Courseiva

AZ-500 Secure identity and access Practice Question

Your organization has Microsoft Entra ID and uses Microsoft Copilot for Microsoft 365. You need to ensure that Copilot interactions are logged and accessible for security investigations. What should you configure?

⚠ Common exam trap

It's easy for candidates to assume Copilot logs are collected via Azure Monitor or Microsoft Sentinel connectors by default, when in reality Copilot auditing is a Microsoft Purview feature that must be explicitly enabled and is not automatically routed to Azure monitoring tools.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure that auditing is enabled in Microsoft Purview to capture Copilot interactions

Microsoft Copilot for Microsoft 365 interactions are audited through the Microsoft Purview audit log. Enabling auditing in Purview captures detailed records of Copilot prompts and responses, which are then accessible for security investigations via the Purview compliance portal or through the Office 365 Management Activity API. This is the designated mechanism for logging Copilot activity, as Copilot interactions are considered Microsoft 365 workload events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Microsoft Sentinel to collect Copilot logs via the Office 365 connector

    Why it's wrong here

    The Microsoft Sentinel Office 365 connector ingests the standard Microsoft 365 audit log, but Copilot interaction records are not exposed as a dedicated log type through that connector. These events are generated exclusively in Microsoft Purview's unified audit log, which requires Purview auditing to be enabled first. Deploying Sentinel without first enabling Purview auditing would yield no Copilot data, so this action alone cannot meet the audit requirement.

  • ✗

    Enable diagnostic settings in Azure Monitor to collect Copilot logs

    Why it's wrong here

    Azure Monitor diagnostic settings are designed to route resource logs and metrics for Azure infrastructure services, such as virtual machines, App Services, or Azure SQL, to a Log Analytics workspace or archive. Microsoft 365 Copilot is a SaaS offering that does not emit resource-specific logs into Azure Monitor, so there is no 'Copilot' log category to enable in diagnostic settings. Configuring diagnostic settings would have no effect on capturing Copilot interactions; the only valid source for these logs is the Microsoft Purview audit log.

  • ✓

    Ensure that auditing is enabled in Microsoft Purview to capture Copilot interactions

    Why this is correct

    Microsoft Purview's unified audit log is the authoritative repository for compliance-related events across Microsoft 365, including Copilot user prompts and responses. When Purview auditing is enabled at the tenant level, the audit engine records Copilot interaction metadata such as the user, timestamp, and action performed, making these records searchable in the Purview compliance portal. This audit trail can also be exported through the Office 365 Management Activity API or integrated with Microsoft Sentinel after the logs have been collected by Purview, but the core requirement is enabling Purview auditing itself.

  • ✗

    Deploy Microsoft Defender for Cloud Apps to monitor Copilot usage

    Why it's wrong here

    Microsoft Defender for Cloud Apps (now part of Microsoft Defender XDR) is a cloud access security broker that focuses on app discovery, conditional access policies, session control, and data-loss prevention for third-party cloud applications. It does not ingest Microsoft 365 Copilot interaction logs because Copilot events are scoped to Microsoft Purview's auditing framework and are not accessible via Defender for Cloud Apps' API connectors. Deploying Defender for Cloud Apps without enabling Purview auditing would fail to capture any Copilot usage, making it an ineffective substitute for the correct compliance control.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.