← SC-500: cloud and AI security
06 / 6 · 40 MIN

Posture, Sentinel, and evidence

Prioritize risk and establish collection, automation, and reporting limits.

Concept and mechanism

A recommendation list needs context. Attack paths connect exposure, vulnerability, privileges, and critical assets to guide remediation order. Closing many easy items does not establish reduction of the most relevant risk. Compliance assessment should distinguish observed scope, automated controls, and manual evidence; a green dashboard does not award organizational certification. Connecting AWS to Defender for Cloud also does not prove every capability is active: check required plans, permissions, and components. Record coverage and resources that remain outside it.

Guided application

When changing a custom table schema, coordinate and validate the DCRs feeding it. In a CEF pipeline, establish arrival at the forwarder, AMA processing, DCR association and filters, destination, and recent table events. Connector health and an end-to-end check help interpret falling alert counts. Define analytics and total retention around query access, retrieval, and cost per table. Sentinel automation needs service authorization to run playbooks in addition to the rights of the person editing the rule. Security Copilot platform roles are separate from Microsoft plugin permissions. In Defender for AI Services, disabling prompt evidence masks content in alerts without disabling all analysis. In fictional reporting after maintenance, communicate the collection gap and limit conclusions to the period actually observed.

IN PRACTICE

Zero alerts plus zero recent events after maintenance requires investigating collection before announcing improvement.

Common pitfalls

Count as risk; configuration as execution evidence; retention as immediate querying; Copilot as universal access; empty table as absence of threats.

Related topics: Identity, access, and governance · Storage, SQL, and keys · Private networks and diagnosis

Take this idea with you

Explain evidence coverage before drawing security conclusions.

Create account

Reference: Connector health monitoring · SC-500 guide updated 2026-05-13; Microsoft security documentation accessed 2026-09-30