nerdexam
Microsoft

SC-200 · Question #273

You have a Microsoft 365 subscription that uses Microsoft Defender for Cloud Apps and has Cloud Discovery enabled. You need to enrich the Cloud Discovery data. The solution must ensure that…

The correct answer is B. Create a Microsoft 365 app connector. To enrich Cloud Discovery data by associating usernames from traffic logs with Microsoft Entra ID UPNs, creating an app connector for Microsoft 365 is the first step.

Submitted by paula_co· Apr 18, 2026Manage threat mitigation using Microsoft Defender XDR

Question

You have a Microsoft 365 subscription that uses Microsoft Defender for Cloud Apps and has Cloud Discovery enabled. You need to enrich the Cloud Discovery data. The solution must ensure that usernames in the Cloud Discovery traffic logs are associated with the user principal name (UPN) of the corresponding Microsoft Entra ID user accounts. What should you do first?

Options

  • AFrom Conditional Access App Control, configure User monitoring.
  • BCreate a Microsoft 365 app connector.
  • CEnable automatic redirection to Microsoft 365 Defender.
  • DCreate an Azure app connector.

How the community answered

(64 responses)
  • A
    3% (2)
  • B
    89% (57)
  • C
    6% (4)
  • D
    2% (1)

Why each option

To enrich Cloud Discovery data by associating usernames from traffic logs with Microsoft Entra ID UPNs, creating an app connector for Microsoft 365 is the first step.

AFrom Conditional Access App Control, configure User monitoring.

Conditional Access App Control is used for real-time monitoring and control of access to cloud apps, not for enriching historical Cloud Discovery data with UPNs from traffic logs. User monitoring within CAAC focuses on session policies.

BCreate a Microsoft 365 app connector.Correct

Creating a Microsoft 365 app connector allows Microsoft Defender for Cloud Apps to integrate with Microsoft Entra ID, enabling it to retrieve detailed user information, group memberships, and activity data. This integration is crucial for enriching Cloud Discovery logs by resolving usernames from traffic data to their corresponding Microsoft Entra ID UPNs and other identity attributes.

CEnable automatic redirection to Microsoft 365 Defender.

Enabling automatic redirection to Microsoft 365 Defender is a configuration for integrating security portals, but it does not directly enable the mapping of usernames from raw traffic logs to Entra ID UPNs within Defender for Cloud Apps.

DCreate an Azure app connector.

An Azure app connector is used for connecting to Azure services for governance and security within Defender for Cloud Apps, which is different from connecting to Microsoft Entra ID for user identity resolution in Cloud Discovery.

Concept tested: Defender for Cloud Apps Cloud Discovery user enrichment

Source: https://learn.microsoft.com/en-us/defender-cloud-apps/connect-office-365-to-defender-for-cloud-apps

Topics

#Microsoft Defender for Cloud Apps#Cloud Discovery#App Connectors#User Mapping

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice