Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelEasy

A security analyst is configuring data ingestion for Microsoft Sentinel. The analyst needs to connect Azure Activity logs from multiple subscriptions to a single Sentinel workspace. Which data connector should be used to achieve this efficiently?

  1. AAzure Firewall
  2. BAzure Activity
  3. CAzure Active Directory Identity Protection
  4. DMicrosoft 365 Defender
Show answer & explanation

Correct answer: B. Azure Activity

The Azure Activity data connector is specifically designed to collect subscription-level events and audit logs from Azure, making it the correct choice for ingesting Azure Activity logs into Microsoft Sentinel.

Why the other options are wrong

  • A. Azure Firewall is a product that generates its own logs, which would typically be ingested via a different connector, not the general Azure Activity logs.
  • C. Azure Active Directory Identity Protection is used for identity-related risk detections, not general activity logs.
  • D. Microsoft 365 Defender integrates security alerts and raw data from various Microsoft 365 services, not Azure subscription activity logs directly.

Azure Activity Data Connector

A Microsoft Sentinel data connector that ingests subscription-level events and audit logs from Azure into a Log Analytics workspace.

  • Collects administrative, service health, resource health, and security events.
  • Essential for monitoring operations within Azure subscriptions.
  • Supports connecting multiple subscriptions to a single Sentinel instance.

Memory trick: Connectors are the 'pipes' that bring data into Sentinel's 'brain'.

More Mitigate threats using Microsoft Sentinel questions