All certifications / SC-500 / Cheat sheet
SC-500 SC-500 cheat sheet
Domain 1: Manage identity, access, and governance (24%)
Exam tips
- If the question is about users, groups, apps or tenant settings, the answer is an Entra role; if it is about subscriptions or resources, it is an Azure RBAC role. Only Owner, User Access Administrator and Role Based Access Control Administrator (among the built-ins) can assign Azure roles; Contributor cannot.
- Questions often test that NotActions is not a deny and that reading data in a storage account needs a DataActions role, not Contributor. Also watch for a role that cannot be assigned because the target scope is outside its AssignableScopes.
- Eligible is 'can activate', active is 'has it now'. If a question asks how to remove standing admin access while keeping the ability to perform admin work, the answer is converting permanent active assignments to eligible ones in PIM.
- Remember evaluation logic: all matching policies apply, block always wins, and exclusions beat inclusions. If a scenario warns about locking everyone out, the answer usually involves report-only mode, What If and break-glass exclusions.
- If the question asks for protection against phishing or MFA fatigue, 'require MFA' is not enough; choose the phishing-resistant authentication strength with FIDO2/passkeys, Windows Hello for Business or certificate-based authentication. SMS and voice are never phishing-resistant.
- If several resources must share one identity, or the identity must survive resource deletion, pick user-assigned. If the scenario says 'no credentials stored in code or configuration', the answer is a managed identity plus an RBAC role on the target.
- Application permissions need admin consent, full stop. When the question is 'where do I restrict who can sign in to this app or assign it to users', the answer is Enterprise applications (the service principal), not App registrations.
- Contributor on a vault does not grant secret access in the RBAC model, but in the access-policy model a Contributor can add themselves a policy. If data must be unrecoverable-proof against deletion, the answer is purge protection, not just soft delete.
- Deny stops it, Audit reports it, Modify and DeployIfNotExists fix it, and existing resources need a remediation task plus a managed identity. For a temporary, documented exception, choose an exemption with an expiration date.
- Locks override RBAC for everyone, including Owners, but only for management operations, not data. If a question says users can still delete blobs despite a lock, that is expected behavior.
- Sign-in risk maps to 'require MFA'; user risk maps to 'require password change'. Leaked credentials is a user-risk detection, while anonymous IP and atypical travel are sign-in risk detections.
Key terms
- Microsoft Entra role
- A directory role that grants permissions over identity objects and tenant settings, such as User Administrator or Security Administrator.
- Azure RBAC role
- A role definition that grants permissions over Azure resources through Azure Resource Manager, such as Owner, Contributor or Reader.
- Scope
- The level at which a role assignment applies: management group, subscription, resource group or resource; lower levels inherit it.
- User Access Administrator
- An Azure RBAC role that can manage role assignments but not the resources themselves.
- Least privilege
- Granting only the permissions needed, at the narrowest scope and for the shortest time.
- Actions
- Control-plane operations the role allows, such as creating or restarting a VM.
- NotActions
- Operations removed from the Actions wildcard for this role only; not a deny if another role grants them.
- DataActions
- Data-plane operations the role allows, such as reading blobs or Key Vault secrets.
- AssignableScopes
- The management groups, subscriptions or resource groups where a custom role may be assigned.
- Eligible assignment
- A PIM assignment that lets a user activate a role when needed; it grants no permissions until activated.
- Active assignment
- A role assignment whose permissions are currently in effect, either permanently or for a set time.
- Activation
- The just-in-time step where an eligible user turns on a role, subject to MFA, justification, ticket or approval settings.
- Access review
- A scheduled check in which reviewers confirm or remove users' continued access to a role, group or app.
- Conditional Access policy
- An if-then rule in Entra ID that evaluates sign-in signals and enforces grant or session controls.
- Grant control
- The part of a policy that blocks access or grants it only if requirements such as MFA or a compliant device are met.
- Session control
- A control that limits the session after access is granted, such as sign-in frequency or app-enforced restrictions.
- Named location
- A set of IP ranges or countries used as a condition; it can be marked as trusted.
- Report-only mode
- A policy state that logs what would happen without enforcing the policy.
- Authentication methods policy
- The Entra ID policy that enables or disables each sign-in method for all users or selected groups.
- Phishing-resistant MFA
- Methods bound cryptographically to the legitimate site, such as FIDO2 keys, passkeys, Windows Hello for Business and certificate-based authentication.
- Passkey
- A FIDO2 credential stored on a security key or device that signs in with a private key unlocked by PIN or biometrics.
- Authentication strength
- A Conditional Access grant control that requires specific combinations of methods, such as the built-in phishing-resistant MFA strength.
- Temporary Access Pass
- A time-limited passcode used to register or recover strong methods without a password.
- Managed identity
- An Entra identity for an Azure resource whose credentials Azure manages and rotates automatically.
- System-assigned identity
- A managed identity created on and tied to one resource's life cycle.
- User-assigned identity
- A standalone managed identity resource that can be attached to many resources and persists independently.
- IMDS
- The Azure Instance Metadata Service at 169.254.169.254 that VMs use to request managed identity tokens.
- Application object
- The global app definition in its home tenant, managed under App registrations.
- Service principal
- The tenant-local instance of an application, managed under Enterprise applications, that receives consent and assignments.
- Delegated permission
- A permission used by an app on behalf of a signed-in user, limited by that user's own access.
- Application permission
- An app-only permission used with no signed-in user; it always needs admin consent.
- Admin consent workflow
- A process that lets users request admin approval for apps they are not allowed to consent to.
- Access policy model
- The legacy Key Vault data-plane authorization that grants vault-wide permission sets per principal.
- Key Vault RBAC
- Data-plane authorization using Azure roles like Key Vault Secrets User, scopable to a single secret.
- Soft delete
- Keeps deleted vaults and objects recoverable for a 7 to 90 day retention period.
- Purge protection
- Prevents permanent deletion until the retention period passes; cannot be disabled once enabled.
- Key rotation policy
- A schedule that automatically creates new key versions and can notify before expiry.
- Policy definition
- A JSON rule with a condition and an effect that describes allowed resource configurations.
- Initiative
- A group of policy definitions assigned and reported on together, also called a policy set.
- DeployIfNotExists
- An effect that deploys a missing related resource or configuration using a template.
- Remediation task
- A job that applies Modify or DeployIfNotExists to resources that already existed before assignment.
- Exemption
- A record excluding a resource or scope from an assignment, categorized as Waiver or Mitigated, optionally time-limited.
- CanNotDelete lock
- A lock that allows reads and updates but blocks deletion of the resource and its children.
- ReadOnly lock
- A lock that blocks both updates and deletion, allowing only read operations.
- Management group
- A container above subscriptions whose RBAC and policy assignments are inherited by all subscriptions beneath it.
- Root management group
- The single top-level management group in every tenant that contains all others.
- Sign-in risk
- The likelihood that a specific authentication request was not made by the legitimate user.
- User risk
- The likelihood that an identity is compromised, for example because its credentials leaked.
- Risk-based Conditional Access
- Policies that require MFA or a secure password change based on sign-in or user risk level.
Domain 2: Secure storage, databases, and networking (28%)
Exam tips
- Owner or Contributor alone does not give Entra data access, but it does allow listing keys, which gives full data access. The most secure answer for storage is almost always Entra ID with a data role and Shared Key disabled.
- Most secure SAS: user delegation. Revoke a service SAS without rotating keys: stored access policy. Revoke an ad hoc key-signed SAS: regenerate the key that signed it. Account SAS cannot use stored access policies.
- Infrastructure encryption can only be enabled at creation. A locked time-based retention policy cannot be shortened or removed, only extended. CMK needs soft delete plus purge protection on the vault and a managed identity with wrap/unwrap rights.
