Create and connect workspaces in Microsoft Sentinel (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
   --> Implement activity and event collection in Microsoft Sentinel
      --> Create and connect workspaces in Microsoft Sentinel

Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) platform that collects security data from cloud, on-premises, and other environments and uses that data for detection, investigation, threat hunting, and response.

A fundamental part of implementing Microsoft Sentinel is understanding its workspace architecture. Microsoft Sentinel is deployed to a Log Analytics workspace, which provides the underlying data store for the logs and events that Sentinel analyzes.

For the SC-500 exam, you should understand not only how to create a workspace, but also how to decide on an appropriate workspace architecture, how Microsoft Sentinel is connected to a workspace, how permissions affect access, and when multiple workspaces or tenants may be appropriate.

Microsoft’s current training module specifically identifies three core objectives for this area:

  • Describe Microsoft Sentinel workspace architecture.
  • Onboard a Microsoft Sentinel workspace to Microsoft Defender.
  • Manage a Microsoft Sentinel workspace in Microsoft Defender.

1. Understanding the Microsoft Sentinel Workspace

The most important concept to remember is:

Microsoft Sentinel is added to a Log Analytics workspace.

A Log Analytics workspace is an Azure resource that stores and organizes log data. Microsoft Sentinel adds SIEM capabilities to that workspace, allowing security teams to analyze the collected data and build security operations processes around it.

A simplified architecture looks like this:

                    Data Sources
                         |
          +--------------+--------------+
          |              |              |
       Azure          Microsoft      On-premises
      Resources       Services        Systems
          |              |              |
          +--------------+--------------+
                         |
                         v
                Data Connectors
                         |
                         v
              +----------------------+
              |  Log Analytics      |
              |     Workspace       |
              |                      |
              |  Logs / Events       |
              |  Tables              |
              |  Security Data       |
              +----------+-----------+
                         |
                  Microsoft Sentinel
                         |
          +--------------+--------------+
          |              |              |
       Analytics       Incidents      Hunting
         Rules                        & KQL
          |              |              |
          +--------------+--------------+
                         |
                  Investigation &
                     Response

The workspace therefore provides the underlying location for Sentinel data, while Sentinel supplies the security operations capabilities.

Microsoft’s current onboarding guidance confirms that Microsoft Sentinel must be added to a Log Analytics workspace. An existing Log Analytics workspace can be used, or a new one can be created before Sentinel is enabled.


2. Why Workspace Architecture Matters

The choice of workspace architecture can have a major impact on:

  • Security operations
  • Data isolation
  • Access control
  • Data residency
  • Regulatory requirements
  • Retention requirements
  • Cost
  • Administration
  • Cross-workspace monitoring
  • Cross-tenant operations

For many organizations, a single workspace is sufficient and simpler to manage.

However, there are circumstances in which multiple workspaces make sense.

Microsoft’s current deployment guidance recommends evaluating factors such as the number of tenants, compliance and data-storage requirements, access-control requirements, and the organization’s data sources before determining the appropriate architecture.

Example

Consider a company with three business divisions:

Contoso Corporation
|
+-----+-----+
| |
Finance Healthcare
| |
Workspace A Workspace B
+
|
Retail
|
Workspace C

The organization might decide to use separate workspaces because different divisions have:

  • Different regulatory requirements
  • Different data-retention requirements
  • Different security teams
  • Different access requirements

However, multiple workspaces introduce additional management complexity.

Exam Tip: If a question does not provide a compelling reason for multiple workspaces, do not automatically assume that multiple workspaces are the better design.


3. Single-Workspace Architecture

A single-workspace architecture places the organization’s Microsoft Sentinel data into one Log Analytics workspace.

For example:

Azure Resources
Microsoft 365
On-premises Servers
Network Devices
Third-party Applications
|
v
+-------------------------+
| Log Analytics Workspace |
| |
| Microsoft Sentinel |
+-------------------------+

Advantages

A single workspace can simplify:

  • Data management
  • KQL queries
  • Analytics rules
  • Incident investigation
  • Workbooks
  • Automation
  • Permissions
  • Administration

Microsoft currently recommends a single-workspace environment when practical, while recognizing that specific organizational requirements can justify multiple workspaces.

