What's changed: Created SC-100 Chapter 2 (Domain 2 first-half "Security operations": Defender XDR/Sentinel (SIEM)/XDR+SIEM integration/Defender for Endpoint, Identity, Office 365, Cloud Apps; SOAR/automation rules/playbooks (Logic Apps)/threat hunting (KQL)/UEBA; centralized logging/Microsoft Purview Audit (Standard, Premium)/multicloud monitoring/retention and isolation; MITRE ATT&CK (Enterprise/Mobile/ICS)/detection coverage/incident-response workflows).
2.1Detection and response with XDR and SIEM
Understand the roles of Microsoft Defender XDR (cross-domain detection/response across identity/endpoints/email/SaaS) and Microsoft Sentinel (cloud-native SIEM), an integrated XDR+SIEM detection/response design, and monitoring for hybrid/multicloud.
The heart of security operations (SecOps) is "detect fast, respond fast." Microsoft provides two complementary products: Microsoft Defender XDR for deep cross-domain detection/response, and Microsoft Sentinel, a SIEM that aggregates and correlates all sources. Architects keep their roles distinct and design an integrated SOC.
2.1.1Microsoft Defender XDR: cross-domain detection/response
Microsoft Defender XDR (formerly Microsoft 365 Defender) auto-correlates signals from Defender for Endpoint (devices), Defender for Identity (on-prem AD/identity), Defender for Office 365 (email/collaboration), and Defender for Cloud Apps (SaaS), grouping scattered alerts into a single incident. Architects choose XDR for "visualize the attack chain across domains" and "reduce alert fatigue." XDR excels at deep detection/response within the Microsoft ecosystem.
2.1.2Microsoft Sentinel: cloud-native SIEM
Microsoft Sentinel is a SIEM that aggregates every source—not just Microsoft products but AWS/GCP, on-prem appliances, and third parties (firewalls, etc.). It ingests via data connectors, detects via analytics rules, and enables long-term retention and org-wide hunting. Choose Sentinel for "centralized monitoring/correlation across the whole org, multicloud, and third parties." XDR can feed its incidents into Sentinel via a connector, so the two are not competitors but layers (XDR = deep cross-domain; Sentinel = org-wide aggregation).
Cues: "deep cross-domain detection with auto-correlation over Microsoft endpoints/identity/email/SaaS" = Defender XDR. "aggregate/correlate/retain org-wide including AWS/GCP, on-prem, and third parties" = Sentinel (SIEM). Most designs "connect XDR into Sentinel" to get both.
Watch the mix-ups: (1) XDR ≠ SIEM. XDR is cross-domain detection/response; SIEM (Sentinel) is all-source aggregation/correlation. (2) Defender XDR is different from Defender for Cloud (cloud-infra posture/CWPP). (3) For "ingest third-party logs," XDR alone is insufficient—use Sentinel.
2.1.3Section summary
- Defender XDR = auto-correlates endpoint/identity/email/SaaS signals into incidents (cross-domain detection/response)
- Sentinel = cloud-native SIEM; aggregates/correlates/retains AWS/GCP, on-prem, and third parties
- Most designs connect XDR into Sentinel = deep cross-domain plus org-wide aggregation
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. To aggregate, correlate, and retain org-wide logs including AWS/GCP, on-prem appliances, and third-party firewalls, which is best?
Q2. To auto-correlate an attack chain spanning endpoints, identity, email, and SaaS into a single incident, which is best?
Q3. What is the common design for combining Defender XDR and Sentinel?
Q4. Which Defender component detects attacks on on-prem Active Directory (lateral movement, Pass-the-Hash, etc.)?
Q5. Which correctly states the difference between XDR and SIEM?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

