What's changed: Created SC-100 Chapter 2 (Domain 2 first-half "Security operations": Defender XDR/Sentinel (SIEM)/XDR+SIEM integration/Defender for Endpoint, Identity, Office 365, Cloud Apps; SOAR/automation rules/playbooks (Logic Apps)/threat hunting (KQL)/UEBA; centralized logging/Microsoft Purview Audit (Standard, Premium)/multicloud monitoring/retention and isolation; MITRE ATT&CK (Enterprise/Mobile/ICS)/detection coverage/incident-response workflows).
2.1Detection and response with XDR and SIEM
Understand the roles of Microsoft Defender XDR (cross-domain detection/response across identity/endpoints/email/SaaS) and Microsoft Sentinel (cloud-native SIEM), an integrated XDR+SIEM detection/response design, and monitoring for hybrid/multicloud.
The heart of security operations (SecOps) is "detect fast, respond fast." Microsoft provides two complementary products: Microsoft Defender XDR for deep cross-domain detection/response, and Microsoft Sentinel, a SIEM that aggregates and correlates all sources. Architects keep their roles distinct and design an integrated SOC.
2.1.1Microsoft Defender XDR: cross-domain detection/response
Microsoft Defender XDR (formerly Microsoft 365 Defender) auto-correlates signals from Defender for Endpoint (devices), Defender for Identity (on-prem AD/identity), Defender for Office 365 (email/collaboration), and Defender for Cloud Apps (SaaS), grouping scattered alerts into a single incident. Architects choose XDR for "visualize the attack chain across domains" and "reduce alert fatigue." XDR excels at deep detection/response within the Microsoft ecosystem.
2.1.2Microsoft Sentinel: cloud-native SIEM
Microsoft Sentinel is a SIEM that aggregates every source—not just Microsoft products but AWS/GCP, on-prem appliances, and third parties (firewalls, etc.). It ingests via data connectors, detects via analytics rules, and enables long-term retention and org-wide hunting. Choose Sentinel for "centralized monitoring/correlation across the whole org, multicloud, and third parties." XDR can feed its incidents into Sentinel via a connector, so the two are not competitors but layers (XDR = deep cross-domain; Sentinel = org-wide aggregation).
Cues: "deep cross-domain detection with auto-correlation over Microsoft endpoints/identity/email/SaaS" = Defender XDR. "aggregate/correlate/retain org-wide including AWS/GCP, on-prem, and third parties" = Sentinel (SIEM). Most designs "connect XDR into Sentinel" to get both.
Watch the mix-ups: (1) XDR ≠ SIEM. XDR is cross-domain detection/response; SIEM (Sentinel) is all-source aggregation/correlation. (2) Defender XDR is different from Defender for Cloud (cloud-infra posture/CWPP). (3) For "ingest third-party logs," XDR alone is insufficient—use Sentinel.
2.1.3Section summary
- Defender XDR = auto-correlates endpoint/identity/email/SaaS signals into incidents (cross-domain detection/response)
- Sentinel = cloud-native SIEM; aggregates/correlates/retains AWS/GCP, on-prem, and third parties
- Most designs connect XDR into Sentinel = deep cross-domain plus org-wide aggregation
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. To aggregate, correlate, and retain org-wide logs including AWS/GCP, on-prem appliances, and third-party firewalls, which is best?
Q2. To auto-correlate an attack chain spanning endpoints, identity, email, and SaaS into a single incident, which is best?
Q3. What is the common design for combining Defender XDR and Sentinel?
Q4. Which Defender component detects attacks on on-prem Active Directory (lateral movement, Pass-the-Hash, etc.)?
Q5. Which correctly states the difference between XDR and SIEM?