When it is especially attractive

A single workspace is often appropriate when:

  • The organization has a single Microsoft Entra tenant.
  • Security teams need centralized visibility.
  • Data does not need to be separated for regulatory reasons.
  • Different business units do not require strong data isolation.
  • A common retention strategy is acceptable.

4. Multiple-Workspace Architecture

Some organizations need multiple Log Analytics workspaces with Microsoft Sentinel enabled.

Examples include:

  • Large enterprises
  • Managed Security Service Providers (MSSPs)
  • Organizations with multiple Microsoft Entra tenants
  • Organizations with different regulatory boundaries
  • Organizations requiring different retention policies
  • Organizations requiring strong separation between business units

Microsoft supports cross-workspace and cross-tenant Sentinel architectures for these scenarios.

For example:

                 Central SOC
                     |
        +------------+------------+
        |            |            |
        v            v            v
   Workspace A  Workspace B  Workspace C
     Finance      Retail       Europe

The security operations team can maintain centralized visibility while allowing each environment to retain its own workspace.


5. Primary and Secondary Workspaces

Current Microsoft Sentinel architecture in the Microsoft Defender portal supports a primary workspace and multiple secondary workspaces for a tenant.

Microsoft defines a workspace in this context as a Log Analytics workspace with Microsoft Sentinel enabled.

This distinction is important because some tenant-level Microsoft security integrations operate through the primary workspace.

For example, in a multiple-workspace environment, the Microsoft Defender XDR connector is connected to the primary workspace. Certain standalone Microsoft security-product connectors are consequently handled differently in secondary workspaces to prevent duplicate tenant-based alerts.

Exam Tip

If a question asks about the primary workspace, think about the workspace that provides the central Sentinel context for the tenant, particularly for supported Microsoft security integrations.


6. Creating a Log Analytics Workspace

Before Microsoft Sentinel can be deployed, you need a Log Analytics workspace.

At a high level, the process is:

  1. Select the Azure subscription.
  2. Select or create a resource group.
  3. Specify the Log Analytics workspace name.
  4. Select an appropriate region.
  5. Configure the required workspace settings.
  6. Validate the configuration.
  7. Create the workspace.

Microsoft’s current onboarding process explicitly follows this model: create or select a Log Analytics workspace, choose its subscription/resource group and region, and deploy it before adding Microsoft Sentinel.

Workspace location matters

The workspace’s Azure region can matter for:

  • Data residency
  • Regulatory requirements
  • Performance
  • Organizational policies
  • Integration requirements

Therefore, selecting the region should be treated as an architectural decision rather than simply choosing the closest Azure region.


7. Adding Microsoft Sentinel to the Workspace

Once the Log Analytics workspace exists, Microsoft Sentinel can be added to it.

Conceptually:

Step 1
Create Log Analytics Workspace
|
v
Step 2
Add Microsoft Sentinel
|
v
Step 3
Configure Data Connectors
|
v
Step 4
Configure Security Content
|
v
Step 5
Begin Monitoring

The resulting relationship is:

Log Analytics Workspace
|
+-- Microsoft Sentinel
|
+-- Logs
+-- Tables
+-- Security Events
+-- Data

Microsoft’s current quickstart describes this as adding Microsoft Sentinel to an existing Log Analytics workspace.


8. Connecting a Workspace to Microsoft Defender

Microsoft Sentinel can be accessed and managed through the Microsoft Defender portal, providing a unified security operations experience.

For a single-workspace deployment, the prerequisite is a Log Analytics workspace with Microsoft Sentinel enabled, together with the appropriate permissions.

In the Defender portal, administrators can connect an existing Sentinel workspace.

The current workflow includes:

  1. Open the Microsoft Defender portal.
  2. Navigate to the Microsoft Sentinel settings.
  3. View the available Sentinel workspaces.
  4. Select the workspace.
  5. Connect the workspace.
  6. Where applicable, designate it as the primary workspace.

For current Defender-portal deployments, Microsoft describes a workspace as a Log Analytics workspace with Microsoft Sentinel enabled.


