Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
06Connect logs to Microsoft Sentinel7 modules · 49 units · Content Hub, Microsoft services, Defender, Windows, CEF, Syslog, and threat intelligence0/49 units complete
Learning path 06 · Connect logs to Microsoft Sentinel

7 modules · 49 units · Content Hub, Microsoft services, Defender, Windows, CEF, Syslog, and threat intelligence

0%

Study focus

Data onboarding

Select and configure connectors for Microsoft services, Defender, Windows, CEF, and Syslog sources.

Collection reliability

Plan agents, data collection rules, forwarding, destination tables, threat indicators, and ingestion validation.

7 modules · 49 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

02

Module 2

Connect Microsoft services to Microsoft Sentinel

Focus: Microsoft 365, Microsoft Entra, Identity Protection, and Azure Activity connectors.
0/8
01 / 08Introduction

Microsoft service connectors bring audit, identity, risk, and Azure control-plane signals into Sentinel. Each connector has distinct permissions, tables, pricing implications, and incident behavior.

Official moduleMicrosoft connector objectives
02 / 08Plan for Microsoft services connectors
ConnectorPrimary output
Microsoft 365Exchange, SharePoint, and Teams audit records in OfficeActivity.
Microsoft Entra IDSeparate tables for audit, user, service principal, managed identity, provisioning, and AD FS sign-ins.
Entra ID ProtectionRisk alerts in SecurityAlert; optional incident creation rule.
Azure ActivitySubscription and ARM control-plane events in AzureActivity.

Select only log types required by detection and investigation use cases, while retaining enough identity and audit context.

Official lessonService-to-table planning
03 / 08Connect the Microsoft 365 connector

Install the Microsoft 365 solution, open its connector, verify prerequisites, select Exchange, SharePoint, and/or Teams record types, and apply changes. Wait until validation completes and the action changes to Disconnect.

Use OfficeActivity to investigate mailbox changes, file access and downloads, sharing activity, group changes, Teams operations, and the responsible user.

Official lessonMicrosoft 365 audit ingestion
04 / 08Connect the Microsoft Entra connector
Log typeTable
Interactive user sign-insSigninLogs
Non-interactive sign-insAADNonInteractiveUserSignInLogs
Service principal sign-insAADServicePrincipalSignInLogs
Managed identity sign-insAADManagedIdentitySignInLogs
ProvisioningAADProvisioningLogs
AD FS sign-insADFSSignInLogs
Directory auditAuditLogs

Install the Entra ID solution, open the connector, select required streams independently, and connect. Ingestion scope directly affects cost and detection coverage.

Official lessonEntra sign-in and audit streams
05 / 08Connect the Microsoft Entra ID Protection connector

Install the Identity Protection solution, open the connector, and connect risk alerts. Enabling automatic incident creation activates the default analytics rule that converts ingested Identity Protection alerts into Sentinel incidents.

The connector supplies alert context, not all underlying identity telemetry. Combine it with Entra sign-in and audit logs for investigation.

Official lessonRisk alerts and incident creation
06 / 08Connect the Azure Activity connector

Azure Activity captures subscription-level ARM operations, resource writes, service-health events, and operation status. The connector uses Azure Policy to deploy the subscription-to-workspace streaming configuration.

  1. Install Azure Activity and open the connector.
  2. Launch the Azure Policy assignment wizard and select subscription scope.
  3. Select the primary Log Analytics workspace.
  4. Create a remediation task so existing subscriptions receive the configuration.

The lesson requires Owner on the relevant subscription.

Official lessonPolicy-based Azure Activity ingestion
07 / 08Module assessment

Match Microsoft services to their tables, permissions, selectable streams, alert-versus-raw-data behavior, and Azure Policy deployment requirements.

Official assessmentMicrosoft connectors knowledge check
08 / 08Summary and resources

Connect the minimum set of service streams that satisfies audit and detection requirements, then validate both connector health and representative rows in every expected table.

Official moduleSummary and resources
End of learning pathConnect logs to Microsoft Sentinel