Entra ID Security: Identity Detection & Operations

The second half of the identity picture

ARC401 covers the controls and the attacks they stop. This course covers what you do when they do not: detecting identity attacks in the log, governing the identities nobody owns, and operating Entra ID as a system that has to keep running.

View Pricing

What you'll be able to do

Build identity detection rules that fire on the attacks Conditional Access did not stop
Govern the workload and external identities that no interactive control reaches
Operate Entra ID as a running system: monitoring, log routing, backup and recovery
Correlate identity signal across Defender XDR and Sentinel into one investigation

This course assumes ARC401 or equivalent working knowledge of Conditional Access, authentication methods, token security and application registrations. It does not re-teach them.

In development. Nine modules covering workload identity, external identities, lifecycle governance, identity detection engineering, monitoring and operations, backup and recovery, Defender XDR integration, architecture, and a capstone design exercise.

Version and changelog

Current version: 1.0  |  Last updated: August 2026

August 2026, v1.0: Course created from ARC401 modules 10 to 18, which covered detection, governance and operations. Renumbered as modules 1 to 9 under the ID prefix. In development.

This course is in development and is not yet available.

// reasoning-review IS NAMED HERE BECAUSE IT EMITS ITS rc-code AT RUNTIME. // This condition scans the SERVER-RENDERED content, and reasoning-review.js builds its // artifact block after fetch, so the page contains no rc-code at the moment this runs and // code-chrome never loaded. Deployed 2026-08-26 with correct markup, transparent background // and no chrome, because the class the loader looks for did not exist yet. Any future // component that writes rc-code from script has to be named here too.