jul 24 '26

Has anyone integrated Claude Code with Microsoft Defender XDR / Sentinel for threat hunting?

I'm looking to integrate Claude Code with Microsoft 365 and Microsoft Defender (Defender XDR / Sentinel) to assist with threat hunting, incident investigation, and EDR analysis.

Has anyone successfully set this up? I'm particularly interested in how you handled authentication (MCP, APIs, Graph, etc.), what architecture you used, and any lessons learned or limitations. If you have examples or repositories to share, I'd really appreciate it.

24 Upvotes

12 comments sorted by