Manage and monitor security posture
Three stages, and each one is switched on the same way
An administrator who already holds Security Reader opens the Regulatory compliance dashboard and finds it empty, which is not a bug: reading that policy compliance data takes the Reader role on the subscription, and Security Reader does not include it. That shape, a role whose name sounds like the capability but does not carry the read, repeats everywhere in this domain, and three stages, named here rather than by Microsoft, tell you where you are when you meet it. Assess measures the configuration, risk, and compliance of resources you have already connected, and Microsoft Defender for Cloud owns it. Collect brings records of what happened into a workspace and decides what runs when they land, and Microsoft Sentinel owns it. Assist sets up the platform, the capacity, and the agents that answer questions over that data, and Microsoft Security Copilot owns it. What makes the three feel alike is how a capability is switched on in each: attach a scope, choose the tier that carries it, and then grant permission, usually two permissions rather than one, one that lets somebody configure the platform and one that lets them reach the data inside it. Treating those two as one is the classic trap: Copilot owner is the settings role and returns no security data until the same person also holds a source-service role, a role in the source service being queried, such as Microsoft Sentinel Reader on the workspace.
The domain unfolds in three steps, one per page
The through-line runs from the state of your resources (Assess), to the history they emit (Collect), to the assistance you put on top (Assist). Manage security posture by using Defender for Cloud comes first because nothing is assessed until an environment is connected, meaning an Azure subscription, an AWS account, or a GCP project onboarded as an environment; on top of that scope sit security recommendations, secure score, cloud security posture management (CSPM) in a free foundational form and a paid graph-backed form, compliance against security standards, the workload protection plans that watch resources at runtime, machine vulnerability assessment, and Microsoft Defender External Attack Surface Management (Defender EASM) for internet-facing assets nobody registered. Implement activity and event collection in Microsoft Sentinel takes the next step, from state to history: the eligible Log Analytics workspace Sentinel runs on, the roles that separate enabling it from operating it, the Content hub solutions that supply connectors, the four paths events travel along to reach the workspace, and what happens once they land, namely automation rules, playbooks, and the retention clocks that decide how long the evidence survives. Implement Microsoft Security Copilot closes the domain with the assistance layer: the workspace that fixes where session data is stored and which capacity pays for it, the Security Compute Units (SCUs) every surface spends, the two grants that open a session that actually returns something, the plugins that decide which sources a prompt may call, and the Microsoft-built and partner-built agents that run on their own. Read the pages in that order and each one starts where the previous one stopped.
When two answers both work, control what is collected and kept, and grant the narrower role
Across all three pages the exam rewards the same two instincts. The first is to configure the control that decides what is actually collected and kept, not the one that only changes what a report shows: a data collection rule decides what is ingested and billed while a workbook filter changes the view alone, and years of evidence belong in total retention, retrieved with a search job, rather than in the more expensive interactive retention that everyday queries read. The second is to grant the narrowest access that names the capability you need, because a role that sounds security-shaped is often not the one that carries the read: Microsoft Sentinel Reader is the least-privileged built-in choice for a Copilot user who must see Sentinel incidents, installing a Content hub solution takes Microsoft Sentinel Contributor at the resource group, which Microsoft Sentinel Reader and Responder do not include, and a Microsoft-built agent is safer with its own identity through Microsoft Entra Agent ID and only the plugins it needs than borrowing a person's access or a tenant-wide plugin switch. When a distractor is broader, later in the pipeline, or merely cosmetic, it is usually the wrong answer.
The three stages of this domain, and the page that owns each
| Stage | The question it answers | Scope you connect first | Drill into |
|---|---|---|---|
| Assess | Which resources are misconfigured, how risky that is on this resource, and whether they satisfy a named standard | An Azure subscription, AWS account, or GCP project onboarded as an environment | Manage security posture by using Defender for Cloud |
| Collect | Which records of what happened reach a workspace, and what runs when they land | An eligible Log Analytics workspace with Microsoft Sentinel enabled on it | Implement activity and event collection in Microsoft Sentinel |
| Assist | Who and what may ask questions over that data, and which sources an answer may draw on | A Security Copilot workspace with capacity, measured in Security Compute Units, associated to it | Implement Microsoft Security Copilot |