Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
05Configure your Microsoft Sentinel environment6 modules · 42 units · SIEM architecture, workspaces, logs, watchlists, threat intelligence, and unified SIEM/XDR0/42 units complete
Learning path 05 · Configure your Microsoft Sentinel environment

6 modules · 42 units · SIEM architecture, workspaces, logs, watchlists, threat intelligence, and unified SIEM/XDR

0%

Study focus

Sentinel foundation

Understand the SIEM workflow and design workspaces, permissions, retention, and data tiers.

Security context

Use logs, watchlists, threat intelligence, and Defender XDR integration to support operations.

6 modules · 42 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

06

Module 6

Integrate Microsoft Defender XDR with Microsoft Sentinel

Focus: unified SIEM and XDR, portal differences, prerequisites, workspace connection, and the integrated operating model.
0/8
01 / 08Introduction

Onboarding a Sentinel workspace to the Defender portal combines Sentinel's broad SIEM collection and content with Defender XDR incidents, detections, entities, advanced hunting, and response in a unified operations experience.

Official moduleIntegration objectives and prerequisites
02 / 08Understand the benefits of integrating Microsoft Sentinel with Defender XDR
  • A unified incident queue correlates Defender XDR and Sentinel evidence.
  • Advanced hunting can query XDR telemetry and onboarded Sentinel workspace tables.
  • Analysts use one portal for triage, investigation, hunting, automation, content, connectors, and settings.
  • Microsoft correlation replaces duplicate or overlapping incident-creation paths.

The integration preserves Sentinel's Azure RBAC model while bringing its data and capabilities into the Defender portal.

Official lessonUnified SIEM and XDR benefits
03 / 08Explore capability differences between portals

Most Sentinel functions exist in both portals, but some tasks remain portal-specific or behave differently. Examples from the lesson include Azure-only bookmark support in advanced hunting, editing comments and incident tasks; Defender-only SAP attack disruption and certain alert-to-incident operations; and differing automation procedures.

After onboarding, Defender XDR incident correlation replaces Fusion for Microsoft security alerts, and some incident creation or reopening behaviors change. Always verify the portal required by the specific operation.

Official lessonAzure and Defender portal differences
04 / 08Onboard Microsoft Sentinel to Microsoft Defender XDR

Prerequisites include a Sentinel-enabled Log Analytics workspace, the Microsoft Defender XDR solution and connector with incidents and alerts enabled, Defender XDR access in the same Entra tenant, and suitable Azure roles.

  1. Open the Defender portal and select Connect a workspace.
  2. Select the Sentinel workspace and review product changes.
  3. Confirm that Sentinel tables and functions become available to advanced hunting.
  4. Connect and verify unified metrics, incidents, connectors, and automation.

Owner, or User Access Administrator plus Sentinel Contributor, is required to connect or disconnect at the documented scopes. Reader supports viewing and querying; Contributor supports incident actions. Azure RBAC continues to be managed in Azure.

Exam takeaway: onboarding can deactivate Microsoft-security incident creation rules to prevent duplicates while streaming Defender alerts through the primary XDR connector.
Official lessonPrerequisites, roles, connect, and disconnect
05 / 08Explore Microsoft Sentinel features in Microsoft Defender XDR

Unified Overview, Incidents, and Advanced hunting combine Sentinel and Defender XDR data. Sentinel-specific navigation in Defender includes Search, Threat management, Content management, and Configuration.

  • Threat management: workbooks, hunting, bookmarks, livestream, notebooks, TI, and MITRE coverage.
  • Content management: Content Hub and repositories.
  • Configuration: connectors, analytics rules, watchlists, automation rules, and playbooks.
  • System settings: workspace and Sentinel integration configuration.
Official lessonUnified portal feature map
06 / 08Exercise - Connect Microsoft Sentinel to Microsoft Defender XDR

Use the simulation to practice locating the connection workflow, selecting a Sentinel workspace, reviewing prerequisites and changes, completing onboarding, and confirming that Sentinel features appear in the Defender portal.

Official simulationConnect Sentinel to the Defender portal
07 / 08Module assessment

Review integration benefits, portal-specific capabilities, connector and RBAC prerequisites, onboarding side effects, workspace connection and disconnection, and the location of Sentinel features in Defender.

Official assessmentUnified SIEM/XDR knowledge check
08 / 08Summary

The unified Defender portal brings Sentinel's SIEM breadth and Defender XDR's native telemetry and correlation into one analyst workflow, while workspace data, retention, and Azure RBAC remain governed by the underlying Azure resources.

Official moduleSummary and resources
End of learning pathConfigure your Microsoft Sentinel environment