← SC-900: security, identity, and operational decisions
04 / 6 · 40 MIN

Posture, detection, and response

Connect recommendations, signals, and response to operational impact.

Concept and mechanism

Posture and detection answer different questions. CSPM identifies configurations and exposures to improve; workload protection addresses threats to covered resources. Defender for Cloud brings together capabilities in these areas, with plans and integrations to confirm. Defender XDR connects signals across products to help understand incident sequence and scope. Visibility depends on licensed, provisioned services with available data. Defender for Office 365 covers email and collaboration; Defender for Endpoint covers devices; Defender for Identity uses on-premises identity signals; Defender for Cloud Apps adds visibility and control for SaaS applications. A shared interface does not automatically make every data source available.

Guided application

In a fictional SOC, Sentinel receives integrated sources and supports SIEM correlation. Automation rules and playbooks support SOAR, but impactful actions need boundaries, permissions, and validation. Indiscriminately isolating batch servers for every weak alert can turn noise into unavailability. Start by assessing precision, dependencies, and conditions for human approval. Preserve evidence and communicate confirmed facts, hypotheses, and next actions. Also update access runbooks: inspected documentation schedules the end of Sentinel support in the Azure portal after 2027-03-31 while retaining the service in the Defender portal. A portal change is not service retirement, and onboarding varies with tenant circumstances.

Threat context and remediation priority

Threat intelligence adds campaign, infrastructure, and indicator context to an investigation. A domain linked to a campaign deserves analysis but does not alone prove an application is compromised. In a fictional funds portal, correlate the indicator with time, process, and the control outcome. The July guide names Defender Threat Intelligence; current documentation describes the integrated Defender experience, including preview capabilities. Confirm tenant availability. Defender Vulnerability Management helps prioritize remediation using exposure, threat, and asset-criticality context. A recommendation still requires execution and validation. At a change committee, distinguish vulnerability risk, remediation impact, and the evidence required to close the action.

IN PRACTICE

An email alert and an endpoint alert can belong to one incident; the connection needs evidence.

Common pitfalls

Dashboard as complete coverage; correlation as attribution proof; automation without impact review; old runbook dates.

Related topics: Classification, DLP, and retention · Evidence, investigation, and compliance

Take this idea with you

Understand signal coverage and bound action impact.

Create account

Reference: Microsoft Sentinel · SC-900 objectives 2026-07-28; October 2026 update announced