- Private IP ranges cannot be added to the storage IP firewall; use VNet rules or private endpoints. If a Microsoft service like Azure Backup fails after locking the firewall, the fix is the trusted services exception or a resource instance rule.
- Hide data from DBAs: Always Encrypted. Hide data in results for low-privileged users: dynamic data masking. Protect disks and backups: TDE. Control the key yourself: TDE with CMK. Stop password logins: Entra-only authentication.
- Lowest priority number wins and evaluation stops at the first match. Default rules allow all VNet-to-VNet traffic, so micro-segmentation inside a VNet needs explicit deny rules with priority numbers below 65000. Inbound: subnet then NIC; outbound: NIC then subnet.
- Order is security admin rules, then NSGs. Deny at the admin layer cannot be overridden; Allow still lets NSGs deny; Always Allow skips NSGs entirely. Choose AVNM when a question asks to enforce rules centrally that local teams cannot bypass.
- On-premises access, a private IP, per-resource scope and exfiltration protection point to private endpoints. Free, simple, subnet-level access with the public IP retained points to service endpoints. If a private endpoint 'doesn't work', suspect DNS first.
- TLS inspection, IDPS and full URL filtering mean Premium. A firewall without a 0.0.0.0/0 UDR on spoke subnets inspects nothing. Forced tunneling requires the AzureFirewallManagementSubnet.
- Global, edge, multi-region: WAF on Front Door. Regional, in a VNet: WAF on Application Gateway. Layer 3/4 floods: DDoS Protection. Custom rules are processed before managed rules, and Detection mode never blocks.
- Whole site to Azure: site-to-site. Individual laptops: point-to-site (with Entra auth for MFA and Conditional Access). Central inspection of Virtual WAN traffic: secured hub with routing intent. Per-app access without network-level VPN: Entra Private Access.
- Is a specific packet allowed and which rule decided? IP flow verify. What rules are in force on a NIC? Effective security rules. Where is traffic going? Next hop. What traffic flowed historically? Flow logs with traffic analytics.
Key terms
- Data-plane RBAC
- Azure roles such as Storage Blob Data Reader that authorize access to data inside a storage account.
- Account access key
- One of two keys granting full access to all data in a storage account via Shared Key authorization.
- allowSharedKeyAccess
- The storage account property that, when false, rejects requests authorized with account keys or key-signed SAS.
- Key expiration policy
- A storage account setting that flags account keys that have not been rotated within a set number of days.
- User delegation SAS
- A Blob SAS signed with a key obtained through Entra ID credentials, bounded by the creator's RBAC permissions.
- Service SAS
- A SAS signed with an account key granting access to resources in a single storage service.
- Account SAS
- A key-signed SAS that can span multiple services and service-level operations.
- Stored access policy
- A named policy on a container, queue, table or share that service SAS tokens can reference, allowing central change or revocation.
- Customer-managed key
- A key in Key Vault or Managed HSM that wraps the storage account's data encryption keys under your control.
- Infrastructure encryption
- A second, independent layer of encryption enabled only at storage account creation.
- Time-based retention policy
- An immutability policy keeping blobs undeletable and unmodifiable for a set interval; once locked, it can only be extended.
- Legal hold
- An immutability setting that preserves data indefinitely until the hold tag is removed.
- Storage firewall
- Network rules that restrict which subnets, public IP ranges or private endpoints can reach a storage account.
- Trusted services exception
- A firewall setting that allows listed Azure services, such as Azure Backup, to bypass network rules.
- Resource instance rule
- A firewall rule that allows a specific Azure resource instance, identified by its managed identity, to access the account.
- Malware scanning
- A Defender for Storage feature that scans uploaded blobs for malware and tags or alerts on results.
- Sensitive data threat detection
- Defender for Storage prioritization that uses Purview sensitive information types to flag threats to accounts holding sensitive data.
- Microsoft Entra-only authentication
- A server setting that disables SQL authentication so only Entra identities can sign in.
- TDE
- Transparent data encryption that encrypts database files, logs and backups at rest.
- Always Encrypted
- Client-side column encryption that keeps plaintext hidden from the database engine and its administrators.
- Dynamic data masking
- A policy that obfuscates column values in query results for users without UNMASK permission.
- Database-level firewall rule
- An IP rule stored in one database that applies only to that database.
- Network security group
- A stateful set of allow and deny rules applied to subnets or NICs.
- Rule priority
- A number from 100 to 4096; lower numbers are processed first and the first match wins.
- Service tag
- A Microsoft-maintained label representing the IP prefixes of an Azure service or category, such as Storage or Internet.
- Application security group
- A logical grouping of NICs used as a source or destination in NSG rules instead of IP addresses.
- Azure Virtual Network Manager
- A central service that groups virtual networks and deploys connectivity and security configurations to them at scale.
- Network group
- A static or policy-driven dynamic set of virtual networks targeted by AVNM configurations.
- Security admin rule
- A centrally managed rule evaluated before NSGs, with Allow, Deny or Always Allow actions.
- Always Allow
- A security admin action that permits traffic and bypasses NSG evaluation for it.
- Service endpoint
- A subnet setting that routes traffic to an Azure service over the backbone and lets the service firewall allow that subnet; the service keeps its public IP.
- Private endpoint
- A NIC with a private IP in your subnet mapped to one specific resource through Private Link.
- Private Link service
- Your own service behind a Standard Load Balancer, exposed to consumers through private endpoints.
- Private DNS zone
- An Azure DNS zone, such as privatelink.blob.core.windows.net, that resolves service names to private endpoint IPs for linked VNets.
- Application rule
- An Azure Firewall rule that allows or denies outbound traffic by FQDN or FQDN tag.
- TLS inspection
- A Premium feature that decrypts and re-encrypts HTTPS traffic using an intermediate CA certificate from Key Vault.
- IDPS
- Signature-based intrusion detection and prevention in Azure Firewall Premium.
- Firewall policy
- A resource holding firewall rules and settings, reusable across firewalls and supporting parent-child inheritance.
- User-defined route
- A custom route, such as 0.0.0.0/0 to the firewall's private IP, that overrides Azure's system routes.
- Web application firewall
- A layer 7 filter that inspects HTTP requests for attacks such as SQL injection and cross-site scripting.
- Managed rule set
- Microsoft-maintained WAF rules based on the OWASP Core Rule Set or Microsoft Default Rule Set.
- Custom rule
- A user-defined WAF rule, evaluated before managed rules, matching conditions such as IP, geography or rate.
- Detection mode
- A WAF mode that logs rule matches without blocking requests.
- DDoS Network Protection
- The paid Azure DDoS tier that adds adaptive tuning, telemetry, rapid response and cost protection for VNet resources.
- Site-to-site VPN
- An IPsec/IKE tunnel connecting an on-premises network's VPN device to an Azure VPN gateway.
- Point-to-site VPN
- A VPN from individual client devices to an Azure virtual network using OpenVPN, IKEv2 or SSTP.
- Secured virtual hub
- A Virtual WAN hub with Azure Firewall managed by Firewall Manager, with routing intent to inspect traffic.
- ZTNA
- Zero Trust network access, granting per-application access after identity and device checks instead of network-wide access.
- Microsoft Entra Private Access
- Microsoft's ZTNA service that publishes private apps through Global Secure Access with Conditional Access per app.
- IP flow verify
- A Network Watcher tool that tests whether a specific packet is allowed or denied to or from a VM and names the deciding rule.
- Effective security rules
- The merged view of all NSG and default rules that actually apply to a NIC.
- VNet flow logs
- Flow records captured at the virtual network, subnet or NIC level, independent of NSGs, stored in a storage account.
- Traffic analytics
- A feature that aggregates flow logs into Log Analytics for dashboards, queries and threat insights.
Domain 3: Secure compute (24%)
Exam tips
- Know the pairing: Prompt Shields is the prevention layer inside the request path (content filtering); Defender for AI services is the detection layer producing security alerts. User prompts carry jailbreaks; documents carry indirect injections.
- Copilot never grants new access; it exposes existing overpermissions. When a question asks how to find overshared content before a Copilot rollout, choose DSPM for AI data risk assessments. When it asks how to stop sensitive data being pasted into consumer AI sites, choose the DLP policy offered through DSPM for AI.
- APIM-to-model auth uses APIM's managed identity plus an RBAC role, which lets you disable model API keys. Overuse protection is the token limit policy (429 on excess); usage visibility is the token metric policy plus Application Insights and Log Analytics.
- The answer to 'how do we govern AI agents' mirrors workload identity governance: a unique identity per agent, an accountable owner, least-privilege permissions, Conditional Access and risk policies, and access reviews. Avoid answers that share a human's credentials with an agent.
- Temp disk and cache coverage without an in-guest agent means encryption at host. Customer control of keys for managed disks means a disk encryption set. BitLocker or DM-Crypt inside the guest means Azure Disk Encryption, which is the legacy option.
- Signed boot components: Secure Boot. Keys and measurements: vTPM. Detecting a tampered boot chain: boot integrity monitoring through Guest Attestation and Defender for Cloud. Trusted launch requires Gen2 VMs; encrypting memory in use is confidential VMs, not trusted launch.
- No public IPs on VMs and RDP/SSH through the browser over 443: Azure Bastion in AzureBastionSubnet. Ports closed until an approved, time-limited request: JIT, which needs Defender for Servers Plan 2.
- JIT, file integrity monitoring and agentless scanning are Plan 2 features. Non-Azure servers need Azure Arc before Defender for Servers, Policy or Update Manager can manage them. The built-in vulnerability scanner is Microsoft Defender Vulnerability Management.
- Network policies need a network policy engine enabled on the cluster, normally chosen at cluster creation. Disabling local accounts is what forces all access through Entra. Gatekeeper enforcement in the cluster is Azure Policy for AKS; threat detection and image scanning is Defender for Containers.
- Least-privilege runtime access is AcrPull; pipelines need AcrPush. Private endpoints and firewall rules require the Premium SKU. Image CVE scanning comes from Defender for Containers, not from ACR by itself.
- Key Vault references need a managed identity with secret read access, and network-restricted vaults need VNet integration. Inbound filtering is access restrictions or private endpoints; outbound reach into a VNet is VNet integration. Protecting an app without code changes points to Easy Auth.
Key terms
- Jailbreak
- A direct prompt injection in which a user tries to make a model ignore its instructions or safety rules.
- Indirect prompt injection
- Malicious instructions hidden in documents or data that a model processes, rather than typed by the user.
- Prompt Shields
- An Azure AI Content Safety feature that detects jailbreak attempts in prompts and indirect attacks in documents.
- Defender for AI services
- A Defender for Cloud plan that raises threat alerts for Azure OpenAI and Foundry model deployments.
- DSPM for AI
- A Microsoft Purview solution that discovers AI usage, sensitive data in prompts and responses, and oversharing risks.
- Oversharing
- Content accessible to far more people than need it, which Copilot can surface to any of them.
- Data risk assessment
- A DSPM for AI report that finds overshared SharePoint sites and files and suggests remediation.
- Sensitivity label
- A Purview classification that can encrypt and mark content and that Copilot honors when accessing or generating data.
- AI gateway
- The set of Azure API Management capabilities for governing and securing access to AI model endpoints.
- authentication-managed-identity
- An APIM policy that obtains an Entra token using APIM's managed identity to call a backend.
- llm-token-limit
- An APIM policy that enforces tokens-per-minute rates and token quotas per key, returning 429 when exceeded.
- Token metrics
- Prompt, completion and total token counts emitted by APIM to Application Insights for monitoring and chargeback.
- Microsoft Entra Agent ID
- Entra capabilities that give AI agents their own directory identities for inventory, access control and protection.
- Agent identity
- A directory identity representing a specific AI agent, distinct from users and ordinary app service principals.
- Agent identity blueprint
- A template from which agent identities are created, defining shared configuration and permissions.
- Sponsor
- The human accountable for an agent's purpose, access and life cycle.
- Server-side encryption
- Always-on AES-256 encryption of managed disks at rest in Azure Storage, with platform or customer-managed keys.
- Disk encryption set
- A resource linking managed disks to a customer-managed key in Key Vault or Managed HSM through a managed identity.
- Encryption at host
- Encryption performed on the VM's physical host so temp disks and caches are encrypted before reaching storage.
- Azure Disk Encryption
- Legacy guest-based encryption using BitLocker or DM-Crypt with keys in Key Vault, scheduled for retirement.
- Trusted launch
- An Azure security type for Gen2 VMs combining Secure Boot, vTPM and boot integrity monitoring.
- Secure Boot
- A UEFI feature that loads only boot components signed by trusted publishers.
- vTPM
- A virtual TPM 2.0 that stores keys and records measured boot values for the VM.
- Boot integrity monitoring
- Remote attestation of a VM's boot measurements, reported as health status in Defender for Cloud.
- Measured boot
- Recording hashes of each boot stage into the TPM so the startup chain can be verified later.
- Azure Bastion
- A managed service providing browser or native-client RDP and SSH to VMs over TLS without public IPs on the VMs.
- AzureBastionSubnet
- The dedicated subnet name required for deploying Azure Bastion.
- Just-in-time VM access
- A Defender for Servers Plan 2 feature that keeps management ports closed and opens them temporarily for approved requests.
- Management port
- A port for remote administration such as 3389 (RDP) or 22 (SSH).
- Defender for Servers Plan 1
- Server protection centered on Microsoft Defender for Endpoint integration and core vulnerability management.
- Defender for Servers Plan 2
- Adds agentless scanning, JIT access, file integrity monitoring, premium vulnerability management and more.
- Azure Arc-enabled server
- A non-Azure machine running the Connected Machine agent so it can be managed as an Azure resource.
- Azure Update Manager
- A service that assesses and schedules OS patching for Azure VMs and Arc-enabled servers.
- Agentless scanning
- Analysis of VM disk snapshots for vulnerabilities, secrets and malware without an installed agent.
- AKS-managed Entra integration
- Configuration where users sign in to the Kubernetes API with Entra identities instead of local certificates.
- Azure RBAC for Kubernetes
- Using Azure role assignments, at cluster or namespace scope, to authorize Kubernetes API actions.
- Private cluster
- An AKS cluster whose API server is reachable only through a private IP in the virtual network.
- Network policy
- A Kubernetes resource that restricts traffic between pods based on labels, namespaces and ports.
- Azure Policy add-on
- An AKS add-on using OPA Gatekeeper to audit or deny non-compliant Kubernetes resources.
- Admin user
- A shared registry credential with full push and pull rights that should remain disabled.
- AcrPull
- An Azure role that allows pulling images from a registry.
- AcrPush
- An Azure role that allows pushing and pulling images.
- Scope map and token
- Registry features granting repository-specific permissions to non-Entra clients.
- Key Vault reference
- An app setting value of the form @Microsoft.KeyVault(...) that the platform resolves using the app's managed identity.
- Access restrictions
- Priority-ordered allow and deny rules that filter inbound traffic to an App Service or Function app.
- HTTPS Only
- A setting that redirects all HTTP requests to HTTPS.
- Easy Auth
- App Service built-in authentication that signs users in through identity providers before requests reach the code.
- VNet integration
- A feature that lets an app make outbound calls into a virtual network to reach private resources.
Domain 4: Manage and monitor security posture (24%)
Exam tips
- Free tier gives recommendations, secure score and MCSB compliance; attack path analysis, cloud security explorer, governance rules and agentless scanning require Defender CSPM. A control's full points only come when every affected resource is healthy.
