A security analyst is investigating a Microsoft Sentinel incident involving suspicious Azure OpenAI usage. The analyst wants to correlate this incident with related Microsoft Defender XDR alerts to build a complete attack timeline. Which Sentinel feature provides this cross-product correlation?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because by connecting Microsoft Defender XDR to Microsoft Sentinel via the M365 Defender data connector, alerts from Defender products are ingested into Sentinel. The Fusion correlation engine in Sentinel automatically correlates related alerts from multiple sources into a single incident, providing a unified attack timeline.
Full explanation below image
Full Explanation
B is correct because by connecting Microsoft Defender XDR to Microsoft Sentinel via the M365 Defender data connector, alerts from Defender products are ingested into Sentinel. The Fusion correlation engine in Sentinel automatically correlates related alerts from multiple sources into a single incident, providing a unified attack timeline. Analysts can also pivot between Sentinel incidents and linked Defender XDR incidents directly. A is wrong because Sentinel Workbooks are reporting and visualization tools, not incident correlation engines. C is wrong because UEBA focuses on behavioral anomalies for specific entities (users, hosts) but does not specifically correlate Sentinel incidents with Defender XDR alerts. D is wrong because the Threat Intelligence blade manages indicators of compromise (IOCs), not cross-product incident correlation.