nerdexam
Microsoft

MS-102 · Question #27

You have a Microsoft 365 tenant. You plan to manage incidents in the tenant by using the Microsoft 365 Defender. Which Microsoft service source will appear on the Incidents page of the Microsoft 365…

The correct answer is D. Microsoft Defender for Identity. rather be forwarded from M365 Defender TO Sentinel. Azure ARC and Defender for Cloud (not Defender for Cloud Apps) will send their alerts to Sentinel. That leaves MS Defender for Identity and that will indeed send alerts to M365 Defender interface.

Submitted by viktor_hu· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

You have a Microsoft 365 tenant. You plan to manage incidents in the tenant by using the Microsoft 365 Defender. Which Microsoft service source will appear on the Incidents page of the Microsoft 365 Defender portal?

Options

  • AMicrosoft Sentinel
  • BMicrosoft Defender for Cloud
  • CAzure Arc
  • DMicrosoft Defender for Identity

How the community answered

(30 responses)
  • A
    3% (1)
  • C
    7% (2)
  • D
    90% (27)

Explanation

rather be forwarded from M365 Defender TO Sentinel. Azure ARC and Defender for Cloud (not Defender for Cloud Apps) will send their alerts to Sentinel. That leaves MS Defender for Identity and that will indeed send alerts to M365 Defender interface.

Topics

#Microsoft 365 Defender#Incident management#Defender for Identity#Security services

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice