The built-in Fusion correlation rule in Microsoft Sentinel generates incidents only when it has sufficient telemetry from connected sources (e.g., Microsoft 365 Defender products, Azure AD sign-in logs, Cloud App, etc.). If no relevant data connectors are connected or sending data, Fusion will remain silent even if the rule is enabled. Connecting and authorizing the required data connectors provides the multi-signal input Fusion needs to produce incidents.