Microsoft 365 Security Automation and Orchestration
Master Microsoft 365 Security Automation and Orchestration
Scale your security operations without scaling headcount. Design, build, and operationalize powerful automation and orchestration workflows using Microsoft Sentinel, Logic Apps, Playbooks, and Defender XDR, so you can respond to threats faster, reduce manual work, and run a more efficient, effective SOC.
What you'll be able to do
Course Syllabus
Every module and every lesson. Open a module to see its lessons.
Download the full syllabus (PDF)
Phase 1: Foundations
What Microsoft 365 Security Automation and Orchestration teaches: build Sentinel and Logic Apps playbooks that enrich alerts, collect evidence, and auto-contain threats across identity, endpoint, and cloud, so your...
13 lessonsHide lessons
- 0.1 Why Most SOCs Don't Automate (And Why They Should)Preview
- 0.2 The Automation SpectrumPreview
- 0.3 The Three Automation TiersPreview
- 0.4 The Confidence Threshold ProblemPreview
- 0.5 The Blast Radius AssessmentPreview
- 0.6 NE's Automation LandscapePreview
- 0.7 Sentinel Automation ArchitecturePreview
- 0.8 Defender XDR Automation ArchitecturePreview
- 0.9 The Automation Governance FrameworkPreview
- 0.10 The Automation Maturity ModelPreview
- 0.11 Guided Walkthrough: Automation AssessmentPreview
- Module SummaryPreview
- Check My KnowledgePreview
Build your first automation rule and your first Sentinel playbook.
13 lessonsHide lessons
- 1.1 Automation Rules. The Lightweight Layer
- 1.2 Playbooks. The Power Layer
- 1.3 Your First Automation Rule
- 1.4 Your First Playbook
- 1.5 Authentication and Permissions
- 1.6 Entity Extraction and Mapping
- 1.7 Error Handling and Retry Logic
- 1.8 Testing Automation Safely
- 1.9 Monitoring Automation Health
- 1.10 Cost Management
- 1.11 Guided Walkthrough. Connecting the Automation Chain
- Module Summary
- Check My Knowledge
Phase 2: Enrichment & Collection
Build the enrichment pipeline that transforms every alert into an investigation-ready incident.
13 lessonsHide lessons
- 2.1 The Enrichment Stack
- 2.2 IP Reputation Enrichment Playbook
- 2.3 User Risk Enrichment Playbook
- 2.4 Device Compliance Enrichment Playbook
- 2.5 Alert History and Pattern Enrichment
- 2.6 Threat Intelligence Auto-Correlation
- 2.7 Geo-Location and Impossible Travel Enrichment
- 2.8 Combining Enrichments. The Enrichment Pipeline
- 2.9 Watchlist-Driven Dynamic Enrichment
- 2.10 Enrichment Performance Tuning
- 2.11 Guided Walkthrough. Building the Production Enrichment Pipeline
- Module Summary
- Check My Knowledge
Build the evidence collection pipeline that captures volatile data at alert time, before session tokens expire, before processes terminate, before containment modifies the environment.
13 lessonsHide lessons
- 3.1 The Collection Problem
- 3.2 Cloud Evidence Auto-Collection
- 3.3 Endpoint Evidence Auto-Collection
- 3.4 Identity Evidence Auto-Collection
- 3.5 Network Evidence Auto-Collection
- 3.6 Evidence Packaging and Chain of Custody
- 3.7 Collection Playbook for AiTM Incidents
- 3.8 Collection Playbook for Endpoint Incidents
- 3.9 Collection Playbook for Email Incidents
- 3.10 Collection Timing and Retention
- 3.11 Interactive Lab: Auto-Collection Pipeline
- Module Summary
- Check My Knowledge
Build the notification pipeline that delivers the right information to the right people at the right severity, Teams adaptive cards for the SOC, escalation cascades for after-hours, MSSP coordination to prevent...
13 lessonsHide lessons
- 4.1 Who Needs to Know, and When
- 4.2 Teams Channel Notifications
- 4.3 Email Notifications
- 4.4 On-Call Escalation Automation
- 4.5 MSSP Notification and Coordination
- 4.6 Management and Executive Notifications
- 4.7 Ticketing Integration (ServiceNow/Jira)
- 4.8 Regulatory Notification Triggers
- 4.9 Notification Fatigue Prevention
- 4.10 Approval Workflows
- 4.11 Interactive Lab: Notification Pipeline
- Module Summary
- Check My Knowledge
Phase 3: Response Automation
Build the identity containment playbook that revokes sessions, surgically removes attacker MFA methods, activates emergency conditional access, revokes OAuth consents, and disables accounts, gated by confidence...
