AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You are configuring Microsoft Sentinel to ingest logs from Microsoft Entra ID (now Microsoft Entra ID). You need to collect sign-in logs and audit logs. Which data connector should you enable?
⚠ Common exam trap
It's easy for candidates to confuse the 'Office 365' connector (which handles Exchange, SharePoint, and Teams logs) with Microsoft Entra ID logs, or mistakenly think 'Microsoft Entra ID Authentication' is a valid connector name, when the correct name is 'Microsoft Entra ID' (now Microsoft Entra ID).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID (now Microsoft Entra ID)
The Microsoft Entra ID (now Microsoft Entra ID) data connector is the correct choice because it is specifically designed to ingest both sign-in logs and audit logs from Microsoft Entra ID into Microsoft Sentinel. This connector enables the collection of user sign-in activities and directory audit events, which are essential for security monitoring and incident detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID Protection
Why it's wrong here
Microsoft Entra ID Protection is a separate Sentinel connector that ingests only risk-related events such as risky users, risk detections, and sign-in risk verdicts. It does not provide the comprehensive sign-in or audit log streams necessary for general user activity monitoring, so while useful for threat detection, it cannot serve as the primary source for full Microsoft Entra ID logs.
- ✗
Office 365
Why it's wrong here
The Office 365 connector in Sentinel collects audit logs from Exchange Online, SharePoint Online, Microsoft Teams, and other O365 workloads, but explicitly excludes Microsoft Entra ID sign-in and audit logs. Identity events like user logons and directory changes are not part of its schema; those logs require the Microsoft Entra ID/Entra ID connector, which is why this option is incorrect.
- ✗
Microsoft Entra ID Authentication
Why it's wrong here
There is no 'Microsoft Entra ID Authentication' connector in the Microsoft Sentinel data connectors gallery. Authentication-related data is contained within the Microsoft Entra ID sign-in logs, specifically the 'AuthenticationDetails' and related properties, but it is ingested through the Microsoft Entra ID (Entra ID) connector. Selecting a non-existent connector would not provide any log ingestion.
- ✓
Microsoft Entra ID (now Microsoft Entra ID)
Why this is correct
The Microsoft Entra ID (now Microsoft Entra ID) connector is the correct choice because it directly ingests both SignInLogs and AuditLogs into Sentinel. This enables monitoring of user sign-in attempts, multi-factor authentication challenges, and directory configuration changes, providing the core identity telemetry needed for investigations.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.