Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

You have configured Microsoft Sentinel to ingest logs from Microsoft Entra ID (now Microsoft Entra ID). You notice that sign-in logs for external guest users are not appearing in Sentinel. What is the most likely cause?

⚠ Common exam trap

Many exam-takers assume guest user logs require a special connector or are not logged at all, when in reality the issue is simply a missing or incomplete diagnostic settings configuration in Entra ID.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The diagnostic settings in Microsoft Entra ID are not configured to stream sign-in logs to the Log Analytics workspace used by Sentinel.

Microsoft Sentinel ingests Microsoft Entra ID (Entra ID) logs via diagnostic settings configured on the Entra ID tenant. These settings must explicitly stream sign-in logs (including guest user sign-ins) to a Log Analytics workspace. If the diagnostic settings are missing or misconfigured, no sign-in logs—including those for external guest users—will appear in Sentinel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The diagnostic settings in Microsoft Entra ID are not configured to stream sign-in logs to the Log Analytics workspace used by Sentinel.

    Why this is correct

    The Microsoft Entra ID connector for Microsoft Sentinel relies on diagnostic settings that must be explicitly enabled in Microsoft Entra ID to route sign-in logs to a Log Analytics workspace. If these settings are absent or misconfigured, sign-in log ingestion fails even though the Sentinel connector itself appears connected, which precisely matches the reported symptom. You must verify that the diagnostic setting streams AuditLogs and SignInLogs to the same workspace that Sentinel uses, and that the workspace ID matches the one selected in the connector.

  • ✗

    Microsoft Sentinel does not support ingestion of external guest user sign-in logs.

    Why it's wrong here

    Microsoft Sentinel fully supports ingestion of all Microsoft Entra ID sign-in logs, including those from external guest users, provided the diagnostic settings are configured correctly. Guest user sign-in events are generated within the Entra ID directory and appear alongside internal user events in the SignInLogs table. The connector does not differentiate by user type, and there is no product limitation that would exclude guest users from ingestion, so this statement is factually incorrect.

  • ✗

    The Microsoft Sentinel Entra ID connector requires a separate connector for guest users.

    Why it's wrong here

    The Microsoft Sentinel Entra ID connector is a single data connector that collects both audit logs and sign-in logs for the entire tenant. It does not require separate connectors for different user categories, such as guest users or members, because all sign-in events are emitted to the same Log Analytics tables (SignInLogs and AADNonInteractiveUserSignInLogs) through the configured diagnostic settings. There is no additional connector to deploy or configure for guest users specifically.

  • ✗

    Guest user sign-ins are not logged in Microsoft Entra ID.

    Why it's wrong here

    Microsoft Entra ID does log sign-in activity for guest users, just as it logs sign-ins for internal users. Guest user sign-ins produce entries in the SignInLogs table, but whether those entries reach Sentinel depends on diagnostic settings that stream those logs to the Log Analytics workspace. The diagnostic settings can be configured to include all sign-in logs, regardless of user type, so the absence of guest user sign-in logs in Sentinel points to a configuration issue rather than a lack of logging.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.