Using Defender for Identity to mark a sensitive AD group and alert in Sentinel
Your on-premises network contains an Active Directory Domain Services (AD DS) domain and a hybrid deployment between a Microsoft Exchange Server 2019 organization and an Exchange Online tenant. The AD DS domain contains a group named Group1. Group1 is a member of the Organization Management role group for the Exchange deployment. You have a Microsoft 365 E5 subscription that uses Microsoft Defender. You have an Azure subscription that uses Microsoft Sentinel. You need to recommend a solution to ensure that Group1 is marked as a sensitive group and that any changes made to Group1 raises an alert in Microsoft Sentinel. The solution must minimize administrative effort. What should you include in the recommendation?
Community Votes
80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Defender for Identity monitors on-premises AD DS, lets you designate sensitive groups such as Org Management, and integrates with Sentinel for alerts; PIM and Entra ID Protection do not cover on-prem AD DS group changes.
To mark an on-premises AD DS group (Organization Management) as sensitive and raise a Sentinel alert on changes with minimal effort, use Microsoft Defender for Identity, which monitors AD DS, flags sensitive groups, and feeds signals to Defender XDR/Sentinel.
Choosing PIM (C) — PIM governs Entra ID role eligibility, not on-premises AD DS group membership changes, which is what Defender for Identity monitors.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Defender for Identity monitors on-premises Active Directory, can mark high-privilege groups such as Exchange Organization Management as sensitive, and surfaces alerts that flow into Microsoft Defender XDR and Microsoft Sentinel, meeting the requirement with minimal effort.Why the Other Options Are Wrong
Microsoft Entra PIM (C) and Entra ID Protection (B) operate on Entra ID, not on on-premises AD DS group membership. Defender for Office 365 (D) protects email, not AD DS group changes. Therefore Defender for Identity (A) is the only option that covers on-prem AD DS sensitive-group monitoring and Sentinel alerting.Community Comment Notes
The community favored A (80 votes). Comments note that the Exchange hybrid means the Org Management group is synced from on-prem and must be protected by Defender for Identity; a minority (C, 20 votes) suggested PIM, which does not cover on-prem AD DS.Official Reference
Related Analysis
Practice All SC-100 Questions
Access 110 questions with complete answers and detailed explanations.
View Full SC-100 Practice Test →