Lock-lab workspace cost spiked after every Microsoft Sentinel Content Hub connector was enabled. How should the Azure security engineer choose connectors?
Select an answer to reveal the explanation.
Short Explanation
Connecting everything is how the bill bites. Turn on the connectors that back the analytics you’ll actually enable—Activity, Defender for Cloud, Entra sign-in—and leave the rest off.
Full Explanation
Connector selection should follow planned detections: enable sources that feed analytics rules you will turn on, such as Azure Activity, Microsoft Defender for Cloud, and Microsoft Entra sign-in data. Enabling every connector without a detection plan inflates cost and noise. Disabling Sentinel or zeroing retention is not a substitute for deliberate connector selection at Azure security-engineer depth.