9. Azure Portal Versus Microsoft Defender Portal

This is an important current-state exam consideration.

Microsoft is transitioning Microsoft Sentinel toward the Microsoft Defender portal.

Microsoft currently states that after March 31, 2027, Microsoft Sentinel will no longer be supported in the Azure portal and will be available only through the Microsoft Defender portal. Microsoft also recommends that organizations using Sentinel in the Azure portal begin planning the transition.

Therefore, you may encounter documentation and questions involving both experiences during the transition.

The underlying architectural concept remains the same:

Microsoft Sentinel operates on top of a Log Analytics workspace.


10. Workspace Resource Groups

A resource group can be used to organize the Azure resources associated with Microsoft Sentinel.

For example:

Security Resource Group
|
+-- Log Analytics Workspace
|
+-- Microsoft Sentinel
|
+-- Supporting Security Resources
|
+-- Workbooks
|
+-- Other Sentinel Resources

Keeping Sentinel-related resources organized can simplify:

  • RBAC assignments
  • Resource management
  • Governance
  • Administration
  • Lifecycle management

Microsoft’s current unified security operations deployment guidance recommends placing Microsoft Sentinel-related resources in a common security resource group when appropriate and assigning Sentinel permissions at the resource-group level to simplify administration.


11. Microsoft Sentinel Roles and Permissions

Security teams should use Azure role-based access control (RBAC) to provide users with only the access they need.

Common Sentinel-specific roles include:

RoleGeneral purpose
Microsoft Sentinel ReaderView Sentinel resources and data
Microsoft Sentinel ResponderRespond to incidents and perform appropriate response actions
Microsoft Sentinel ContributorManage Sentinel resources and security content
Microsoft Sentinel Playbook OperatorManage or execute applicable playbook operations
Log Analytics ReaderRead Log Analytics data
Log Analytics ContributorManage Log Analytics resources and configurations

The exact permissions required depend on the operation being performed.

For example, an analyst who only needs to view Sentinel information should not automatically be given Contributor permissions.

Microsoft’s current guidance identifies the Microsoft Sentinel Reader role as the minimum Sentinel-specific permission for an analyst who only needs to view Microsoft Sentinel data.


12. Least Privilege Is Important

The principle of least privilege is particularly important in a SIEM because Sentinel can expose highly sensitive security information.

Consider these users:

UserAppropriate access
SOC analystReader or appropriate incident-response permissions
Incident responderResponder
Sentinel administratorContributor
Security architectPermissions based on required administrative duties
AuditorRead-only access

Avoid giving every security employee Contributor or Owner permissions.

Exam Tip: When a question asks how to give an analyst access while minimizing privileges, look for a read-oriented RBAC role, not Owner or Contributor.


13. Connecting Data Sources

Creating a workspace does not automatically populate it with security data.

You must configure data connectors to ingest data from the systems you want Microsoft Sentinel to monitor.

Examples include:

  • Azure resources
  • Microsoft Entra ID
  • Microsoft Defender products
  • Windows systems
  • Linux systems
  • Network devices
  • Third-party security products
  • Cloud platforms
  • Applications

Conceptually:

Microsoft Entra ID ----+
Azure Activity --------+
Microsoft Defender ----+
Windows ---------------+----> Microsoft Sentinel
Linux -----------------+
Firewall --------------+
Third-party Apps ------+

Data connectors establish the path by which security data enters the Sentinel environment.


14. Data Retention

Retention is another important workspace design consideration.

Organizations should determine how long security data needs to remain available for:

  • Threat investigation
  • Threat hunting
  • Incident response
  • Compliance
  • Forensics
  • Historical analysis

Retention requirements can differ between organizations and even between different categories of data.

Microsoft’s current Sentinel onboarding guidance notes that organizations should configure appropriate data-retention and archive policies in Azure Monitor Logs.

Important distinction

Do not confuse:

  • Workspace retention
  • Archive/long-term retention
  • Data ingestion
  • Data connector configuration

These are related but separate concepts.


15. Managing Multiple Tenants

Large organizations and MSSPs may need to monitor Sentinel workspaces across multiple Microsoft Entra tenants.

