What's changed: Added an awareness note on Microsoft Security Copilot (generative-AI security operations, Ignite 2025) to the Sentinel section, reflecting the AI-assist trend (no structural change to official skills measured).
3.1Defender for Cloud and Microsoft Sentinel
Understand Microsoft Defender for Cloud, which assesses and strengthens cloud security posture, and Microsoft Sentinel, a cloud SIEM/SOAR that detects and responds to threats.
Microsoft provides solutions for both "is my current state secure (posture)" and "can I detect and respond to threats (operations)." The former is Defender for Cloud; the latter is Microsoft Sentinel.
3.1.1Two roles
- Microsoft Defender for Cloud: assesses cloud security posture (CSPM) with recommendations and Secure Score, and protects servers/storage/DBs via cloud workload protection (CWPP); can also cover other clouds and on-prem.
- Microsoft Sentinel: a cloud-native SIEM + SOAR; collects logs, then detects, investigates, and automatically responds to threats.
SIEM (Security Information and Event Management) centrally collects and analyzes logs from servers, network, identity, and more, using correlation rules to surface threat signs. SOAR (Security Orchestration, Automation and Response) automates post-detection response, running routine actions (disable accounts, isolate, notify) via playbooks. Microsoft Sentinel provides both in the cloud, finding attacks in massive logs and streamlining response. The key split: proactive posture = Defender for Cloud / live detection & response = Sentinel.
| Aspect | Defender for Cloud | Microsoft Sentinel |
|---|---|---|
| Main role | Posture assessment, workload protection | Threat detection/investigation/response |
| Category | CSPM + CWPP | SIEM + SOAR |
| Question | "Are resources configured securely?" | "Is an attack happening; can we respond?" |
| Signature feature | Secure Score, recommendations | Log correlation, playbooks |
Scenario: operations and monitoring. A security team uses Defender for Cloud’s Secure Score to fix recommendations like "unencrypted Storage" or "admins without MFA," raising posture. Meanwhile, signs of a real attack (a spike in suspicious sign-ins) are detected by Sentinel correlating logs, and a playbook automatically isolates and notifies the account. Prevention and response run together.
Watch the mix-ups: (1) Defender for Cloud (proactive posture = CSPM + workload protection) vs Sentinel (live detection/response = SIEM/SOAR). (2) SIEM = collect/analyze logs, SOAR = automate response—Sentinel has both. (3) Secure Score is a Defender for Cloud feature, not Sentinel’s.
Q. CSPM vs CWPP? CSPM is posture management ("is the config secure?"); CWPP protects running workloads like servers and DBs. Defender for Cloud includes both. Q. Sentinel vs Defender XDR? Defender XDR (next section) does specialized detection/response per domain (endpoint, email, identity, apps); Sentinel is an organization-wide SIEM/SOAR collecting logs across everything—and they integrate.
Common: assess posture/Secure Score = Defender for Cloud (CSPM+CWPP), SIEM/SOAR for log collection, detection, automated response = Microsoft Sentinel. SIEM = collect/analyze, SOAR = automate response.
(For awareness) Microsoft Security Copilot: Recently, Microsoft Security Copilot arrived as a generative-AI assistant for security operations, working with Defender, Sentinel, Entra, and Purview to summarize incident investigations and suggest responses (Ignite 2025 announced built-in agents across these products). For SC-900, it is enough to be aware that AI assistance is being added to Microsoft security.
3.1.2Section summary
- Defender for Cloud = posture assessment (CSPM, Secure Score)
- Microsoft Sentinel = cloud SIEM/SOAR (detect/respond)
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which service assesses cloud security posture and drives improvement via Secure Score?
Q2. Which cloud-native SIEM/SOAR collects logs and detects, investigates, and auto-responds to threats?
Q3. What does SOAR mainly provide?

