Instiq
Chapter 3 · Microsoft Security Solutions·v2.1.0·Updated 6/11/2026·~8 min

What's changed: Added an awareness note on Microsoft Security Copilot (generative-AI security operations, Ignite 2025) to the Sentinel section, reflecting the AI-assist trend (no structural change to official skills measured).

3.1Defender for Cloud and Microsoft Sentinel

Key points

Understand Microsoft Defender for Cloud, which assesses and strengthens cloud security posture, and Microsoft Sentinel, a cloud SIEM/SOAR that detects and responds to threats.

Microsoft provides solutions for both "is my current state secure (posture)" and "can I detect and respond to threats (operations)." The former is Defender for Cloud; the latter is Microsoft Sentinel.

3.1.1Two roles

Diagram contrasting Defender for Cloud (assess cloud security posture/CSPM, protect workloads, "are my resources secure?") with Microsoft Sentinel (cloud SIEM + SOAR: collect, detect, investigate, respond, "detect & respond to threats").
Posture assessment vs. threat response
  • Microsoft Defender for Cloud: assesses cloud security posture (CSPM) with recommendations and Secure Score, and protects servers/storage/DBs via cloud workload protection (CWPP); can also cover other clouds and on-prem.
  • Microsoft Sentinel: a cloud-native SIEM + SOAR; collects logs, then detects, investigates, and automatically responds to threats.

SIEM (Security Information and Event Management) centrally collects and analyzes logs from servers, network, identity, and more, using correlation rules to surface threat signs. SOAR (Security Orchestration, Automation and Response) automates post-detection response, running routine actions (disable accounts, isolate, notify) via playbooks. Microsoft Sentinel provides both in the cloud, finding attacks in massive logs and streamlining response. The key split: proactive posture = Defender for Cloud / live detection & response = Sentinel.

AspectDefender for CloudMicrosoft Sentinel
Main rolePosture assessment, workload protectionThreat detection/investigation/response
CategoryCSPM + CWPPSIEM + SOAR
Question"Are resources configured securely?""Is an attack happening; can we respond?"
Signature featureSecure Score, recommendationsLog correlation, playbooks
Example

Scenario: operations and monitoring. A security team uses Defender for Cloud’s Secure Score to fix recommendations like "unencrypted Storage" or "admins without MFA," raising posture. Meanwhile, signs of a real attack (a spike in suspicious sign-ins) are detected by Sentinel correlating logs, and a playbook automatically isolates and notifies the account. Prevention and response run together.

Warning

Watch the mix-ups: (1) Defender for Cloud (proactive posture = CSPM + workload protection) vs Sentinel (live detection/response = SIEM/SOAR). (2) SIEM = collect/analyze logs, SOAR = automate response—Sentinel has both. (3) Secure Score is a Defender for Cloud feature, not Sentinel’s.

Note

Q. CSPM vs CWPP? CSPM is posture management ("is the config secure?"); CWPP protects running workloads like servers and DBs. Defender for Cloud includes both. Q. Sentinel vs Defender XDR? Defender XDR (next section) does specialized detection/response per domain (endpoint, email, identity, apps); Sentinel is an organization-wide SIEM/SOAR collecting logs across everything—and they integrate.

Exam point

Common: assess posture/Secure Score = Defender for Cloud (CSPM+CWPP), SIEM/SOAR for log collection, detection, automated response = Microsoft Sentinel. SIEM = collect/analyze, SOAR = automate response.

Note

(For awareness) Microsoft Security Copilot: Recently, Microsoft Security Copilot arrived as a generative-AI assistant for security operations, working with Defender, Sentinel, Entra, and Purview to summarize incident investigations and suggest responses (Ignite 2025 announced built-in agents across these products). For SC-900, it is enough to be aware that AI assistance is being added to Microsoft security.

3.1.2Section summary

  • Defender for Cloud = posture assessment (CSPM, Secure Score)
  • Microsoft Sentinel = cloud SIEM/SOAR (detect/respond)

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Which service assesses cloud security posture and drives improvement via Secure Score?

Q2. Which cloud-native SIEM/SOAR collects logs and detects, investigates, and auto-responds to threats?

Q3. What does SOAR mainly provide?

Check your understandingPractice questions for Chapter 3: Microsoft Security Solutions