Azure Lighthouse can provide delegated management capabilities across tenants.

For example:

                    Central SOC
                        |
                  Azure Lighthouse
                        |
        +---------------+---------------+
        |               |               |
        v               v               v
    Tenant A         Tenant B        Tenant C
        |               |               |
    Sentinel         Sentinel        Sentinel
    Workspace        Workspace       Workspace

This can be useful for:

  • MSSPs
  • Global organizations
  • Organizations with multiple Entra tenants
  • Central security operations teams

Azure Lighthouse supports management of multiple Sentinel workspaces across tenants, including scenarios involving cross-workspace queries, workbooks, and security operations.


16. When Should You Use Multiple Workspaces?

A common exam scenario is determining whether an organization should use one workspace or several.

Consider multiple workspaces when there is a meaningful requirement such as:

Regulatory separation

Different jurisdictions may have different data requirements.

Different security boundaries

Separate business units may need strict separation.

Different retention requirements

One organization might require different retention periods for different data sets.

Multiple tenants

A global organization may operate multiple Microsoft Entra tenants.

MSSP scenarios

An MSSP may manage Sentinel environments belonging to multiple customers.

Data ownership

Different organizations or subsidiaries may need to maintain control over their own security data.

Microsoft’s current guidance highlights scenarios such as MSSPs, global SOCs, multiple tenants, granular access control, data privacy, and regulatory compliance as reasons a multiple-workspace architecture may be appropriate.


17. When Should You Avoid Multiple Workspaces?

Multiple workspaces introduce complexity.

They can complicate:

  • Queries
  • Analytics rules
  • Workbooks
  • Data management
  • Permissions
  • Administration
  • Investigations
  • Content deployment

Therefore, don’t create separate workspaces simply because different departments exist.

Instead, ask:

Is there a security, compliance, operational, or architectural reason to separate the data?

If the answer is no, a single workspace may be simpler.


18. Workspace Architecture Decision Matrix

RequirementLikely approach
Small organization with centralized SOCSingle workspace
One tenant and centralized securitySingle workspace
Different regulatory boundariesMultiple workspaces may be appropriate
Multiple Entra tenantsMultiple workspaces may be appropriate
MSSP managing customer environmentsMultiple workspaces/tenants
Different data-retention requirementsMultiple workspaces may be appropriate
Need strict business-unit isolationMultiple workspaces may be appropriate
No compelling separation requirementPrefer simpler single-workspace design

The important exam principle is:

Choose the simplest architecture that satisfies the organization’s requirements.


19. Workspace Manager

For organizations operating multiple Sentinel workspaces, Microsoft provides capabilities to manage workspaces at scale.

Workspace Manager can be used to centrally manage member workspaces and organize them into groups based on factors such as:

  • Business unit
  • Geography
  • Organizational structure
  • Other operational requirements

Microsoft’s current documentation describes onboarding member workspaces and organizing them into workspace-manager groups for centralized management.

This is different from simply creating multiple workspaces. The purpose is to make the resulting environment easier to manage consistently.


20. Multiple-Workspace Incident Management

Security teams may need to investigate incidents across multiple Sentinel workspaces.

Microsoft provides multiple-workspace capabilities for this purpose.

For example:

Workspace A ----+
Workspace B ----+----> Central SOC
Workspace C ----+
Workspace D ----+

Current multiple-workspace functionality allows security teams to view incidents from multiple workspaces and, where supported, across tenants. Microsoft currently documents a maximum of 100 concurrently displayed workspaces in the multiple-workspace incident view.

However, permissions still matter. A user needs the appropriate permissions on the workspaces involved in an operation.


21. Connecting Versus Ingesting Data

One of the most important conceptual distinctions is:

Connecting a workspace to Microsoft Sentinel is not the same thing as connecting a data source to Sentinel.

For example:

Log Analytics Workspace
|
+-- Microsoft Sentinel
|
+-- Data Connector: Azure Activity
+-- Data Connector: Entra ID
+-- Data Connector: Defender XDR
+-- Data Connector: Firewall

The workspace provides the foundation.

Data connectors bring security information into that foundation.

