Connecting the Microsoft 365 app connector to enrich Cloud Discovery usernames with Entra ID UPNs

Topic 4
Answer Correct answer: B — Connecting the Microsoft 365 app connector is the prerequisite for enriching Cloud Discovery usernames with Entra ID UPNs.

You have a Microsoft 365 subscription that uses Microsoft Defender for Cloud Apps and has Cloud Discovery enabled. You need to enrich the Cloud Discovery data. The solution must ensure that usernames in the Cloud Discovery traffic logs are associated with the user principal name (UPN) of the corresponding Microsoft Entra ID user accounts. What should you do first?

  1. From Conditional Access App Control, configure User monitoring.
  2. Create a Microsoft 365 app connector. Correct Answer
  3. Enable automatic redirection to Microsoft 365 Defender.
  4. Create an Azure app connector.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Cloud Discovery AAD/Entra enrichment requires the Microsoft 365 (formerly Office 365) app connector to be connected before usernames in traffic logs can be resolved to Entra ID UPNs.

To enrich Microsoft Defender for Cloud Apps Cloud Discovery data so discovered usernames map to Microsoft Entra ID UPNs, you must first connect the Microsoft 365 app connector, which is the prerequisite for Entra ID (Azure AD) enrichment of Cloud Discovery.

Choosing Conditional Access App Control user monitoring or an Azure app connector — neither is the prerequisite for resolving Cloud Discovery usernames to Entra ID UPNs; the Microsoft 365 app connector is.

Community Discussion (3 comments)

certinfra 👍 10
Microsoft 365 app connector has to be connected first before you can enrich Cloud Discovery data: https://learn.microsoft.com/en-us/defender-cloud-apps/cloud-discovery-aad-enrichment
sapphire 👍 2 Selected: B
B is correct answer. https://learn.microsoft.com/en-us/defender-cloud-apps/cloud-discovery-aad-enrichment
Vokuhila 👍 2 Selected: B
B is correct. See prerequisites on https://learn.microsoft.com/en-us/defender-cloud-apps/cloud-discovery-aad-enrichment

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Defender for Cloud Apps Cloud Discovery can enrich discovered usernames with their Microsoft Entra ID (Azure AD) UPNs, but the documented prerequisite is to connect the Microsoft 365 app connector first; without it the enrichment cannot resolve identities to Entra ID accounts.

Why the Other Options Are Wrong

Conditional Access App Control user monitoring (A) governs app-access session control, not Cloud Discovery identity enrichment. An Azure app connector (D) is not the connector used for this Entra ID UPN enrichment. Automatic redirection to Microsoft 365 Defender (C) is unrelated to Cloud Discovery identity enrichment.

Community Comment Notes

The community is unanimous (B 100). certinfra (10 likes) cites the cloud-discovery-aad-enrichment documentation and notes the Microsoft 365 app connector must be connected first, with sapphire and Vokuhila confirming B.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide