Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
06Connect logs to Microsoft Sentinel7 modules · 49 units · Content Hub, Microsoft services, Defender, Windows, CEF, Syslog, and threat intelligence0/49 units complete
Learning path 06 · Connect logs to Microsoft Sentinel

7 modules · 49 units · Content Hub, Microsoft services, Defender, Windows, CEF, Syslog, and threat intelligence

0%

Study focus

Data onboarding

Select and configure connectors for Microsoft services, Defender, Windows, CEF, and Syslog sources.

Collection reliability

Plan agents, data collection rules, forwarding, destination tables, threat indicators, and ingestion validation.

7 modules · 49 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

03

Module 3

Connect Microsoft Defender XDR to Microsoft Sentinel

Focus: unified and Azure portal integration, Defender for Cloud and IoT, and legacy connector replacement.
0/8
01 / 08Introduction

Defender connectors bring cross-domain incidents and alerts into Sentinel and can optionally ingest raw events for hunting, correlation, and analytics.

Official moduleDefender connector objectives
02 / 08Plan for Microsoft Defender XDR connectors

The primary Microsoft Defender XDR connector covers Endpoint, Identity, Office 365, Cloud Apps, and other integrated alert providers. Plan whether you need bidirectional incident synchronization, alerts only, raw advanced-hunting events, or entity data.

Individual Defender for Endpoint, Identity, Office 365, and Cloud Apps alert connectors are legacy. Prefer the unified XDR connector to avoid independently managed duplicate incidents and missing raw data.

Official lessonDefender integration decisions
03 / 08Connect the Microsoft Defender XDR connector

When Sentinel is onboarded to the Defender portal and properly licensed, the XDR connector is configured automatically and individual alert-provider connectors are disconnected. For Azure-portal integration, install the Defender XDR solution and explicitly connect incidents and alerts.

  • Incidents are synchronized across portals, including title, severity, tags, selected metadata, and new comments.
  • Optional events and entities support hunting and UEBA.
  • Incident creation rules for integrated Microsoft products should be disabled to avoid duplicates.
  • Normal incident appearance is typically within five minutes; table ingestion can take longer.
Official lessonUnified connection and synchronization
04 / 08Connect Microsoft Defender for Cloud connector

Connect selected subscriptions to stream Defender for Cloud security alerts into Sentinel for workbooks, KQL, analytics, incidents, and response. Enable bidirectional synchronization when status changes should flow between products.

Official lessonCloud workload alert connection
05 / 08Connect Microsoft Defender for IoT

Connect the subscription to ingest Defender for IoT alerts and use built-in content for alert trends, severity breakdowns, top alerts, and IoT security recommendations.

Official lessonIoT alerts and recommendations
06 / 08Connect Microsoft Defender legacy connectors

Legacy product connectors sent alerts only, did not ingest raw telemetry, and could create separate Sentinel incidents that had to be managed independently from Defender incidents. Replace them with the Microsoft Defender XDR connector wherever supported.

Official lessonLegacy limitations and migration rationale
07 / 08Module assessment

Review automatic versus manual XDR integration, synchronized incidents, optional raw data, duplicate prevention, Defender for Cloud and IoT connections, and legacy limitations.

Official assessmentDefender connector knowledge check
08 / 08Summary and resources

Use the unified XDR connector as the central Defender integration and deliberately control incident, alert, entity, and raw-event ingestion to balance coverage and cost.

Official moduleSummary and resources
End of learning pathConnect logs to Microsoft Sentinel