The Microsoft Entra ID connector in Microsoft Sentinel stays disconnected for the lock-lab tenant. What should the Azure security engineer verify first?
Select an answer to reveal the explanation.
Short Explanation
A red Entra connector is usually rights or unfinished setup—not a poetry slam in KQL. Grant the workspace and tenant permissions, finish diagnostic settings or consent, and get that connector green.
Full Explanation
Unhealthy Microsoft Sentinel connectors commonly lack required workspace or tenant permissions or have incomplete connector-specific configuration such as diagnostic settings or consent. Fixing authorization and finishing configuration restores ingestion. Writing parsers first, substituting Defender for Cloud Apps, or deleting the workspace does not address the typical disconnected-connector root cause.