Microsoft Sentinel is a cloud-native SIEM and SOAR platform that collects, analyzes, and responds to security data across an organization using AI and automation.
Required Permissions
The Log Analytics Reader role is required to enable full API access to the Log Analytics Workspace.
Scytale follows the least-privilege principle, limiting permission scopes strictly to what's required for audit evidence collection.
How to Connect
In Scytale, go to 'Integrations'.
Search for Microsoft Sentinel and select 'Connect'.
Paste your tenant ID, client ID, client secret & workspace ID.
Add a connection name — this will be used to differentiate between your connections — and then select 'Connect'.
You have now successfully connected to Microsoft Sentinel.
How to Generate Credentials in Microsoft Sentinel
Step 1 — Register an app in Azure
(reuse existing from Defender if already done)
Go to portal.azure.com.
Search for Microsoft Entra ID → App registrations.
Click New registration, give it a name (e.g.
scytale-integration), and click Register.Copy the Application (client) ID and Directory (tenant) ID.
Step 2 — Create a client secret
(reuse existing from Defender if already done)
In your app, go to Certificates & secrets → New client secret.
Set an expiry and click Add.
Copy the secret value immediately — you won't be able to see it again.
Step 3 — Grant API Permission for Log Analytics
In your app, go to API Permissions → Add a permission.
Select APIs my organization uses → search for "Log Analytics".
Add the
Data.Readpermission.Click Grant admin consent.
Step 4 — Create a Log Analytics Workspace
Go to Log Analytics Workspaces → + Create.
Fill in: Subscription, Resource Group, Name, Region.
Click Review + Create → Create.
Step 5 — Attach Microsoft Sentinel to the Workspace
Step 6 — Connect Data Connectors
In Microsoft Sentinel → Data Connectors.
Enable relevant connectors (e.g. Microsoft Defender for Cloud, Azure Activity).
Step 7 — Assign the Log Analytics Reader role on the Workspace
Go to Log Analytics Workspaces → select your workspace.
Click Access Control (IAM) → Add role assignment.
Select role: Log Analytics Reader (*).
Assign it to your registered app.
Step 8 — Find your Workspace ID
Step 9 — Enter your credentials in Scytale
Provide the following values:
Tenant ID — from Step 1
Client ID — from Step 1
Client Secret — from Step 2
Workspace ID — from Step 8