13 lessonsHide lessons
- 5.1 The Auto-Containment Decision
- 5.2 Session Revocation Automation
- 5.3 MFA Reset Automation
- 5.4 Conditional Access Emergency Policy
- 5.5 OAuth App Revocation
- 5.6 Account Disable with Safeguards
- 5.7 Inbox Rule Remediation
- 5.8 Password Reset Orchestration
- 5.9 Identity Containment Verification
- 5.10 Identity Containment Rollback
- 5.11 Interactive Lab: Identity Auto-Containment
- Module Summary
- Check My Knowledge
Build the endpoint containment playbook that isolates compromised devices through Defender for Endpoint, collects forensic evidence before isolation, blocks malicious files fleet-wide, and applies the...
13 lessonsHide lessons
- 6.1 Endpoint Isolation Decision Logic
- 6.2 Defender for Endpoint Isolation Automation
- 6.3 Automated Investigation Package Collection
- 6.4 Automated Live Response Actions
- 6.5 File Quarantine and Block
- 6.6 Network Containment via Firewall API
- 6.7 Endpoint Containment for Servers vs Workstations
- 6.8 Multi-Endpoint Containment Coordination
- 6.9 Endpoint Containment Verification
- 6.10 Endpoint Containment Rollback
- 6.11 Interactive Lab: Endpoint Containment Pipeline
- Module Summary
- Check My Knowledge
Build the synchronized containment playbook that responds to attacks spanning cloud, endpoint, and network at once, parallel session revocation, device isolation, and IP blocking, with blast radius assessment, human...
13 lessonsHide lessons
- 7.1 The Coordinated Containment Problem
- 7.2 Synchronized Containment Playbook
- 7.3 Containment Sequence Prioritization
- 7.4 Blast Radius Assessment Automation
- 7.5 Human Approval Gates for High-Impact Actions
- 7.6 Automation for CHAIN-HARVEST Response
- 7.7 Automation for CHAIN-PRIVILEGE Response
- 7.8 Partial Automation Patterns
- 7.9 Containment Monitoring and Breakout Detection
- 7.10 Post-Containment Automation
- 7.11 Interactive Lab: Cross-Environment Response
- Module Summary
- Check My Knowledge
Phase 4: Operational Mastery
Build automation native to Microsoft Defender XDR, custom detection rules with auto-actions, Automated Investigation and Response, attack disruption, custom indicators, and the per-workload automation across MDO...
13 lessonsHide lessons
- 8.1 Custom Detection Rules with Auto-Actions
- 8.2 Auto Investigation and Response (AIR)
- 8.3 Attack Disruption Configuration
- 8.4 MDE Custom Indicators for Automated Blocking
- 8.5 Defender for Office 365 Automation
- 8.6 Defender for Identity Auto-Response
- 8.7 Defender for Cloud Apps Automation
- 8.8 Unified XDR + Sentinel Automation
- 8.9 XDR Automation Monitoring
- 8.10 XDR Automation at Scale
- 8.11 Interactive Lab: XDR Custom Detection and Auto-Response
- Module Summary
- Check My Knowledge
Engineer KQL as the control layer for automation, queries as triggers, dynamic watchlists for runtime control, suppression with audit cycles, multi-signal correlation that composes confidence, health monitoring...
13 lessonsHide lessons
- 9.1 KQL as Automation Trigger
- 9.2 Dynamic Watchlists for Automation Control
- 9.3 KQL-Based Alert Suppression
- 9.4 KQL Correlation Rules for Multi-Signal Automation
- 9.5 KQL for Automation Health Monitoring
- 9.6 KQL-Driven Hunting Automation
- 9.7 KQL for Evidence Collection Queries
- 9.8 Advanced KQL Patterns for Automation
- 9.9 KQL Alert Tuning for Automation Confidence
- 9.10 Building a KQL Automation Query Library
- 9.11 Interactive Lab: KQL-Driven Automation
- Module Summary
- Check My Knowledge
Build Azure Functions for automation that exceeds Logic Apps, TI enrichment with caching and retry, bulk remediation with dry-run safety, custom IOC feed processing with deduplication and expiry, evidence packaging...
13 lessonsHide lessons
- 10.1 When Logic Apps Are Not Enough
- 10.2 Azure Function Architecture for Security
- 10.3 Building a TI Enrichment Function
- 10.4 Building a Bulk Remediation Function
- 10.5 Building a Custom IOC Feed Processor
- 10.6 Building an Evidence Packager
- 10.7 Error Handling and Observability
- 10.8 Security Considerations for Functions
- 10.9 Testing and Deployment
- 10.10 Connecting Functions to Sentinel
- 10.11 Interactive Lab: Azure Functions for Security Automation
- Module Summary
- Check My Knowledge
Build the discipline that keeps automation trustworthy, the testing framework, staging workspace, safe containment testing, version control, change management, operational runbooks, audit trails, false positive...
13 lessonsHide lessons
- 11.1 The Case for Automation Testing
- 11.2 The Testing Framework
- 11.3 The Staging Workspace
- 11.4 Testing Containment Automation Safely
- 11.5 Version Control for Automation
- 11.6 Change Management for Production Automation
- 11.7 Automation Runbooks
- 11.8 Automation Audit Trail
- 11.9 False Positive Impact Analysis
- 11.10 Continuous Improvement
- 11.11 Interactive Lab: Testing and Governing the Automation Stack
- Module Summary
- Check My Knowledge
Turn automation capability into a sustained program, a dependency-ordered roadmap, leverage-based candidate selection, a team structure that survives turnover, business metrics, playbook library governance, MSSP...
