SC-200 Manage a security operations environment Practice Question
Your organization has deployed Microsoft Sentinel. You need to ensure that user and entity behavior analytics (UEBA) is enabled for all data sources. What is the minimum role required to enable UEBA in Microsoft Sentinel?
⚠ Common exam trap
It's easy for candidates to assume a higher-privilege role like Global Administrator is needed for any security configuration, but Microsoft Sentinel has its own granular RBAC roles, and the exam tests knowledge of these specific permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel Contributor
To enable UEBA in Microsoft Sentinel, you need the Microsoft Sentinel Contributor role because it includes the necessary permissions to manage Sentinel settings, including turning on UEBA for all data sources. This role allows you to access the UEBA configuration blade and modify the analytics settings, which is the minimum privilege required for this task.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Sentinel Contributor
Why this is correct
The Microsoft Sentinel Contributor role is the minimal built-in Azure RBAC role that provides full access to Sentinel resources, including the ability to enable UEBA. It grants write permissions to Sentinel settings, such as turning on User and Entity Behavior Analytics from the Settings blade. This role is scoped to the Sentinel workspace or resource group, ensuring least-privilege access for security operators. Because it specifically targets Sentinel's control plane, no additional tenant-level permissions are needed.
- ✗
Global Administrator
Why it's wrong here
Global Administrator is an Microsoft Entra ID tenant-level role that grants broad access to all management functions, including user and subscription administration. However, Microsoft Sentinel uses Azure RBAC, not Microsoft Entra ID roles, for its control plane; the Global Admin role does not natively include Sentinel-specific permissions to enable UEBA. While a Global Admin could assign themselves Sentinel Contributor, doing so is unnecessary and violates the principle of least privilege. The correct approach is to assign the granular Sentinel Contributor role directly to the users who need to configure features like UEBA.
- ✗
Security Reader
Why it's wrong here
Security Reader is an Azure RBAC role that provides read-only access to security-related data and configuration, including Microsoft Sentinel components. It is designed for users who need to view Sentinel incidents, workbooks, and settings but are not allowed to change anything. Enabling UEBA requires a modification to Sentinel settings, which is a write operation that Security Reader cannot perform. Accordingly, this role cannot be used to turn on UEBA.
- ✗
Log Analytics Contributor
Why it's wrong here
Log Analytics Contributor is an Azure RBAC role that grants full access to Log Analytics workspaces, allowing users to manage workspace data and the Workspace Settings. This role does not, however, extend to Sentinel-specific resources because Sentinel is a separate Azure resource provider with its own RBAC model. Users with Log Analytics Contributor can write to the underlying workspace tables, but they cannot access Sentinel's UI settings or enable UEBA. A dedicated Sentinel role like Microsoft Sentinel Contributor is required.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.