Gathering Context About a User Entity in Microsoft Sentinel
A security analyst is using Microsoft Sentinel to investigate an incident. Which THREE data sources can be ingested into Sentinel?
⚠ Common exam trap
It's easy for candidates to assume any Microsoft service log can be ingested into Sentinel, but only services with dedicated, built-in data connectors (like Microsoft Entra ID, Office 365, and Windows Security Events) are directly supported, while others like Power BI and Azure DevOps require custom or third-party solutions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID logs
Microsoft Sentinel natively supports ingesting Microsoft Entra ID (Azure AD) sign-in and audit logs through the Microsoft Entra ID data connector, making option B correct for identity-based threat detection. Option C is correct because Office 365 logs (Exchange, SharePoint, Teams, etc.) are ingested via the Office 365 connector using the Office 365 Management Activity API. Option D is correct because Windows Security Events can be collected via the Azure Monitor Agent (AMA) or the Log Analytics agent using the Windows Security Events via AMA connector or the Security Events connector. Option A is not a supported Sentinel data source, as Power BI usage metrics are not part of Sentinel's built-in connectors. Option E is also not a standard Sentinel connector; Azure DevOps audit logs are not natively ingested into Sentinel without custom workarounds.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Power BI usage metrics
Why it's wrong here
Power BI usage metrics, while valuable for understanding adoption and performance, are not directly ingested into Microsoft Sentinel as a native data connector for security analysis. Sentinel primarily focuses on security-relevant logs and events from services like Microsoft Entra ID, Office 365, and various infrastructure components. While custom ingestion via Azure Data Factory or Logic Apps is theoretically possible, it's not a standard or recommended method for these specific metrics, making it an unsupported direct data source.
- ✓
Microsoft Entra ID logs
Why this is correct
Microsoft Sentinel offers a robust, out-of-the-box data connector for Microsoft Entra ID, enabling the ingestion of critical identity-related logs such as sign-in logs, audit logs, and provisioning logs. These logs are fundamental for detecting suspicious authentication attempts, privilege escalation, and other identity-based threats across an organization's cloud identity infrastructure. The connector streams these events directly into a Log Analytics workspace for real-time analysis and correlation with other security data.
- ✓
Office 365 logs
Why this is correct
Microsoft Sentinel provides a dedicated connector to ingest audit logs from various Office 365 services, including Exchange Online, SharePoint Online, and Microsoft Teams. This allows security analysts to monitor user and administrative activities within productivity applications, identifying potential data exfiltration, unauthorized access, or policy violations. The Office 365 connector is crucial for comprehensive cloud application security monitoring and compliance.
- ✓
Windows Security Events
Why this is correct
Windows Security Events are a cornerstone of endpoint security monitoring and are fully supported for ingestion into Microsoft Sentinel. These events, encompassing logon/logoff activities, process creation, and object access, are collected from Windows servers and workstations using either the legacy Microsoft Monitoring Agent (MMA) or the modern Azure Monitor Agent (AMA). The agents forward these critical security logs to a Log Analytics workspace for centralized analysis, threat detection, and incident response.
- ✗
Azure DevOps audit logs
Why it's wrong here
While Azure DevOps generates audit logs that are crucial for monitoring development pipeline security, Microsoft Sentinel does not currently offer a direct, out-of-the-box data connector specifically for Azure DevOps audit logs. Ingesting these logs would typically require a custom solution, such as exporting them to Azure Storage and then using Azure Logic Apps or Azure Functions to push them into a Log Analytics workspace. This makes it a non-standard, more complex ingestion scenario compared to native connectors.
Go deeper
Related to this question
Learn chapter
Audit Log Retention Policies
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.