Which Source Appears on Microsoft Defender XDR Incidents Page?
You have a Microsoft 365 tenant. You plan to manage incidents in the tenant by using the Microsoft Defender XDR. Which Microsoft service source will appear on the Incidents page of the Microsoft 365 Defender portal?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tested: identifying which Microsoft service natively surfaces incidents in the Microsoft 365 Defender portal; the trap is confusing Sentinel or Defender for Cloud, which require explicit connectors, with a built-in source like Defender for Identity.
Microsoft Defender XDR aggregates incidents from multiple Microsoft security services. This page establishes that Microsoft Defender for Identity is the correct native source appearing on the Incidents page of the Microsoft 365 Defender portal.
Choosing Microsoft Sentinel because it is a major security service; however, Sentinel only appears on the Incidents page if it is explicitly connected to Defender XDR, whereas Defender for Identity is a default integrated source.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Defender for Identity is a first-party Microsoft 365 Defender service that natively feeds identity-based alerts and incidents into the Microsoft 365 Defender portal. The question specifies a Microsoft 365 tenant managing incidents with Microsoft Defender XDR, and Defender for Identity is one of the core workload sources listed in the official documentation. As Ody commented, "D is the best answer. However, if connected, Sentinel will also," confirming that Sentinel requires an extra connection while Defender for Identity is inherently present. The community consensus (100% votes for D) aligns with the vendor's design: Defender for Identity incidents appear on the Incidents page without additional configuration. Therefore, D is the correct answer.Why the Other Options Are Wrong
Option A (Microsoft Sentinel) is a cloud-native SIEM/SOAR that can be connected to Microsoft Defender XDR, but it is not a default Microsoft service source for the Incidents page in a standard Microsoft 365 tenant. Option B (Microsoft Defender for Cloud) is focused on Azure and hybrid cloud workloads, and its alerts are not natively surfaced in Defender XDR incidents unless integration is configured. Option C (Azure Web Application Firewall) is a network security service that does not generate incidents in the Microsoft 365 Defender portal. Only Defender for Identity is a built-in Microsoft 365 Defender component whose incidents appear automatically.Community Comment Notes
BJS78 quoted the official Microsoft Learn page listing sources that appear on the Incidents page, including "Microsoft Defender for Identity" alongside Defender for Endpoint, Defender for Office 365, and others. Tr619899 affirmed that Defender for Identity provides identity-based threat detection and that its incidents appear in the portal. APK1 highlighted Defender for Identity's role in identity monitoring, reinforcing why it is the expected source. No commenter argued for Sentinel as the sole answer; Ody's note about Sentinel only applies when it is explicitly connected.Official Reference
Exam Strategy
Focus on native Microsoft 365 Defender sources versus optional connectors. Questions often contrast built-in services like Defender for Identity with external SIEM or cloud security tools that require explicit integration.
Frequently Asked Questions
Why is Microsoft Sentinel not the correct answer here?
Sentinel only appears on the Incidents page when explicitly connected to Defender XDR; Defender for Identity is a default integrated source in a Microsoft 365 tenant.
Does Microsoft Defender for Cloud show incidents in the Defender XDR portal?
Defender for Cloud can integrate, but it is not a native Microsoft 365 Defender incident source by default, so it is not the expected answer for a standard tenant.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →