Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelEasy
A security engineer is configuring data ingestion for Microsoft Sentinel. The organization uses Azure Active Directory (Azure AD) and needs to collect sign-in logs and audit logs into Sentinel. Which data connector should the engineer configure to ingest these specific log types?
- AAzure Activity
- BAzure Active Directory
- CMicrosoft Defender for Cloud
- DMicrosoft 365 Defender
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Active Directory
The Azure Active Directory data connector in Microsoft Sentinel is specifically designed to ingest Azure AD sign-in logs, audit logs, and provisioning logs.
Why the other options are wrong
- A. Azure Activity connector ingests subscription-level events (e.g., resource creation/deletion), not Azure AD sign-in or audit logs.
- C. Microsoft Defender for Cloud provides security posture management and threat protection for Azure resources, not direct Azure AD sign-in/audit logs.
- D. Microsoft 365 Defender connector brings in data from Defender for Endpoint, Identity, Office 365, etc., but the direct Azure AD logs are best sourced via the Azure AD connector.
Azure Active Directory Data Connector
The Azure Active Directory data connector in Microsoft Sentinel is used to ingest Azure AD sign-in logs, audit logs, and provisioning logs into your Sentinel workspace.
- Ingests Azure AD sign-in logs.
- Ingests Azure AD audit logs.
- Provides visibility into identity-related activities.
Memory trick: To see Azure AD actions, use the 'Azure AD' connector directly.