SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Identity (MDI) and Microsoft Sentinel. You notice that MDI alerts are not appearing in Sentinel. You have already installed the MDI data connector and configured the workspace. What is the most likely cause?
⚠ Common exam trap
It's easy for candidates to confuse 'installed' with 'enabled', assuming that installing a data connector automatically starts data ingestion, when in fact a separate enablement step is required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The data connector is not enabled, even though it is installed
The most likely cause is that the MDI data connector, although installed, is not enabled. In Microsoft Sentinel, installing a data connector only makes it available; you must explicitly enable it to start ingesting data. Without enabling the connector, alerts from Microsoft Defender for Identity will not flow into Sentinel, even if the workspace is correctly configured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The workspace is in a different region than MDI
Why it's wrong here
Sentinel's data connectors use API-based ingestion that is not constrained by the geographic region of the Log Analytics workspace relative to the Microsoft Defender for Identity tenant. Even if the workspace is in a different Azure region, the MDI connector still establishes a connection through the Microsoft Graph Security API and can pull alerts successfully. Therefore, a region mismatch cannot explain why you see no MDI alerts; the failure is more likely due to an unenabled connector or a permission issue on the subscription.
- ✗
The Microsoft 365 Defender connector is not installed
Why it's wrong here
Microsoft Defender for Identity alerts are ingested exclusively through the Microsoft Defender for Identity data connector in Sentinel, which is distinct from the Microsoft 365 Defender connector. The Microsoft 365 Defender connector polls data from Microsoft 365 Defender incident and alert pipelines, but MDI telemetry is not part of that pipeline because Defender for Identity is an Azure portal-based identity security service. Since MDI uses its own sensor and agent to send alerts to the cloud, the absence of the M365 Defender connector does not affect MDI alert ingestion.
- ✓
The data connector is not enabled, even though it is installed
Why this is correct
Installing the Microsoft Defender for Identity data connector from the Content Hub only copies the connector into your Sentinel workspace; you must separately enable it by opening the connector page and clicking 'Connect' to establish the data flow. In the common scenario where the connector is installed but not enabled, the Health and Status column shows 'Disconnected' while the connector still appears as installed. Without this explicit enablement step, even an active MDI deployment will not send alerts to Sentinel, so the alerts remain missing from the workspace.
- ✗
Microsoft Defender for Identity is not licensed
Why it's wrong here
If Microsoft Defender for Identity were unlicensed, the MDI service would not function at all—there would be no sensor agents, no domain controller integration, and no generated security alerts to ingest. The organization already uses MDI, which implies it is licensed and producing alerts; otherwise, there would be nothing to forward to Sentinel. Thus, a licensing issue cannot be the root cause, and the investigation should focus on connector health and enablement rather than license status.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.