SC-200 Manage a security operations environment Practice Question
Your Microsoft Sentinel workspace has a Microsoft 365 Defender connector configured. You notice that incidents are being created from Microsoft Defender for Office 365 alerts, but not from Microsoft Defender for Identity alerts. What should you check?
⚠ Common exam trap
Test-takers frequently assume a working connector automatically streams all Defender alerts, but Microsoft deliberately tests whether you know that each workload's alert streaming must be individually enabled in the connector configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the Microsoft Defender for Identity alert streaming in the connector configuration.
The Microsoft 365 Defender connector in Microsoft Sentinel requires explicit enablement of alert streaming for each Microsoft Defender service. By default, the connector may stream alerts from Defender for Office 365 but not from Defender for Identity unless the corresponding toggle is turned on in the connector configuration. Option A directly addresses this by instructing you to enable the Defender for Identity alert streaming, which resolves the missing incident creation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable the Microsoft Defender for Identity alert streaming in the connector configuration.
Why this is correct
The Microsoft 365 Defender connector in Microsoft Sentinel has a service-selection pane that allows you to choose which Defender signal sources to ingest, including Microsoft Defender for Identity alerts. If only Office 365 alerts are flowing, the most likely root cause is that the Defender for Identity alert stream was not toggled on in the connector's configuration. After enabling it, save the connector configuration and wait for new alerts to start appearing in the Sentinel workspace.
- ✗
Verify that the Microsoft 365 Defender connector is connected.
Why it's wrong here
Since Office 365 alerts are already being ingested, the Microsoft 365 Defender connector is demonstrably connected and operational. A connectivity failure would prevent all alert streams from flowing simultaneously, not just those from Defender for Identity, so checking the connection status would not resolve the issue. The symptom described points to a selective streaming configuration, not a broken connection.
- ✗
Ensure you have licenses for Microsoft Defender for Identity.
Why it's wrong here
Microsoft Defender for Identity licenses determine whether the service can generate identity alerts at all; if licenses were missing, no identity-related events would exist for the connector to forward. Because the scenario indicates that other alert types are flowing and the issue is specifically about the identity alert stream, the licensing prerequisite is likely already satisfied. Prematurely assuming a licensing problem would lead you away from the actual configuration oversight.
- ✗
Check the incident correlation rules in Microsoft Defender XDR.
Why it's wrong here
Incident correlation rules in Microsoft Defender XDR control how alerts are aggregated into incidents in the Defender portal, and those incidents are then exported to Sentinel via the connector. They do not govern the selective streaming of individual alert types from underlying services such as Defender for Identity. Adjusting correlation rules would affect incident grouping in Defender, not whether identity alerts are streamed into Sentinel, so this action would not correct the missing alert stream.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.