This distinction frequently appears in certification questions.


22. A Typical Deployment Sequence

A practical deployment can follow this sequence:

Step 1 — Plan the architecture

Determine:

  • Number of tenants
  • Number of workspaces
  • Data residency
  • Regulatory requirements
  • Retention
  • Access control
  • Security operations structure

Step 2 — Create or identify a Log Analytics workspace

Select:

  • Subscription
  • Resource group
  • Region
  • Workspace configuration

Step 3 — Enable Microsoft Sentinel

Add Microsoft Sentinel to the Log Analytics workspace.

Step 4 — Connect the workspace to Microsoft Defender

For organizations using the unified Defender experience, connect the workspace and configure its role in the Defender portal.

Step 5 — Configure permissions

Apply appropriate Azure RBAC roles.

Step 6 — Configure data connectors

Connect the required data sources.

Step 7 — Configure retention

Set appropriate retention and archive policies.

Step 8 — Deploy security content

Configure:

  • Analytics rules
  • Workbooks
  • Automation rules
  • Playbooks
  • Watchlists
  • Other Sentinel content

Step 9 — Validate data ingestion

Confirm that expected events are arriving in the workspace.


23. Common Mistakes

Mistake 1: Assuming Sentinel is a standalone Log Analytics replacement

It isn’t.

Microsoft Sentinel is added to a Log Analytics workspace.


Mistake 2: Creating a new workspace without evaluating existing ones

An organization may already have an appropriate Log Analytics workspace.

Creating unnecessary workspaces can increase operational complexity.


Mistake 3: Assuming one workspace is always correct

Single-workspace architecture is often simpler, but regulatory, organizational, tenant, or operational requirements can justify multiple workspaces.


Mistake 4: Giving analysts excessive permissions

An analyst who only needs to view data does not necessarily need Contributor or Owner permissions.


Mistake 5: Assuming that enabling Sentinel automatically collects all security data

Data connectors must be configured for the relevant data sources.


Mistake 6: Confusing workspace architecture with data connectors

Workspace architecture determines where Sentinel data is organized and managed.

Data connectors determine how particular data sources send data to Sentinel.


Mistake 7: Ignoring data residency

The workspace’s region can be an important architectural and compliance consideration.


24. Key Exam Comparisons

ConceptRemember
Log Analytics workspaceUnderlying workspace used by Sentinel
Microsoft SentinelSIEM/security operations capabilities
Data connectorBrings data from a source into Sentinel
Analytics ruleDetects patterns or conditions in data
IncidentSecurity case generated from alerts/detections
Single workspaceSimpler centralized architecture
Multiple workspacesUsed when separation or organizational requirements justify it
Primary workspaceCentral Sentinel workspace in supported Defender portal multi-workspace scenarios
Azure LighthouseHelps manage resources across tenants
RBACControls user access to Sentinel resources/data
RetentionDetermines how long data remains available
Defender portalCurrent unified experience for Microsoft security operations

25. Exam-Focused Scenario

Scenario

A multinational company has:

  • Three Microsoft Entra tenants
  • Separate security teams for each tenant
  • Different regulatory requirements
  • A central SOC that needs visibility across all environments

Which architecture is most appropriate?

The strongest answer would generally involve multiple Sentinel workspaces aligned with the tenant/security requirements, combined with centralized management capabilities.

Why?

Because the organization has legitimate architectural reasons for separation:

  • Multiple tenants
  • Different security boundaries
  • Regulatory requirements
  • Centralized SOC requirements

This is substantially different from a company with one tenant and one centralized security team that has no data-isolation requirements.


26. SC-500 Exam Tips

Exam Tip 1: Remember the relationship:

Log Analytics workspace → Microsoft Sentinel

Exam Tip 2: If the question asks where Sentinel stores/analyzes its collected log data, think Log Analytics workspace.

Exam Tip 3: If the question asks how data enters Sentinel, think data connectors.

Exam Tip 4: If the question asks whether to use one or multiple workspaces, look for requirements involving regulatory boundaries, data residency, access isolation, multiple tenants, MSSP operations, or different retention requirements.

