SC-200 · Question #308
Your on-premises network contains an Active Directory Domain Services (AD DS) forest. You have a Microsoft Entra tenant that uses Microsoft Defender for Identity. The AD DS forest syncs with the…
The correct answer is D. IdentityLogonEvents. The IdentityLogonEvents table in Microsoft Sentinel / Defender XDR captures authentication and logon activity detected by Microsoft Defender for Identity, which monitors on-premises Active Directory Domain Services. LDAP simple binds to domain controllers are a form of AD…
Question
Your on-premises network contains an Active Directory Domain Services (AD DS) forest. You have a Microsoft Entra tenant that uses Microsoft Defender for Identity. The AD DS forest syncs with the tenant. You need to create a hunting query that will identify LDAP simple binds to the AD DS domain controllers. Which table should you query?
Options
- AAADServicePrincipalRiskEvents
- BAADDomainServicesAccountLogon
- CSigninLogs
- DIdentityLogonEvents
How the community answered
(28 responses)- A4% (1)
- B4% (1)
- C11% (3)
- D82% (23)
Explanation
The IdentityLogonEvents table in Microsoft Sentinel / Defender XDR captures authentication and logon activity detected by Microsoft Defender for Identity, which monitors on-premises Active Directory Domain Services. LDAP simple binds to domain controllers are a form of AD authentication that Defender for Identity sensors capture and surface in this table. AADServicePrincipalRiskEvents (A) covers Azure AD service principal risk signals. AADDomainServicesAccountLogon (B) is specific to Azure AD Domain Services (the managed PaaS offering), not on-premises AD DS. SigninLogs (C) contains Azure AD interactive and non-interactive cloud sign-in data, not on-premises LDAP authentication.
Community Discussion
No community discussion yet for this question.