SC-200 Manage a security operations environment Practice Question
Your organization is migrating from Microsoft Entra ID to Microsoft Entra ID. You need to ensure that Microsoft Sentinel continues to receive identity logs. What should you do?
⚠ Common exam trap
Candidates often assume a rebranding or migration requires reconfiguring connectors or creating new ones, when in fact the underlying service and API endpoints remain unchanged, so the existing connector continues to function automatically.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No action is required; the existing connector automatically updates.
The migration from Microsoft Entra ID (Azure AD) to Microsoft Entra ID is a rebranding and consolidation effort that does not change the underlying service endpoints, APIs, or log schemas. The existing Microsoft Entra ID data connector in Microsoft Sentinel continues to collect identity logs (e.g., Sign-in logs, Audit logs, Provisioning logs) without any reconfiguration because the connector is tied to the same underlying directory service. Therefore, no action is required; the existing connector automatically updates to reflect the new name.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install the new Microsoft 365 Defender connector for identity logs.
Why it's wrong here
The Microsoft 365 Defender connector ingests threat alerts and incidents from Microsoft 365 Defender, not raw identity audit logs such as sign-in and audit events. Microsoft Entra ID (now Microsoft Entra ID) audit logs are collected by the Microsoft Entra ID connector via Microsoft Graph API. Installing this connector would bring in unrelated security alert data and fail to satisfy the requirement for identity audit log collection during the migration.
- ✓
No action is required; the existing connector automatically updates.
Why this is correct
No action is required because the Microsoft Entra ID connector (formerly Azure AD) uses the same underlying Microsoft Graph API endpoints; the rebranding does not change the data schema or the retrieval method. The connector automatically inherits the updated display name and continues sending audit and sign-in logs to the same Log Analytics workspace. Recreating or reinstalling it would introduce unnecessary disruption and potential data gaps.
- ✗
Reconfigure the diagnostic settings to send logs to a new Log Analytics workspace.
Why it's wrong here
Reconfiguring diagnostic settings to a new Log Analytics workspace would be both unnecessary and disruptive because the Microsoft Entra ID connector ingests audit logs directly through the Graph API, not through diagnostic settings. Diagnostic settings for Microsoft Entra ID are used when you want to stream logs to Event Hubs or archive to storage, but the Sentinel connector does not depend on them. Changing workspaces would break the existing connector's data source and require repointing security content, with no benefit from the name change.
- ✗
Create a new data connector for Microsoft Entra ID.
Why it's wrong here
Creating a new data connector for Microsoft Entra ID is redundant because the existing Microsoft Entra ID connector in Microsoft Sentinel is the same connector, simply renamed. The connector's underlying code and API integration are unaffected by the branding change, so it will continue to collect the required logs. Adding a second connector would result in duplicate ingestion, increased Log Analytics costs, and possible alert duplication.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.