AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your security team uses Microsoft Sentinel's UEBA (User and Entity Behavior Analytics) to detect insider threats. To enable UEBA, which data source must be connected to Sentinel?
⚠ Common exam trap
It's easy for candidates to assume Office 365 or Azure Activity logs provide sufficient user context for UEBA, but Microsoft explicitly requires the Microsoft Entra ID data connector as the prerequisite identity source.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID data connector
Microsoft Sentinel's UEBA relies on Microsoft Entra ID (now Microsoft Entra ID) as the primary identity source to build behavioral baselines for users and entities. The Entra ID data connector ingests sign-in logs, audit logs, and risk detections, which are essential for UEBA to analyze patterns and detect anomalies indicative of insider threats. Without this identity telemetry, UEBA cannot establish the necessary behavioral profiles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID data connector
Why this is correct
The Microsoft Entra ID data connector is the correct choice because it ingests sign-in logs, audit logs, and user properties that are the foundation of UEBA. UEBA in Microsoft Sentinel relies on identity data to build a behavior baseline for each user, detect anomalous sign-ins, and generate risk-based alerts. Without Entra ID (formerly Azure AD) identity telemetry, UEBA lacks the context needed to correlate user actions with security incidents.
- ✗
Azure Key Vault data connector
Why it's wrong here
The Azure Key Vault data connector captures audit and access logs for key vault operations such as secret retrieval, key rotation, and access policy changes. While these logs are useful for monitoring sensitive resource access, they do not contain user behavioral attributes like sign-in patterns, location, or group memberships. UEBA requires identity-centric data to model baseline behavior; key management events are operational and do not provide the entity-level context needed for user entity analytics.
- ✗
Office 365 data connector
Why it's wrong here
The Office 365 data connector ingests logs from Exchange, SharePoint, Teams, and other M365 workloads, which reflect user collaboration and productivity activity. However, Microsoft Sentinel's UEBA primarily uses Microsoft Entra ID data as the authoritative source for establishing user identity baselines and detecting anomalies. Office 365 data is supplementary and can enrich UEBA, but it is not required, and enabling it alone does not satisfy the core identity data requirement for UEBA.
- ✗
Azure Activity log data connector
Why it's wrong here
The Azure Activity log data connector captures subscription-level administrative events such as resource creation, VM start/stop, and role assignments. These control-plane operations indicate what changed in Azure, but they do not provide the user identity attributes, sign-in history, or behavioral patterns that UEBA consumes. UEBA depends on identity and session data from Microsoft Entra ID, not resource management logs, so this connector is not the appropriate source for user entity behavior analytics.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.