AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
A company uses Microsoft Defender for Cloud to manage the security posture of multiple Azure subscriptions. The security team wants to ensure that all subscriptions are covered by the same Microsoft Defender for Cloud policy initiative, but one subscription is not showing compliance data. The subscription is in the same Microsoft Entra ID tenant and has the same tags. What is the most likely cause?
⚠ Common exam trap
It's easy for candidates to assume missing compliance data is due to permissions (Security Admin) or missing policy assignments, but the root cause is frequently the unregistered Microsoft.Security resource provider, which is a prerequisite that many overlook.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The subscription is not registered with the Microsoft.Security resource provider.
Microsoft Defender for Cloud relies on the Microsoft.Security resource provider to collect security configurations, apply policy initiatives, and report compliance data. If a subscription is not registered with the Microsoft.Security resource provider, Defender for Cloud cannot evaluate policies or generate compliance results, even if the subscription is in the same tenant and has identical tags. Registering the resource provider is a prerequisite for any Defender for Cloud functionality, including policy assignment and compliance reporting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user does not have Security Admin permissions on the subscription.
Why it's wrong here
Security Admin RBAC permissions control a user's ability to manage security policies, dismiss alerts, or apply recommendations in Microsoft Defender for Cloud. They do not affect the underlying data collection process: Defender for Cloud's assessment engine scans the subscription's resources regardless of which user is viewing the console. If the subscription were properly onboarded, a user with inadequate permissions would see a permission error or restricted visibility, not a complete absence of compliance data. Therefore, missing permissions explain a user's inability to see certain controls, but they do not explain why the subscription or workload shows no compliance data at all.
- ✗
The subscription does not have any tags applied.
Why it's wrong here
Azure tags are logical metadata used for organising resources, cost management, or grouping by environment; they play no role in whether Defender for Cloud can collect security configuration data. The compliance scanning process reads resource properties such as network settings, storage encryption, and OS configuration, none of which depend on tag assignments. Even a subscription with zero tags will still have its resources assessed against the default Azure Security Benchmark initiative. Consequently, an absence of tags cannot cause missing compliance findings or prevent the Microsoft.Security resource provider from functioning.
- ✗
The subscription does not have the default policy initiative assigned.
Why it's wrong here
The default policy initiative in Defender for Cloud is automatically assigned to every subscription when it is first onboarded, so a subscription without it would indicate a deeper onboarding failure rather than a configurable exclusion. Even if a user manually disables individual policy assignments, the compliance dashboard still shows the initiative's state and available recommendations. The key point is that the automatic assignment happens after the Microsoft.Security resource provider is registered, making an unregistered provider the root cause for a total absence of compliance data. Thus, 'no default initiative assigned' is a symptom, not a cause, of the issue described in the question.
- ✓
The subscription is not registered with the Microsoft.Security resource provider.
Why this is correct
For Defender for Cloud to assess a subscription, the Microsoft.Security resource provider must be registered at the subscription level, as this registration is what allows the service to query Azure Resource Manager for resource metadata and configuration. When the provider is unregistered, Defender for Cloud cannot perform any resource discovery, so no security recommendations, regulatory compliance controls, or secure score data are generated for that subscription. Registration is typically performed automatically when a user first opens Defender for Cloud in the portal, but it can also be done programmatically via Azure CLI (`az provider register --namespace Microsoft.Security`) or PowerShell. An unregistered provider explains both the absence of data and why the user perceives that security posture is completely missing.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.