How to Enable Microsoft Defender XDR Connector for Incident Creation in Microsoft Sentinel
Your organization uses Microsoft Sentinel and Microsoft Defender XDR. The security team wants to automatically create an incident in Microsoft Sentinel when a Microsoft Defender for Endpoint alert is triggered. What should you configure?
Quick Answer
The correct answer is to enable the Microsoft Defender XDR connector in Microsoft Sentinel and configure its incident creation settings. This connector is purpose-built to ingest alerts and incidents from Microsoft Defender for Endpoint and other Defender products, bridging the gap between the two platforms. When enabled with incident creation toggled on, Sentinel automatically generates an incident for every Defender for Endpoint alert, eliminating the need for custom logic or manual polling. On the SC-200 exam, this question tests your understanding of native data connectors versus custom solutions; a common trap is assuming you need a separate playbook or logic app for automation. Remember the key principle: the Defender XDR connector is the single, official pipeline for Defender alerts into Sentinel. A useful memory tip is “XDR connects, incidents reflect”—if you enable the connector, incidents follow automatically.
⚠ Common exam trap
Many exam-takers confuse the purpose of analytics rules (which generate alerts from raw data) with the connector's role (which ingests pre-existing alerts from external sources), leading them to incorrectly select Option D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the Microsoft Defender XDR connector in Microsoft Sentinel and select the incident creation settings.
The Microsoft Defender XDR connector in Microsoft Sentinel is specifically designed to ingest alerts and incidents from Microsoft Defender for Endpoint and other Defender products. By enabling this connector and configuring its incident creation settings, Sentinel automatically creates incidents when Defender for Endpoint alerts are triggered, without requiring custom logic or manual polling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable the Microsoft Defender XDR connector in Microsoft Sentinel and select the incident creation settings.
Why this is correct
Enabling the Microsoft Defender XDR connector streams Defender for Endpoint alerts into Microsoft Sentinel, where the "Create incidents" toggle governs automatic incident generation. This directly satisfies the requirement to auto-create Sentinel incidents from endpoint alerts, since the connector's incident creation setting is the mechanism controlling that behaviour.
- ✗
Set up a Logic App custom connector to poll Defender alerts.
Why it's wrong here
A polling Logic App introduces latency and duplicates the native Defender XDR connector, which already streams alerts into Sentinel. It is tempting because Logic Apps can automate responses, and it would be correct for orchestrating custom workflows across services lacking a built-in connector.
- ✗
Configure the Security Events connector to forward Defender alerts.
Why it's wrong here
The Security Events connector ingests Windows event logs via the Log Analytics agent, not Defender for Endpoint alerts. It is tempting because connectors feed Sentinel data, and it would be correct when collecting security events from on-premises Windows machines rather than XDR alerts.
- ✗
Create analytics rules in Microsoft Sentinel for each Defender alert type.
Why it's wrong here
Analytics rules query data already ingested; they do not create the ingestion path from Defender XDR, so no alert data arrives to trigger them. It is tempting because analytics rules generate Sentinel incidents, and it would be correct for detecting patterns within existing log data.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You want to ensure that incidents generated in Microsoft 365 Defender are automatically synchronized to Microsoft Sentinel. What should you configure?
easy- A.Set up an automation rule to import incidents
- B.Configure the Microsoft Sentinel connector in Microsoft Defender XDR
- C.Create an analytics rule to query Defender XDR data
- ✓ D.Enable the Microsoft Defender XDR data connector in Microsoft Sentinel
Why D: The Microsoft Defender XDR data connector in Microsoft Sentinel is specifically designed to synchronize incidents from Microsoft 365 Defender into Sentinel. When enabled, this connector uses the Microsoft Graph Security API to ingest incidents, alerts, and evidence, ensuring automatic and bidirectional synchronization without requiring additional automation rules or analytics queries.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.