- Automatic, prioritized end-to-end chains: attack path analysis. Your own ad hoc question across the graph: cloud security explorer. Snapshot-based scanning without agents: agentless scanning. Owners and due dates: governance rules. All require Defender CSPM, not foundational CSPM.
- MCSB is the default standard and drives secure score. Adding other regulatory standards is done in Environment settings and generally requires Defender CSPM. On Azure, standards are implemented as Azure Policy initiatives. A green dashboard is not a certification.
- Plans are enabled per subscription on Defender plans; enable at subscription level to cover future resources. Use suppression rules for known benign alerts, workflow automation to respond, and sample alerts to test. Alerts also surface as incidents in Defender XDR.
- AWS onboarding uses a CloudFormation template; GCP uses a Cloud Shell script or Terraform; both avoid long-lived keys through federation. Full server protection in other clouds relies on Azure Arc. Automatic reactions to Defender for Cloud alerts or recommendations are workflow automation with Logic Apps.
- Default to one workspace unless residency, tenant boundaries or billing force more. AMA plus DCRs is the collection method; the legacy agent is retired. CEF goes to CommonSecurityLog via a Linux forwarder; Windows events go to SecurityEvent; DCR transformations filter data before ingestion.
- Fastest detection for a simple condition: NRT. Complex correlation or thresholds: scheduled. Turning other Microsoft products' alerts into incidents: Microsoft security rules, but disable them when Defender XDR incident integration is on to avoid duplicates. Without entity mapping, automation and investigation graphs have nothing to act on.
- Simple triage actions (assign, tag, close, set severity) with no code: automation rules. Actions involving external systems or approvals: playbooks, usually launched by an automation rule. Dashboards: workbooks. Proactive searches: hunting. Lookup lists: watchlists. IoCs: threat intelligence.
- Detection and real-time rules need Analytics-tier data. High-volume, rarely queried data belongs in a lower-cost tier such as the data lake or auxiliary/basic logs. Archived data needs a search job or restore. Custom tables end in _CL.
- Copilot does not bypass permissions: a user sees only data they already have access to. Capacity is SCUs, shared by standalone and embedded use. Owners manage plugins and settings; contributors use it. Reusable multi-step prompts are promptbooks.
- Scoping which emails an attacker read relies on MailItemsAccessed (originally Premium-only, now also in Audit Standard); search-query events are still Premium. Longer retention and custom retention policies are Premium features. Searching requires an Audit Logs role; bringing audit data into Sentinel uses the Microsoft 365 connector (OfficeActivity table).
Key terms
- CSPM
- Cloud security posture management: continuous assessment of configuration against best practices.
- Foundational CSPM
- The free Defender for Cloud tier providing recommendations, secure score, inventory and MCSB compliance.
- Defender CSPM
- The paid posture plan adding attack paths, cloud security explorer, agentless scanning, governance and data-aware posture.
- Secure score
- A percentage based on security controls, earned when all resources in a control are healthy.
- Security control
- A group of related recommendations whose points count toward secure score.
- Cloud security graph
- The Defender CSPM database of resources, exposures, identities and relationships used for context-aware analysis.
- Attack path analysis
- Automatic discovery of exploitable chains from an entry point to a critical asset, with remediations to break them.
- Cloud security explorer
- A query builder for searching the security graph for risky combinations of conditions.
- Governance rule
- A rule that assigns owners and due dates to matching recommendations and tracks remediation.
- Choke point
- A resource through which many attack paths pass, making it a high-value fix.
- Microsoft cloud security benchmark
- Microsoft's default security standard in Defender for Cloud, covering Azure and multicloud best practices.
- Regulatory compliance dashboard
- The Defender for Cloud view that maps assessments to the controls of selected standards.
- Standard
- A set of compliance controls, such as PCI DSS or ISO 27001, assigned to a scope in Defender for Cloud.
- Custom standard
- A user-defined set of recommendations grouped as a standard for tracking.
