Entra ID Detection and Operations

Detect what the controls did not stop

Most identity training stops at configuration. This course starts where it ends: reading the sign-in that has no user in it, governing the identities nobody owns, and operating a tenant that has to keep running. You will work the evidence Entra ID actually produces, including the tables most tenants have never enabled and the records that expire in thirty days.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 24 CPE Credits

What you'll be able to do

✓Build identity detection rules that fire on the attacks Conditional Access did not stop
✓Govern the workload and external identities that no interactive control reaches
✓Operate Entra ID as a running system: monitoring, log routing, backup and recovery
✓Correlate identity signal across Defender XDR and Sentinel into one investigation
ARC406 | Premium tier | 10 modules across 5 phases | 20-24 hours at your own pace | 24 CPE credits | Free preview, no account needed | No prerequisite

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Foundations

Module 0Course OrientationCourse Preview

What Entra ID Detection and Operations teaches: detect the identity attacks that get past Conditional Access, govern the workload and external identities no control reaches, and run the estate that produces the signal. The tables you will query, the detections you will write, and how the course is structured. Start here.

Show 11 lessonsHide lessons
  1. 0.1ID0.1 What This Course Is AboutPreview
  2. 0.2ID0.2 Where Identity Signal Comes FromPreview
  3. 0.3ID0.3 What a Detection Actually IsPreview
  4. 0.4ID0.4 The Attacks You Will DetectPreview
  5. 0.5ID0.5 Why Most Identity Detections Cannot Tell You Anything AlonePreview
  6. 0.6ID0.6 The Identities Nobody OwnsPreview
  7. 0.7ID0.7 Running an Identity EstatePreview
  8. 0.8ID0.8 The Portal, PowerShell and KQLPreview
  9. 0.9ID0.9 Measuring Detection CoveragePreview
  10. 0.10ID0.10 The Lab EnvironmentPreview
  11. 0.11Module SummaryPreview

Phase 1: Workload and External Identity

Phase 2: Governance and Detection

Phase 3: Operations and Resilience

Phase 0: Course Resources

ResourcesCookbooks

Seven runbooks for the procedures an identity engineer repeats: deploying a policy, retiring a method, migrating to PIM, onboarding a partner, and getting a tenant back.

Show 7 lessonsHide lessons
  1. 1Rotating a Credential Without an Outage
  2. 2Removing a Credential Somebody Added
  3. 3Finding What a Leaver Left Behind
  4. 4Replacing a Retiring Membership Rule
  5. 5Building the Workload Identity Inventory
  6. 6Scoping a Review That Can Remove
  7. 7Routing Identity Logs for Retention
ResourcesLab Setup

A complete build for an identity lab: tenant, workspace, telemetry, a population, a partner tenant, and the checks that prove it works.

Show 5 lessonsHide lessons
  1. 1Getting a Tenant
  2. 2Wiring the Telemetry
  3. 3Building a Population
  4. 4The Second Tenant
  5. 5Verify and Troubleshoot
ResourcesWalkthroughs

Worked identity investigations end to end, including the wrong turns, the queries that looked right and were not, and what would have changed each answer.

Show 7 lessonsHide lessons
  1. 1The Sign-In With Nobody In It
  2. 2The Rule That Stopped Running
  3. 3The Package That Took Ownership
  4. 4The Review That Removed Three
  5. 5The Eleven Nobody Offboarded
  6. 6The Secret That Outlived the Account
  7. 7Two Alerts, One Differing Field
ResourcesPlayground

Where to practice the identity work in this course against real data, without a tenant of your own.

ResourcesReferences & Further Reading

External sources this course draws on: Microsoft Entra documentation, detection guidance, frameworks and community research.

Course Completion

CompletionCourse Completion

You've reached the end of Identity Detection and Operations. This closing module looks back at what you built across the course, how it changed the order you work in, and where to take it next.

Show 1 lessonHide lessons
  1. 1Course Completion. Identity Detection and Operations

Course overview

Identity is where most intrusions now begin, and the evidence it leaves is thinner and stranger than endpoint evidence. A service principal signs in with no user, no device and no MFA. A group membership arrives with no actor at all. A workflow reports thirty-four successful runs and misses eleven people. This course teaches you to read that evidence, and to say honestly what it cannot tell you. Learn how to:

✓ Inventory and govern the workload identities that outnumber your staff and belong to nobody
✓ Read all four identity sign-in tables, and know which one a question actually lives in
✓ Establish which of four mechanisms granted an access, and what each one records
✓ Write identity detections that survive contact with a rota, and know their blind spots
✓ Recover a tenant, including the parts of it that no backup restores

By the end you will operate Entra ID as a running system rather than a configuration, and be able to state what your evidence proves, what it does not, and when it stops existing.

How this course works

This course is the operational half of identity security: detecting what got past the controls and recovering when it did. The loop repeats through every surface it covers.

1. Cover the identities that are not people. Workload identities, service principals and external accounts hold permissions and outnumber your users. Most identity programs monitor the humans.

2. Know which log holds the answer. Sign-ins, non-interactive sign-ins, service principal sign-ins, audit and Graph activity are five sources with five retentions and five schemas.

3. Write detections against the identity behavior. Consent grants, credential additions, role assignments and the token events that precede them, rather than against a signature.

4. Establish what you can still see. Retention differs by tier and by table, and routing decisions made once decide what every future investigation can reach.

5. Rehearse the recovery. Deleted objects, broken break-glass and a directory that will not authenticate. The identity plane is the one whose outage stops the response itself.

The course closes on one identity intrusion worked end to end.

What this course assumes

No minimum experience and no prerequisite course, and no requirement to have taken the identity controls course first. Each log source and object type is introduced where it first appears.

What makes it go faster: a tenant you can read the logs in, and any prior KQL. Neither is required, and every query is shown against data.

What this course does not cover: Conditional Access design in depth and identity governance, which are separate courses. This one is detection, monitoring and recovery.

Who this course is for

Anyone who wants to learn the subject. There is no minimum experience and every concept is explained where it is used.

✓ SOC analysts who get identity alerts and have nowhere to look up what granted the access
✓ Detection engineers writing rules against identity data whose schema is not obvious
✓ Identity and M365 administrators asked to prove that access is granted, reviewed and removed
✓ Security architects designing controls that have to reach identities with no user behind them
✓ Incident responders who need to know what an account still holds after it is disabled

What you'll learn

Ten modules, each built on the evidence Entra ID produces rather than on the blade that configures it. Every module ends with a worked investigation on one fictional estate, and every claim in the course is one you can reproduce in your own tenant.

✓ Workload identity: the population no user-scoped control reaches, its two credential stores, and the one policy type that applies to it
✓ External identities: the defaults you inherited, six populations one policy has to cover, and the review that can actually remove somebody
✓ Identity governance: four ways a permission arrives, the rule that stops running, and why disable is not offboarding
✓ Detection engineering: hypothesis to data, expressing the rule, and coverage that means something
✓ Monitoring, backup and recovery: what the platform reports, what it backs up, and what does not come back
✓ Defender integration and log routing: what identity alone cannot see, and the join that fails when the data lands in two places

Key course takeaways

✓ A workload identity inventory with an owner, a credential kind and a permission scope against every row
✓ Identity detections you have tested, tuned and can explain the blind spots of
✓ A governance page whose every number carries the expected value beside it
✓ A recovery position that names what cannot be restored rather than assuming everything can
✓ Thirty-six reference pages: cheatsheets, runbooks, walkthroughs, alert playbooks and a full lab build

Course Resources - what comes with the modules

Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.

✓ Walkthroughs take one detection problem end to end: the sign-in with nobody in it, the rule that stopped running, the package that took ownership, the secret that outlived the account, and two alerts differing by one field.
✓ Playbooks start where a real alert starts rather than where the evidence tidies up: a credential landed on a service principal, a workload identity signed in from a new address, Graph activity with no matching sign-in.
✓ A cookbook for the operations behind the detections: rotating a credential without an outage, finding what a leaver left behind, scoping a review that can actually remove, routing identity logs for retention.
✓ A command cheatsheet covering the four identity tables, grant paths, credential limits and what expires when.
✓ A lab setup guide for a tenant of your own, the telemetry wiring, a population to detect against, and a second tenant for the cross-tenant work.
✓ A playground for the investigation practice a twenty-user lab cannot give you: the SOC Simulator runs against a corpus with hundreds of users and months of history, which is what baseline comparison needs, alongside the query Practice surface and the Playbook Suite.
✓ A references module for the Microsoft documentation behind the claims.

Things you need to know

What are the prerequisites for this course?

None. ARC401 Entra ID Security is the companion rather than the first half: it covers what the controls stop, and this covers what to do when they did not, so either can be taken first. Every concept here is explained where it is used, and ARC401 is cited as a pointer rather than as a dependency. Familiarity with KQL and with a Microsoft 365 tenant will help you move faster and is not assumed.

What do I need to follow along?

A tenant of your own is useful and not required. The lab setup module walks the whole build, from getting a tenant through wiring the four diagnostic categories this course reads to creating a population with the shapes the queries expect. It is also explicit about what no lab can produce: most identity evidence comes from behavior you cannot safely generate, so parts of this course are read rather than practiced, and the module says which parts.

How will the course benefit your career?

Identity is the control plane, and the number of people who can investigate it rather than configure it is small. An analyst who can say which mechanism granted an access, what a credential can reach, and when the evidence stops existing is answering the questions an incident actually turns on.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may not redistribute course content or share account credentials.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.