Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel →hardMultiple SelectObjective-mapped
Three Prerequisites to Integrate Microsoft Sentinel with Microsoft Defender XDR
Which THREE are prerequisites for integrating Microsoft Sentinel with Microsoft Defender XDR? (Choose three.)
Quick Answer
The correct answer is a valid license for Microsoft 365 Defender, appropriate permissions, and the data connector enabled in Sentinel. These three prerequisites ensure that Microsoft Sentinel can ingest and correlate security signals from Defender XDR’s unified threat protection suite. Technically, the integration relies on the Microsoft 365 Defender connector within Sentinel, which requires an active license for Defender or its individual workloads (like Defender for Endpoint) to authorize data flow, plus the necessary permissions (typically Security Administrator or Global Reader) to configure the connector, and the connector itself must be toggled on in the Sentinel data connectors blade. On the AZ-500 exam, this question tests your understanding of cloud-native security integration without unnecessary overhead—common traps include assuming a specific Azure region is required (any region works) or that endpoint agents must be installed (Defender XDR collects data automatically). A helpful memory tip: think “License, Permissions, Connector” as the three pillars—no region lock, no agents needed.
⚠ Common exam trap
Test-takers frequently assume the Microsoft Monitoring Agent is required for all Microsoft security integrations, but the Sentinel–Defender XDR connector is API-based and does not use MMA, and they also mistakenly think the workspace must be in the same region as the tenant, which is not enforced by the integration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Appropriate permissions (Security Administrator or Global Administrator)
Integrating Microsoft Sentinel with Microsoft Defender XDR requires the user to have either Security Administrator or Global Administrator roles in Azure Active Directory. These permissions are necessary to grant consent for the data connector and to configure cross-tenant or cross-service access policies that enable Defender XDR to send incident and alert data to Sentinel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Appropriate permissions (Security Administrator or Global Administrator)
Why this is correct
Correct: Required to enable the connector.
- ✓
The Microsoft 365 Defender data connector must be enabled in Sentinel
Why this is correct
Correct: The connector ingests the alerts.
- ✗
The Microsoft Monitoring Agent installed on all endpoints
Why it's wrong here
Incorrect: Not required for Microsoft 365 Defender integration.
- ✓
A valid license for Microsoft 365 Defender (or individual workloads)
Why this is correct
Correct: Licenses are required to generate the alerts.
- ✗
An Azure Sentinel workspace in the same region as the Microsoft 365 tenant
Why it's wrong here
Incorrect: No region requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 194 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-500
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are valid ways to integrate Microsoft Sentinel with Microsoft Defender XDR?
medium- ✓ A.Configure the Microsoft Defender XDR data connector
- B.Use Azure Lighthouse to connect Defender XDR to Sentinel
- C.Deploy a playbook that polls Defender XDR APIs
- ✓ D.Enable automatic incident creation in the Microsoft Defender XDR connector
- E.Create a custom log analytics workspace query
Why A: The Microsoft Defender XDR data connector is the official and supported method to ingest alerts and incidents from Microsoft Defender XDR into Microsoft Sentinel. This connector enables bi-directional synchronization, allowing incidents created in Defender XDR to appear in Sentinel and vice versa, with automatic correlation and enrichment.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.