- Cloud workload protection
- Runtime threat detection for specific resource types delivered through Defender for Cloud plans.
- Security alert
- A detection of suspicious activity with severity, evidence, MITRE tactics and response guidance.
- Suppression rule
- A rule that automatically dismisses alerts matching defined conditions, used for known benign activity.
- Sample alerts
- Test alerts generated on demand to validate notifications and automation.
- Multicloud connector
- A Defender for Cloud resource that onboards an AWS account or GCP project for posture assessment and protection.
- CloudFormation template
- The AWS deployment template generated by Defender for Cloud to create the IAM roles the connector needs.
- Workflow automation
- A Defender for Cloud feature that triggers Logic Apps from alerts, recommendations or compliance changes.
- Auto-provisioning of Arc
- Connector-driven installation of the Azure Arc agent on AWS or GCP VMs for Defender for Servers.
- Log Analytics workspace
- The data store underlying Microsoft Sentinel, queried with KQL.
- Azure Monitor Agent
- The current agent for collecting logs from Windows and Linux machines, configured by data collection rules.
- Data collection rule
- A configuration defining what data AMA collects, optional KQL transformations and the destination.
- CEF
- Common Event Format, a standardized Syslog message format used by many security appliances, stored in CommonSecurityLog.
- Log forwarder
- A Linux VM with AMA that receives Syslog or CEF from devices and sends it to the workspace.
- Scheduled query rule
- An analytics rule that runs KQL on a schedule over a lookback window and raises alerts when a threshold is met.
- NRT rule
- A near-real-time analytics rule that runs every minute for fast detection of simple conditions.
- Microsoft security rule
- A rule that creates Sentinel incidents from alerts produced by other Microsoft security products.
- Anomaly rule
- A built-in machine learning rule that records deviations from baselines in the Anomalies table.
- Entity mapping
- Linking query columns to entity types like Account, Host and IP so incidents can be investigated and automated.
- Automation rule
- A no-code Sentinel rule that runs on incident or alert events to assign, tag, change status, add tasks or run playbooks.
- Playbook
- A Logic Apps workflow triggered by Sentinel to perform multistep response and enrichment actions.
- Workbook
- An interactive KQL-driven dashboard for visualizing Sentinel data.
- Hunting query
- A KQL query run proactively to search for threats not caught by analytics rules.
- Watchlist
- A CSV-based lookup table in Sentinel referenced in queries with _GetWatchlist.
- Analytics tier
- The full-featured log tier supporting all KQL, analytics rules and fast queries, at the highest ingestion cost.
- Sentinel data lake
- A low-cost lake tier for long-term security data, queried asynchronously and used to feed summarized results to Analytics.
- Long-term retention
- Low-cost retention up to 12 years, accessed through search jobs or restore.
- Custom table
- A table for non-standard data, named with the _CL suffix, created via the Logs Ingestion API or AMA custom logs.
- summarize
- A KQL operator that aggregates rows, such as counting events by user.
- Security Compute Unit
- The unit of provisioned capacity that determines how much processing Security Copilot can perform.
- Copilot owner
- The Security Copilot role that manages settings, plugins and capacity.
- Plugin
- A connector that gives Security Copilot data and skills from a Microsoft or third-party product.
- Promptbook
- A saved, reusable sequence of prompts for a common security task.
- Embedded experience
- Security Copilot features surfaced inside products like Defender XDR, Entra or Intune.
- Unified audit log
- The central Microsoft 365 record of user and admin activities across services, searched through Purview Audit.
- Audit (Premium)
- The advanced tier adding longer retention, custom retention policies, higher API bandwidth and intelligent insight events such as SearchQueryInitiatedExchange.
- MailItemsAccessed
- An audit event recording access to mailbox items, used to scope email compromise; originally Premium-only, now also logged for Audit (Standard).
- Audit log retention policy
- A Premium policy that sets how long specific audit records are kept.
Study SC-500 for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the SC-500 study planLessons, quizzes, exam simulations and hands-on labs.