Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Identity (MDI) and Microsoft Sentinel. You notice that MDI alerts are not appearing in Sentinel. You have already installed the MDI data connector and configured the workspace. What is the most likely cause?

⚠ Common exam trap

It's easy for candidates to confuse 'installed' with 'enabled', assuming that installing a data connector automatically starts data ingestion, when in fact a separate enablement step is required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The data connector is not enabled, even though it is installed

The most likely cause is that the MDI data connector, although installed, is not enabled. In Microsoft Sentinel, installing a data connector only makes it available; you must explicitly enable it to start ingesting data. Without enabling the connector, alerts from Microsoft Defender for Identity will not flow into Sentinel, even if the workspace is correctly configured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The workspace is in a different region than MDI

    Why it's wrong here

    Sentinel's data connectors use API-based ingestion that is not constrained by the geographic region of the Log Analytics workspace relative to the Microsoft Defender for Identity tenant. Even if the workspace is in a different Azure region, the MDI connector still establishes a connection through the Microsoft Graph Security API and can pull alerts successfully. Therefore, a region mismatch cannot explain why you see no MDI alerts; the failure is more likely due to an unenabled connector or a permission issue on the subscription.

  • ✗

    The Microsoft 365 Defender connector is not installed

    Why it's wrong here

    Microsoft Defender for Identity alerts are ingested exclusively through the Microsoft Defender for Identity data connector in Sentinel, which is distinct from the Microsoft 365 Defender connector. The Microsoft 365 Defender connector polls data from Microsoft 365 Defender incident and alert pipelines, but MDI telemetry is not part of that pipeline because Defender for Identity is an Azure portal-based identity security service. Since MDI uses its own sensor and agent to send alerts to the cloud, the absence of the M365 Defender connector does not affect MDI alert ingestion.

  • ✓

    The data connector is not enabled, even though it is installed

    Why this is correct

    Installing the Microsoft Defender for Identity data connector from the Content Hub only copies the connector into your Sentinel workspace; you must separately enable it by opening the connector page and clicking 'Connect' to establish the data flow. In the common scenario where the connector is installed but not enabled, the Health and Status column shows 'Disconnected' while the connector still appears as installed. Without this explicit enablement step, even an active MDI deployment will not send alerts to Sentinel, so the alerts remain missing from the workspace.

  • ✗

    Microsoft Defender for Identity is not licensed

    Why it's wrong here

    If Microsoft Defender for Identity were unlicensed, the MDI service would not function at all—there would be no sensor agents, no domain controller integration, and no generated security alerts to ingest. The organization already uses MDI, which implies it is licensed and producing alerts; otherwise, there would be nothing to forward to Sentinel. Thus, a licensing issue cannot be the root cause, and the investigation should focus on connector health and enablement rather than license status.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.