Which Source Appears on Microsoft Defender XDR Incidents Page?

Review and respond to security reports and alerts generated by Microsoft Defender XDR
Answer Correct answer: D — Microsoft Defender for Identity is the native Microsoft service source that appears on the Incidents page of the Microsoft 365 Defender portal.

You have a Microsoft 365 tenant. You plan to manage incidents in the tenant by using the Microsoft Defender XDR. Which Microsoft service source will appear on the Incidents page of the Microsoft 365 Defender portal?

  1. Microsoft Sentinel
  2. Microsoft Defender for Cloud
  3. Azure Web Application Firewall
  4. Microsoft Defender for Identity Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tested: identifying which Microsoft service natively surfaces incidents in the Microsoft 365 Defender portal; the trap is confusing Sentinel or Defender for Cloud, which require explicit connectors, with a built-in source like Defender for Identity.

Microsoft Defender XDR aggregates incidents from multiple Microsoft security services. This page establishes that Microsoft Defender for Identity is the correct native source appearing on the Incidents page of the Microsoft 365 Defender portal.

Choosing Microsoft Sentinel because it is a major security service; however, Sentinel only appears on the Incidents page if it is explicitly connected to Defender XDR, whereas Defender for Identity is a default integrated source.

Community Discussion (5 comments)

Ody 👍 3
D is the best answer. However, if connected, Sentinel will also.
BJS78 👍 3
"Alerts from different Microsoft security solutions like Microsoft Defender for Endpoint, Defender for Office 365, Microsoft Sentinel, Defender for Cloud, Defender for Identity, Defender for Cloud Apps, Defender XDR, App Governance, Microsoft Entra ID Protection, and Microsoft Data Loss Prevention appear here." https://learn.microsoft.com/en-us/defender-xdr/investigate-alerts?tabs=settings
Tr619899 👍 1
The correct answer is D. Microsoft Defender for Identity. Microsoft Defender XDR consolidates data from various Microsoft Defender services, and Microsoft Defender for Identity (formerly Azure Advanced Threat Protection) provides identity-based threat detection. Incidents related to identity threats will appear in the Incidents page of the Microsoft 365 Defender portal. Microsoft Sentinel and Defender for Cloud serve broader purposes outside the Microsoft 365 Defender portal, while Azure Web Application Firewall focuses on web application protection.
APK1 👍 2 Selected: D
Microsoft Defender for Identity is a cloud-based security solution that helps secure your identity monitoring across your organization.
Khattak3143 👍 2 Selected: D
Answer seems correct!

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Defender for Identity is a first-party Microsoft 365 Defender service that natively feeds identity-based alerts and incidents into the Microsoft 365 Defender portal. The question specifies a Microsoft 365 tenant managing incidents with Microsoft Defender XDR, and Defender for Identity is one of the core workload sources listed in the official documentation. As Ody commented, "D is the best answer. However, if connected, Sentinel will also," confirming that Sentinel requires an extra connection while Defender for Identity is inherently present. The community consensus (100% votes for D) aligns with the vendor's design: Defender for Identity incidents appear on the Incidents page without additional configuration. Therefore, D is the correct answer.

Why the Other Options Are Wrong

Option A (Microsoft Sentinel) is a cloud-native SIEM/SOAR that can be connected to Microsoft Defender XDR, but it is not a default Microsoft service source for the Incidents page in a standard Microsoft 365 tenant. Option B (Microsoft Defender for Cloud) is focused on Azure and hybrid cloud workloads, and its alerts are not natively surfaced in Defender XDR incidents unless integration is configured. Option C (Azure Web Application Firewall) is a network security service that does not generate incidents in the Microsoft 365 Defender portal. Only Defender for Identity is a built-in Microsoft 365 Defender component whose incidents appear automatically.

Community Comment Notes

BJS78 quoted the official Microsoft Learn page listing sources that appear on the Incidents page, including "Microsoft Defender for Identity" alongside Defender for Endpoint, Defender for Office 365, and others. Tr619899 affirmed that Defender for Identity provides identity-based threat detection and that its incidents appear in the portal. APK1 highlighted Defender for Identity's role in identity monitoring, reinforcing why it is the expected source. No commenter argued for Sentinel as the sole answer; Ody's note about Sentinel only applies when it is explicitly connected.

Official Reference

Exam Strategy

Focus on native Microsoft 365 Defender sources versus optional connectors. Questions often contrast built-in services like Defender for Identity with external SIEM or cloud security tools that require explicit integration.

Frequently Asked Questions

Why is Microsoft Sentinel not the correct answer here?

Sentinel only appears on the Incidents page when explicitly connected to Defender XDR; Defender for Identity is a default integrated source in a Microsoft 365 tenant.

Does Microsoft Defender for Cloud show incidents in the Defender XDR portal?

Defender for Cloud can integrate, but it is not a native Microsoft 365 Defender incident source by default, so it is not the expected answer for a standard tenant.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide