Connecting the Microsoft 365 app connector to enrich Cloud Discovery usernames with Entra ID UPNs
You have a Microsoft 365 subscription that uses Microsoft Defender for Cloud Apps and has Cloud Discovery enabled. You need to enrich the Cloud Discovery data. The solution must ensure that usernames in the Cloud Discovery traffic logs are associated with the user principal name (UPN) of the corresponding Microsoft Entra ID user accounts. What should you do first?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Cloud Discovery AAD/Entra enrichment requires the Microsoft 365 (formerly Office 365) app connector to be connected before usernames in traffic logs can be resolved to Entra ID UPNs.
To enrich Microsoft Defender for Cloud Apps Cloud Discovery data so discovered usernames map to Microsoft Entra ID UPNs, you must first connect the Microsoft 365 app connector, which is the prerequisite for Entra ID (Azure AD) enrichment of Cloud Discovery.
Choosing Conditional Access App Control user monitoring or an Azure app connector — neither is the prerequisite for resolving Cloud Discovery usernames to Entra ID UPNs; the Microsoft 365 app connector is.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Defender for Cloud Apps Cloud Discovery can enrich discovered usernames with their Microsoft Entra ID (Azure AD) UPNs, but the documented prerequisite is to connect the Microsoft 365 app connector first; without it the enrichment cannot resolve identities to Entra ID accounts.Why the Other Options Are Wrong
Conditional Access App Control user monitoring (A) governs app-access session control, not Cloud Discovery identity enrichment. An Azure app connector (D) is not the connector used for this Entra ID UPN enrichment. Automatic redirection to Microsoft 365 Defender (C) is unrelated to Cloud Discovery identity enrichment.Community Comment Notes
The community is unanimous (B 100). certinfra (10 likes) cites the cloud-discovery-aad-enrichment documentation and notes the Microsoft 365 app connector must be connected first, with sapphire and Vokuhila confirming B.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →