Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
03Microsoft Defender for Cloud6 modules · 48 units · 4 hr 17 min · Cloud security posture, multicloud onboarding, workload protection, alerts, and response0/48 units complete
Learning path 03 · Microsoft Defender for Cloud

6 modules · 48 units · 4 hr 17 min · Cloud security posture, multicloud onboarding, workload protection, alerts, and response

0%

Study focus

Cloud posture and coverage

Connect Azure and hybrid resources, extend multicloud coverage, and manage cloud security posture.

Workload threat response

Enable workload protections, investigate alerts, and remediate risks across cloud resources.

6 modules · 48 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

02

Module 2

Connect Azure assets to Microsoft Defender for Cloud

Focus: asset inventory, automatic and manual provisioning, Azure Monitor Agent, and Data Collection Rules.
0/6
01 / 06Introduction

Connected resources must be visible and supply the required telemetry before posture and workload protections can operate. This module covers inventory and the provisioning methods for Azure assets.

Official moduleObjectives and prerequisites
02 / 06Explore and manage your resources with asset inventory

Asset inventory provides one searchable view of resources connected to Defender for Cloud. Filter by subscription, resource type, security state, recommendation, tag, or environment; inspect unhealthy and unmonitored resources; export CSV; or open the underlying Azure Resource Graph query.

  • Apply tags or launch Logic Apps for selected resources.
  • Onboard unmonitored servers where supported.
  • Use resource details to review recommendations and security findings.
Official lessonInventory, filtering, and bulk actions
03 / 06Configure auto provisioning

Auto provisioning deploys required monitoring components consistently across eligible resources. Defender for Cloud uses Azure Policy DeployIfNotExists effects and the environment's Settings & monitoring configuration.

The Azure Monitor Agent (AMA) is the recommended collection agent. Defender for Endpoint integration can automatically onboard supported servers when Defender for Servers is enabled. The legacy Log Analytics agent reached retirement in August 2024.

Exam takeaway: prefer centralized automatic provisioning; use manual onboarding only for controlled exceptions.
Official lessonPolicy-based agent provisioning
04 / 06Manual agent provisioning

Manual AMA deployment uses a Data Collection Rule (DCR) to define which resources collect which data and where it is sent.

  1. Create the DCR and choose platform and region.
  2. Add target resources.
  3. Add data sources such as Windows events, performance counters, Syslog, text, or IIS logs.
  4. Select a Log Analytics workspace destination.
  5. Verify agent health and heartbeat records.

Avoid attaching overlapping DCRs that collect the same stream twice. Direct MDE onboarding can protect a non-Azure server, but it does not provide Azure Arc management capabilities.

Official lessonAMA and Data Collection Rules
05 / 06Module assessment

Distinguish asset inventory from Azure Resource Graph, automatic from manual provisioning, AMA from the retired legacy agent, and a DCR's source-resource-destination model.

Official assessmentAzure connection knowledge check
06 / 06Summary and resources

Use inventory to find coverage gaps, automatic provisioning for consistent deployment, and carefully scoped DCRs when manual AMA configuration is necessary.

Official moduleSummary and resources
End of learning pathMicrosoft Defender for Cloud