nerdexam
Microsoft

SC-200 · Question #308

Your on-premises network contains an Active Directory Domain Services (AD DS) forest. You have a Microsoft Entra tenant that uses Microsoft Defender for Identity. The AD DS forest syncs with the…

The correct answer is D. IdentityLogonEvents. The IdentityLogonEvents table in Microsoft Sentinel / Defender XDR captures authentication and logon activity detected by Microsoft Defender for Identity, which monitors on-premises Active Directory Domain Services. LDAP simple binds to domain controllers are a form of AD…

Submitted by kevin_r· Apr 18, 2026

Question

Your on-premises network contains an Active Directory Domain Services (AD DS) forest. You have a Microsoft Entra tenant that uses Microsoft Defender for Identity. The AD DS forest syncs with the tenant. You need to create a hunting query that will identify LDAP simple binds to the AD DS domain controllers. Which table should you query?

Options

  • AAADServicePrincipalRiskEvents
  • BAADDomainServicesAccountLogon
  • CSigninLogs
  • DIdentityLogonEvents

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    11% (3)
  • D
    82% (23)

Explanation

The IdentityLogonEvents table in Microsoft Sentinel / Defender XDR captures authentication and logon activity detected by Microsoft Defender for Identity, which monitors on-premises Active Directory Domain Services. LDAP simple binds to domain controllers are a form of AD authentication that Defender for Identity sensors capture and surface in this table. AADServicePrincipalRiskEvents (A) covers Azure AD service principal risk signals. AADDomainServicesAccountLogon (B) is specific to Azure AD Domain Services (the managed PaaS offering), not on-premises AD DS. SigninLogs (C) contains Azure AD interactive and non-interactive cloud sign-in data, not on-premises LDAP authentication.

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice