Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium

A security analyst is investigating an incident in Microsoft Sentinel involving suspicious activity from an Azure Active Directory (AAD) user account. The analyst needs to quickly identify all sign-in attempts, administrative actions, and changes to user properties performed by this specific user within the last 72 hours. Which data connector should the analyst primarily focus on to gather this information efficiently?

  1. AMicrosoft 365 Defender
  2. BAzure Security Center
  3. CAzure Activity
  4. DAzure Active Directory
Show answer & explanation

Correct answer: D. Azure Active Directory

The Azure Active Directory data connector ingests logs related to AAD activities, including sign-ins (SignInLogs), audit logs (AuditLogs for administrative actions and user property changes), and provisioning logs. This is the primary source for comprehensive AAD user activity.

Why the other options are wrong

  • A. Microsoft 365 Defender provides broader endpoint, email, and identity protection, but the specific, detailed AAD logs are best sourced directly from the Azure Active Directory connector.
  • B. Azure Security Center (now Microsoft Defender for Cloud) focuses on cloud security posture management and workload protection, not direct AAD user activity logs.
  • C. Azure Activity logs primarily capture resource management plane activities in Azure, not detailed AAD user sign-ins or internal AAD changes.

Azure Active Directory Data Connector

The Azure Active Directory data connector in Microsoft Sentinel ingests identity-related logs, including sign-in logs, audit logs, and provisioning logs, providing visibility into user authentication and administrative activities.

  • Ingests SignInLogs, AuditLogs, ProvisioningLogs.
  • Crucial for identity-based threat detection.
  • Covers user authentication, administrative changes, and user provisioning.

Memory trick: AAD Connector: All About AAD Actions!

More Mitigate threats using Microsoft Sentinel questions