SC-200 · Question #273
You have a Microsoft 365 subscription that uses Microsoft Defender for Cloud Apps and has Cloud Discovery enabled. You need to enrich the Cloud Discovery data. The solution must ensure that…
The correct answer is B. Create a Microsoft 365 app connector. To enrich Cloud Discovery data by associating usernames from traffic logs with Microsoft Entra ID UPNs, creating an app connector for Microsoft 365 is the first step.
Question
You have a Microsoft 365 subscription that uses Microsoft Defender for Cloud Apps and has Cloud Discovery enabled. You need to enrich the Cloud Discovery data. The solution must ensure that usernames in the Cloud Discovery traffic logs are associated with the user principal name (UPN) of the corresponding Microsoft Entra ID user accounts. What should you do first?
Options
- AFrom Conditional Access App Control, configure User monitoring.
- BCreate a Microsoft 365 app connector.
- CEnable automatic redirection to Microsoft 365 Defender.
- DCreate an Azure app connector.
How the community answered
(64 responses)- A3% (2)
- B89% (57)
- C6% (4)
- D2% (1)
Why each option
To enrich Cloud Discovery data by associating usernames from traffic logs with Microsoft Entra ID UPNs, creating an app connector for Microsoft 365 is the first step.
Conditional Access App Control is used for real-time monitoring and control of access to cloud apps, not for enriching historical Cloud Discovery data with UPNs from traffic logs. User monitoring within CAAC focuses on session policies.
Creating a Microsoft 365 app connector allows Microsoft Defender for Cloud Apps to integrate with Microsoft Entra ID, enabling it to retrieve detailed user information, group memberships, and activity data. This integration is crucial for enriching Cloud Discovery logs by resolving usernames from traffic data to their corresponding Microsoft Entra ID UPNs and other identity attributes.
Enabling automatic redirection to Microsoft 365 Defender is a configuration for integrating security portals, but it does not directly enable the mapping of usernames from raw traffic logs to Entra ID UPNs within Defender for Cloud Apps.
An Azure app connector is used for connecting to Azure services for governance and security within Defender for Cloud Apps, which is different from connecting to Microsoft Entra ID for user identity resolution in Cloud Discovery.
Concept tested: Defender for Cloud Apps Cloud Discovery user enrichment
Source: https://learn.microsoft.com/en-us/defender-cloud-apps/connect-office-365-to-defender-for-cloud-apps
Topics
Community Discussion
No community discussion yet for this question.