Exam Tip 5: If the requirement is simply centralized security operations without a compelling separation requirement, a single workspace is often the simpler design.

Exam Tip 6: Remember that Microsoft Sentinel can be managed through the Microsoft Defender portal, and Microsoft’s current roadmap is moving Sentinel away from the Azure portal experience.

Exam Tip 7: Don’t confuse Azure Lighthouse with Microsoft Sentinel itself. Lighthouse provides delegated management capabilities across tenants; it is not the Sentinel data store.

Exam Tip 8: Apply least privilege. A user who only needs to view Sentinel data generally shouldn’t receive Contributor or Owner access.


27. Key Takeaways

The most important concepts to remember for the SC-500 exam are:

  1. Microsoft Sentinel is added to a Log Analytics workspace.
  2. A Log Analytics workspace provides the underlying location for Sentinel data.
  3. Sentinel provides SIEM and security operations capabilities on that data.
  4. Data connectors bring data from individual sources into Sentinel.
  5. A single workspace is often the simplest architecture.
  6. Multiple workspaces can be appropriate for regulatory, security, organizational, tenant, or operational reasons.
  7. Microsoft Defender supports managing Sentinel workspaces through its unified security operations experience.
  8. Azure Lighthouse can help manage Sentinel environments across multiple tenants.
  9. Azure RBAC should be used to implement least-privilege access.
  10. Workspace region, data retention, and data residency should be considered during architecture planning.
  11. Creating a workspace and configuring data connectors are separate activities.
  12. Current Microsoft Sentinel architecture supports primary and secondary workspace concepts in the Defender portal for applicable multi-workspace scenarios.
  13. Avoid unnecessary workspace proliferation because multiple workspaces increase operational complexity.

Practice Exam Questions

Question 1

A company is implementing Microsoft Sentinel for the first time. The security team wants to use an existing Azure Monitor Logs environment as the foundation for Sentinel.

What should the team use?

A. An existing Log Analytics workspace

B. An Azure Storage account

C. An Azure Key Vault

D. An Azure Data Explorer cluster

Answer: A

Explanation

Microsoft Sentinel is added to a Log Analytics workspace. The organization does not need to create a separate Sentinel-specific data store. An existing suitable Log Analytics workspace can be used.

Azure Storage, Key Vault, and Azure Data Explorer serve different purposes and are not the underlying workspace required for a standard Microsoft Sentinel deployment.


Question 2

An organization has one Microsoft Entra tenant, one centralized SOC, no special regulatory separation requirements, and no requirement for separate data-retention policies.

Which workspace architecture should the security architect consider first?

A. One workspace for every Azure subscription

B. One workspace for every department

C. A single Microsoft Sentinel workspace

D. A separate workspace for every data connector

Answer: C

Explanation

There is no stated requirement that justifies separating the environment. A single workspace generally provides a simpler architecture for centralized security operations.

Creating unnecessary workspaces increases administrative and operational complexity. Microsoft currently recommends a single-workspace environment when practical.


Question 3

A multinational organization has separate Microsoft Entra tenants for its European and North American operations. The organization also has different regulatory requirements governing security data in each environment.

What is the strongest reason to consider multiple Microsoft Sentinel workspaces?

A. To allow users to run different versions of KQL

B. To provide appropriate separation for tenant and regulatory requirements

C. To eliminate the need for data connectors

D. To prevent Microsoft Sentinel from using Log Analytics

Answer: B

Explanation

Multiple tenants and different regulatory requirements are legitimate reasons to consider multiple workspaces. Workspace architecture can provide separation of data, access, and operational boundaries while still allowing centralized security operations where appropriate.

The other answers incorrectly describe the purpose of multiple workspaces.


Question 4

A security administrator creates a new Log Analytics workspace but cannot find any security events in Microsoft Sentinel.

What should the administrator do next?

A. Create an Azure Storage account

B. Assign every analyst the Owner role

C. Configure the appropriate Microsoft Sentinel data connectors

D. Delete and recreate the Log Analytics workspace

Answer: C

Explanation

Creating the workspace and enabling Sentinel does not automatically cause every desired security data source to send data to Sentinel. The appropriate data connectors must be configured.

For example, Azure Activity data requires the corresponding connector and configuration to begin sending events to Sentinel.


Question 5

A security analyst only needs to view Microsoft Sentinel data and investigate information without administering Sentinel configuration.

Which approach best follows least-privilege principles?

A. Assign Azure Owner

B. Assign Microsoft Sentinel Reader

C. Assign Microsoft Sentinel Contributor

D. Assign Subscription Administrator

Answer: B

Explanation

The Microsoft Sentinel Reader role is designed for read access and is appropriate when the user needs to view Sentinel information without requiring broad administrative permissions.

Giving the analyst Owner, Contributor, or subscription-level administrative permissions would provide substantially more access than required. Microsoft’s current unified security operations guidance identifies Sentinel Reader as the minimum Sentinel-specific permission for an analyst who only needs to view Sentinel data.


Question 6

A company is deciding whether to create separate Sentinel workspaces for each business unit. All business units:

  • Use the same Microsoft Entra tenant.
  • Have the same regulatory requirements.
  • Use the same retention requirements.
  • Are monitored by the same SOC.

What should the architect generally do?

A. Prefer a single workspace unless another requirement justifies separation

B. Create a workspace for every business unit

C. Create a workspace for every data source

D. Create a workspace for every security analyst

Answer: A

Explanation

There is no stated requirement for data or security separation. A single workspace can simplify queries, administration, security operations, and data management.

Multiple workspaces should be introduced when there is a meaningful architectural reason, rather than simply because an organization has multiple departments.


Question 7

An MSSP needs to manage Microsoft Sentinel workspaces belonging to multiple customer Microsoft Entra tenants. The MSSP wants delegated cross-tenant management capabilities.

Which Azure service is most appropriate?

A. Azure Key Vault

B. Azure Policy

C. Microsoft Entra ID Protection

D. Azure Lighthouse

Answer: D

Explanation

Azure Lighthouse provides delegated management capabilities across Azure tenants and can be used to manage multiple Microsoft Sentinel environments at scale.

This is particularly relevant to MSSP scenarios in which a central SOC needs to manage Sentinel environments belonging to multiple customers.


Question 8

Which statement best describes the relationship between Microsoft Sentinel and a Log Analytics workspace?

A. Microsoft Sentinel replaces the Log Analytics workspace

B. A Log Analytics workspace is optional when Sentinel is deployed

C. Microsoft Sentinel is enabled on a Log Analytics workspace

D. Log Analytics is only used for storing archived Sentinel data

Answer: C

Explanation

Microsoft Sentinel is added to a Log Analytics workspace. The workspace provides the underlying environment for the data Sentinel analyzes.

This relationship is fundamental to Sentinel architecture and is one of the most important concepts to remember for the exam.


Question 9

An organization has several Sentinel workspaces because of regulatory and organizational requirements. The central SOC needs to monitor incidents across those workspaces.

Which capability is designed for this scenario?

A. Multiple-workspace capabilities

B. Azure Key Vault

C. Azure Bastion

D. Microsoft Defender Vulnerability Management

Answer: A

Explanation

Microsoft Sentinel provides multiple-workspace capabilities that allow security teams to work across multiple Sentinel workspaces. Current functionality supports viewing incidents across selected workspaces and, in supported scenarios, across tenants.

The other services address different security requirements.


Question 10

An organization has connected its Sentinel workspace to the Microsoft Defender portal. The security team now wants to start receiving logs from Microsoft Entra ID.

Which statement is correct?

A. Connecting the workspace automatically enables every available security data source

B. The appropriate data connector must be configured

C. A second Sentinel workspace must be created

D. Azure Lighthouse must be configured

Answer: B

Explanation

Connecting or onboarding the Sentinel workspace establishes the Sentinel environment, but individual data sources still need to be configured appropriately.

Data connectors provide the mechanisms for bringing data from services and applications into Microsoft Sentinel.

Therefore, the team should configure the appropriate Microsoft Entra ID data connector rather than create another workspace or configure Azure Lighthouse.


Go to the SC-500 Exam Prep Hub main page

Leave a Reply