Courseiva
Manage a security operations environmenthardMultiple ChoiceObjective-mapped

Automated User Suspension Playbook with Sentinel

Your organization has Microsoft Defender for Cloud Apps and Microsoft Sentinel integrated. You need to create an automated playbook that, when a Microsoft Sentinel incident is created from a Defender for Cloud Apps alert, automatically suspends the user in Microsoft Entra ID and sends a notification to the security team. Which two connectors should you use in the playbook?

Quick Answer

The answer is Microsoft Entra ID and Microsoft Teams. This is correct because the automated user suspension playbook with Sentinel requires Microsoft Entra ID to execute the user suspension action directly via its connector, while Microsoft Teams serves as the notification channel to alert the security team of the suspension. On the Microsoft Security Operations Analyst SC-200 exam, this scenario tests your understanding of integrating Microsoft Defender for Cloud Apps alerts with Sentinel playbooks, specifically the need for identity management and communication connectors rather than scripting or third-party tools. A common trap is choosing Azure Automation for suspension, but that is for complex scripts, not direct user disablement. Remember the memory tip: “Suspend with Entra, notify with Teams” — the two core actions in any automated user suspension playbook with Sentinel are identity control and team alerting.

⚠ Common exam trap

A common mix-up: candidates confuse Outlook.com with Office 365 Outlook (Exchange Online) or think Power BI can be used for notifications, but the question specifically requires enterprise-grade identity suspension and team notification, which only Microsoft Entra ID and Microsoft Teams provide as native connectors in a Logic App playbook.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Entra ID and Microsoft Teams

Microsoft Entra ID provides the identity management action to suspend a user account, and Microsoft Teams enables sending a notification to the security team via a Teams channel or chat. This combination directly fulfills the requirements of suspending the user in Entra ID and notifying the team when a Sentinel incident is triggered from a Defender for Cloud Apps alert.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Power BI and Microsoft Teams

    Why it's wrong here

    Incorrect. Power BI cannot suspend users.

  • Microsoft Entra ID and Microsoft Teams

    Why this is correct

    Correct. Entra ID suspends user, Teams sends notification.

  • Azure Automation and Microsoft Sentinel

    Why it's wrong here

    Incorrect. Azure Automation would require custom scripts, not direct actions.

  • Microsoft Entra ID and Outlook.com

    Why it's wrong here

    Incorrect. Outlook.com is not recommended for enterprise notifications.

About these practice questions

This SC-200 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. You discover that a user is performing unusual bulk downloads from SharePoint. You need to automatically create an incident in Sentinel and suspend the user in Microsoft Entra ID. What should you use?

hard
  • A.Create a scheduled analytics rule in Sentinel and use automation rules to trigger a playbook that suspends the user.
  • B.Configure a Microsoft Entra ID Protection policy to require password reset for risky users.
  • C.Use a playbook triggered by an incident creation rule to suspend the user.
  • D.Configure a policy in Defender for Cloud Apps with a governance action to suspend the user.

Why A: A scheduled analytics rule in Sentinel can detect the unusual bulk download behavior from SharePoint (via ingested logs from Defender for Cloud Apps or Office 365 connector). An automation rule on that analytics rule triggers a playbook (Azure Logic App) that uses the Microsoft Graph API to suspend the user in Microsoft Entra ID, creating an incident automatically as part of the rule's configuration.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.