SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Identity (MDI) to monitor on-premises Active Directory. You want to forward MDI alerts to Microsoft Sentinel. What should you configure?
⚠ Common exam trap
Test-takers frequently confuse the Microsoft Defender for Identity connector with the Microsoft 365 Defender connector, assuming the unified portal connector is the correct way to forward MDI alerts, but the exam expects the specific product-named connector for direct integration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Identity connector
Microsoft Defender for Identity (MDI) alerts are forwarded to Microsoft Sentinel by configuring the Microsoft Defender for Identity data connector. This connector ingests MDI security alerts, such as suspicious Kerberos activity or lateral movement attempts, directly into Sentinel for advanced correlation and incident response. The connector uses the Microsoft Graph Security API to pull alerts from the MDI service, enabling seamless integration without additional agents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft 365 Defender connector
Why it's wrong here
The Microsoft 365 Defender connector (now Microsoft Defender XDR) ingests unified incidents and correlated alerts from across the defender suite, but it does not export raw Microsoft Defender for Identity alerts directly. When you enable this connector, you receive high-level incidents that may reference identity threats, but the standalone MDI alert details are not populated into Sentinel through this path, so it cannot serve as the required connector for MDI alert ingestion.
- ✗
Azure Advanced Threat Protection connector
Why it's wrong here
Azure Advanced Threat Protection (ATP) was the predecessor to Microsoft Defender for Identity, and its Sentinel connector was deprecated when the service was rebranded and replaced. Although older deployments might have used the Azure ATP connector to bring in legacy identity alerts, Microsoft no longer supports it, and the current, supported integration is the dedicated Microsoft Defender for Identity connector; selecting an obsolete connector would not work in a modern deployment.
- ✗
Microsoft Defender for Cloud Apps connector
Why it's wrong here
The Microsoft Defender for Cloud Apps connector is designed to bring in alerts and activities from the cloud application security broker, such as shadow IT discovery, cloud app anomalies, and policy violations for SaaS applications. It does not provide any mechanism to retrieve on-premises or hybrid identity alerts generated by Microsoft Defender for Identity, which focuses on attack techniques like pass-the-hash, golden ticket, and domain controller reconnaissance, so it is not the correct connector for this need.
- ✓
Microsoft Defender for Identity connector
Why this is correct
The Microsoft Defender for Identity connector is the direct and supported data connector in Sentinel for ingesting identity security alerts from Microsoft Defender for Identity. It authenticates to the MDI API and pulls raw alerts—including suspected lateral movement, account enumeration, and domain controller compromise—into the SecurityAlert table with the provider name 'MicrosoftDefenderForIdentity', making it the correct choice for this organization.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.