Entra ID Detection and Operations
Detect what the controls did not stop
Most identity training stops at configuration. This course starts where it ends: reading the sign-in that has no user in it, governing the identities nobody owns, and operating a tenant that has to keep running. You will work the evidence Entra ID actually produces, including the tables most tenants have never enabled and the records that expire in thirty days.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Foundations
What Entra ID Detection and Operations teaches: detect the identity attacks that get past Conditional Access, govern the workload and external identities no control reaches, and run the estate that produces the signal. The tables you will query, the detections you will write, and how the course is structured. Start here.
Show 11 lessonsHide lessons
- 0.1ID0.1 What This Course Is AboutPreview
- 0.2ID0.2 Where Identity Signal Comes FromPreview
- 0.3ID0.3 What a Detection Actually IsPreview
- 0.4ID0.4 The Attacks You Will DetectPreview
- 0.5ID0.5 Why Most Identity Detections Cannot Tell You Anything AlonePreview
- 0.6ID0.6 The Identities Nobody OwnsPreview
- 0.7ID0.7 Running an Identity EstatePreview
- 0.8ID0.8 The Portal, PowerShell and KQLPreview
- 0.9ID0.9 Measuring Detection CoveragePreview
- 0.10ID0.10 The Lab EnvironmentPreview
- 0.11Module SummaryPreview
Phase 1: Workload and External Identity
Most identities in a tenant are not people. What they are, what they can reach, why the interactive controls do not apply to them, and the four activities that decide whether any of it is governed.
Show 12 lessonsHide lessons
- 1.1ID1.1 The Sign-In With Nobody In It
- 1.2ID1.2 What Is Actually In Your Tenant
- 1.3ID1.3 The Credential Decides the Blast Radius
- 1.4ID1.4 The Identity With No Credential to Leak
- 1.5ID1.5 Held Versus Granted
- 1.6ID1.6 The One Policy Type That Reaches Them
- 1.7ID1.7 The Only Record You Get
- 1.8ID1.8 The Credential Nobody Asked For
- 1.9ID1.9 Rotating One Without Breaking It
- 1.10ID1.10 Proving the Inventory Still Describes the Tenant
- 1.11ID1.11 See It Done End to End
- 1.12Check My Knowledge
A cross-tenant access configuration you can defend, inbound and outbound. The population you inherited, the settings nobody chose, and the one property that inherits from the default when somebody leaves it unset.
Show 12 lessonsHide lessons
- 2.1ID2.1 The Population You Have Before You Configure Anything
- 2.2ID2.2 The Defaults You Inherited
- 2.3ID2.3 The Inbound Decision
- 2.4ID2.4 The Trust Decision
- 2.5ID2.5 The Outbound Decision
- 2.6ID2.6 Conditional Access Over Six Populations
- 2.7ID2.7 Onboarding That Makes Review Possible
- 2.8ID2.8 Direct Connect and Sync
- 2.9ID2.9 The Review That Can Actually Remove Someone
- 2.10ID2.10 Proving the Configuration Still Holds
- 2.11ID2.11 See It Done End to End
- 2.12Check My Knowledge
Phase 2: Governance and Detection
A permission arrives by one of four paths and only some of them record why. What governance produces that a detection can join against, and what each control can actually end.
Show 12 lessonsHide lessons
- 3.1ID3.1 Four Ways a Permission Arrives
- 3.2ID3.2 The Paths That Record Nothing
- 3.3ID3.3 The Rule That Stops Running
- 3.4ID3.4 What an Access Package Actually Is
- 3.5ID3.5 The Policy Decides, Not the Package
- 3.6ID3.6 A Review That Can Say No, and What It Never Reaches
- 3.7ID3.7 The Date the Workflow Depends On
- 3.8ID3.8 Disable Is Not Offboarding
- 3.9ID3.9 Joining Governance to Detection
- 3.10ID3.10 Proving It Closed
- 3.11ID3.11 See It Done End to End
- 3.12Check My Knowledge
Detection engineering is a development discipline. One detection carried through ten stages, from a line of threat intelligence to a merged pull request, and two more you build yourself.
Show 12 lessonsHide lessons
- 4.1ID4.1 Detection Engineering as a Development Discipline
- 4.2ID4.2 From Hypothesis to Data Confirmation
- 4.3ID4.3 The Detection Specification
- 4.4ID4.4 Expressing the Rule
- 4.5ID4.5 Blind Spots, Assumptions and False Positives
- 4.6ID4.6 Test Cases and Validation
- 4.7ID4.7 Response Guidance
- 4.8ID4.8 The Repository and the Path to Production
- 4.9ID4.9 Coverage That Means Something
- 4.10ID4.10 The Library, Assembled
- 4.11See It Done End to End
- 4.12Check My Knowledge
Phase 3: Operations and Resilience
Detections decay, configurations drift, and log sources stop without failing. What you watch day to day, and how you find out before an investigation does.
Show 12 lessonsHide lessons
- 5.1ID5.1 What the Platform Reports, and What It Cannot
- 5.2ID5.2 Choosing What to Watch
- 5.3ID5.3 Alerting on Your Own Machinery
- 5.4ID5.4 What You Can Honestly Promise
- 5.5ID5.5 Drift in the Control Plane
- 5.6ID5.6 Credential and Secret Hygiene
- 5.7ID5.7 What Makes an Identity Alert Different
- 5.8ID5.8 Toil, and What to Automate Away
- 5.9ID5.9 Ownership, Escalation and Handover
- 5.10ID5.10 The Operations You Inherited
- 5.11See It Done End to End
- 5.12Check My Knowledge
The platform now backs your tenant up and keeps seven days of it. Median dwell time is fourteen. This module is about the gap, and about the restore that succeeds and leaves the attacker in place.
Show 12 lessonsHide lessons
- 6.1ID6.1 What the Platform Backs Up, and for How Long
- 6.2ID6.2 Two Different Restores Wearing One Word
- 6.3ID6.3 The Control Plane Is the Unit of Recovery
- 6.4ID6.4 What Does Not Come Back
- 6.5ID6.5 Hard Delete, and Protected Actions
- 6.6ID6.6 Break-Glass, the Account Everything Assumes
- 6.7ID6.7 The Baseline You Keep Yourself
- 6.8ID6.8 Rehearsing It
- 6.9ID6.9 The Tenant You Cannot Log Into
- 6.10ID6.10 The Dependencies You Did Not Know You Had
- 6.11See It Done End to End
- 6.12Check My Knowledge
An identity-only view sees one segment of an attack. This module is about what the other products see, what disabling a compromised account actually depends on, and the seam between the cloud directory and the one on your domain controllers.
Show 12 lessonsHide lessons
- 7.1ID7.1 What Identity Alone Cannot See
- 7.2ID7.2 The Prerequisite Chain Nobody Reads
- 7.3ID7.3 What Defender for Identity Actually Adds
- 7.4ID7.4 The Entra Connect Seam
- 7.5ID7.5 The Identity Tables, and What Joins Them
- 7.6ID7.6 Disruption, and What It Does Not Do
- 7.7ID7.7 Predictive Shielding Is Not Disruption
- 7.8ID7.8 The Join Identity Cannot Make Alone
- 7.9ID7.9 What the Unified Queue Changes About Triage
- 7.10ID7.10 What the Integration Does Not Solve
- 7.11See It Done End to End
- 7.12Check My Knowledge
Phase 4: Architecture and Capstone
The seam the rest of the course depends on. Which Entra categories you export, which table each one lands in, what it costs, how long it stays queryable, and which tier decisions silently switch a detection off.
Show 12 lessonsHide lessons
- 8.1ID8.1 The Setting That Turns the Lights On
- 8.2ID8.2 The Category Is Not the Table
- 8.3ID8.3 What Each Category Is Worth, and What It Costs
- 8.4ID8.4 Free Is Not Free
- 8.5ID8.5 Analytics and Data Lake
- 8.6ID8.6 The Retention You Have, and the One You Think You Have
- 8.7ID8.7 Getting Old Data Back
- 8.8ID8.8 The Cost Decision That Removes a Detection
- 8.9ID8.9 Proving the Pipeline Still Runs
- 8.10ID8.10 The Routing You Inherited
- 8.11See It Done End to End
- 8.12Check My Knowledge
One attack that Conditional Access did not stop, worked from the alert to the routing decision to the detection to the response, in a tenant that cannot currently see half of it.
Show 9 lessonsHide lessons
- 9.1ID9.1 The Brief, and What the Tenant Can Currently See
- 9.2ID9.2 The Attack That Got Through
- 9.3ID9.3 What the Evidence Does Not Contain
- 9.4ID9.4 The Routing Decision Comes First
- 9.5ID9.5 Writing It
- 9.6ID9.6 What It Costs to Run
- 9.7ID9.7 The Response You Can Actually Perform
- 9.8ID9.8 Handover
- 9.9Check My Knowledge
Phase 0: Course Resources
Subject-area sheets for identity work: where the control lives in the portal, the query that answers the question at scale, and what the answer does not prove.
Show 10 lessonsHide lessons
- 1Reading a Workload Identity Sign-In
- 2The Four Identity Tables
- 3Grant Paths and What Each Records
- 4Credential Types and Their Limits
- 5Workload Identity Policy Scope
- 6Retention and What Expires When
- 7External Identities and B2B
- 8Governance and Lifecycle
- 9Detection and Monitoring
- 10Backup, Recovery and Resilience
Seven runbooks for the procedures an identity engineer repeats: deploying a policy, retiring a method, migrating to PIM, onboarding a partner, and getting a tenant back.
A complete build for an identity lab: tenant, workspace, telemetry, a population, a partner tenant, and the checks that prove it works.
Show 5 lessonsHide lessons
Worked identity investigations end to end, including the wrong turns, the queries that looked right and were not, and what would have changed each answer.
Seven configuration and governance events that fire at an identity engineer, each with the clearing check, what escalates it, and how to reverse it.
Show 7 lessonsHide lessons
- 1A Credential Landed on a Service Principal
- 2A Workload Identity Signed In From a New Address
- 3A Membership Rule Stopped Processing
- 4An Access Package Assignment Expired Unexpectedly
- 5A Leaver Account Is Still Enabled
- 6Consent Granted an Application Permission
- 7Graph Activity With No Matching Sign-In
Where to practice the identity work in this course against real data, without a tenant of your own.
External sources this course draws on: Microsoft Entra documentation, detection guidance, frameworks and community research.
Course Completion
You've reached the end of Identity Detection and Operations. This closing module looks back at what you built across the course, how it changed the order you work in, and where to take it next.
Show 1 lessonHide lessons
Course overview
Identity is where most intrusions now begin, and the evidence it leaves is thinner and stranger than endpoint evidence. A service principal signs in with no user, no device and no MFA. A group membership arrives with no actor at all. A workflow reports thirty-four successful runs and misses eleven people. This course teaches you to read that evidence, and to say honestly what it cannot tell you. Learn how to:
By the end you will operate Entra ID as a running system rather than a configuration, and be able to state what your evidence proves, what it does not, and when it stops existing.
How this course works
This course is the operational half of identity security: detecting what got past the controls and recovering when it did. The loop repeats through every surface it covers.
1. Cover the identities that are not people. Workload identities, service principals and external accounts hold permissions and outnumber your users. Most identity programs monitor the humans.
2. Know which log holds the answer. Sign-ins, non-interactive sign-ins, service principal sign-ins, audit and Graph activity are five sources with five retentions and five schemas.
3. Write detections against the identity behavior. Consent grants, credential additions, role assignments and the token events that precede them, rather than against a signature.
4. Establish what you can still see. Retention differs by tier and by table, and routing decisions made once decide what every future investigation can reach.
5. Rehearse the recovery. Deleted objects, broken break-glass and a directory that will not authenticate. The identity plane is the one whose outage stops the response itself.
The course closes on one identity intrusion worked end to end.
What this course assumes
No minimum experience and no prerequisite course, and no requirement to have taken the identity controls course first. Each log source and object type is introduced where it first appears.
What makes it go faster: a tenant you can read the logs in, and any prior KQL. Neither is required, and every query is shown against data.
What this course does not cover: Conditional Access design in depth and identity governance, which are separate courses. This one is detection, monitoring and recovery.
Who this course is for
Anyone who wants to learn the subject. There is no minimum experience and every concept is explained where it is used.
What you'll learn
Ten modules, each built on the evidence Entra ID produces rather than on the blade that configures it. Every module ends with a worked investigation on one fictional estate, and every claim in the course is one you can reproduce in your own tenant.
Key course takeaways
Course Resources - what comes with the modules
Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.
Things you need to know
What are the prerequisites for this course?
None. ARC401 Entra ID Security is the companion rather than the first half: it covers what the controls stop, and this covers what to do when they did not, so either can be taken first. Every concept here is explained where it is used, and ARC401 is cited as a pointer rather than as a dependency. Familiarity with KQL and with a Microsoft 365 tenant will help you move faster and is not assumed.
What do I need to follow along?
A tenant of your own is useful and not required. The lab setup module walks the whole build, from getting a tenant through wiring the four diagnostic categories this course reads to creating a population with the shapes the queries expect. It is also explicit about what no lab can produce: most identity evidence comes from behavior you cannot safely generate, so parts of this course are read rather than practiced, and the module says which parts.
How will the course benefit your career?
Identity is the control plane, and the number of people who can investigate it rather than configure it is small. An analyst who can say which mechanism granted an access, what a credential can reach, and when the evidence stops existing is answering the questions an incident actually turns on.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may not redistribute course content or share account credentials.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.