13 lessonsHide lessons
- 12.1 The Automation Roadmap
- 12.2 Identifying Automation Candidates
- 12.3 Building the Automation Team
- 12.4 Automation Metrics Dashboard
- 12.5 The Playbook Library
- 12.6 MSSP Automation Coordination
- 12.7 Automation for Compliance
- 12.8 Cost-Benefit Analysis
- 12.9 Scaling Automation
- 12.10 The Mature Automation Operation
- 12.11 Interactive Lab: Building the Program Roadmap
- Module Summary
- Check My Knowledge
Assemble the entire course into one working system, six automation phases from enrichment through governance, run a realistic multi-stage attack end to end, expose the bugs only integration testing reveals, measure...
13 lessonsHide lessons
- 13.1 Capstone Briefing
- 13.2 Phase 1: Enrichment Automation
- 13.3 Phase 2: Collection Automation
- 13.4 Phase 3: Notification Automation
- 13.5 Phase 4: Containment Automation
- 13.6 Phase 5: Cross-Environment Orchestration
- 13.7 Phase 6: Monitoring and Governance
- 13.8 Integration Testing
- 13.9 Metrics and Business Case
- 13.10 The Complete Automation Architecture
- 13.11 Interactive Lab: Running the Full Stack
- Module Summary
- Check My Knowledge
Phase 0: Course Resources
Automation patterns organized by what they do, each carrying the risk tier that decides whether it runs unattended.
11 lessonsHide lessons
Seven procedures for getting automation into production and keeping it there, each with a state to reach.
A lab with disposable targets, so containment automation can be tested without locking you out of the tenant running it.
5 lessonsHide lessons
Worked automation failures end to end, including the wrong turns and what would have made each answer different.
Response procedures for when the automation is the incident, with dispositions and a handoff artifact.
Where to practice building automation, and the one thing about this discipline no practice surface can give you.
The consolidated lookup and the step-by-step procedures from this course, in one place.
2 lessonsHide lessons
External sources this course draws on: vendor documentation, frameworks, standards, and research.
Course Completion
Security Automation end-of-course exam, a simulation-based assessment testing whether you can diagnose, contain, and remediate an automation failure under pressure, using the engineering and judgment built across all...
1 lessonsHide lessons
Course overview
The Microsoft 365 Security Automation and Orchestration course is built specifically for Security Engineers, Detection Engineers, and Architects who need to scale operations without scaling headcount. You'll gain hands-on expertise to:
By the end, you'll have the practical skills and engineering mindset to automate repetitive tasks, standardize response processes, and dramatically improve your organization's security efficiency and effectiveness.
How this course works
Automation in a SOC is a decision about what a machine may do without asking. This course runs the same loop for every playbook it builds, because the failure mode is not a playbook that breaks but one that acts confidently on a wrong input.
1. Automate the reading before the acting. Enrichment and evidence collection are safe, immediately valuable and reversible. Start there and the containment playbooks arrive with a track record behind them.
2. Define the trigger precisely. A playbook is only as good as the condition that fires it. Most bad automation is a good action on an over-broad trigger.
3. Decide what it may do unattended. Enrich, notify, contain. Each step outward needs a stated reason and a documented rollback, not a feature flag.
4. Test the failure path, not the happy one. What happens when the API is down, the identity is stale, the entity is missing. A playbook that has only been tested when everything works is untested.
5. Govern it as code. Version it, review changes and measure what it did. Automation nobody audits becomes automation nobody trusts, and then automation somebody disables.
What this course assumes
No minimum experience and no prerequisite course. Logic Apps, the connector model and the Sentinel automation surface are explained from the first playbook.
What makes it go faster: an Azure subscription and a Sentinel workspace you can build in. Not required, and every playbook is shown as a definition you can read.
What this course does not cover: investigation technique, detection rule writing, and incident response process. This course automates the response those disciplines decide on.
Who this course is for
You're a Security Engineer, Detection Engineer, or Security Architect who needs to scale security operations without scaling headcount. This course is built for you if you want to:
In short: if you're ready to engineer automation that lets your team do more with less and respond to threats at machine speed, this course is for you.
What you'll learn
By the end of this Microsoft 365 Security Automation and Orchestration course you will be able to:
Key course takeaways
Lab Pack, Build Real Automation in Your Own Sentinel Workspace
Downloadable lab pack with everything you need to build, test, and deploy the SA automation stack in your own Microsoft Sentinel environment.
Lab environment: M365 E5 tenant, a developer subscription if you qualify or a 30-day E5 trial otherwise, plus an Azure subscription and a Sentinel workspace, free for its first 31 days. No local VMs required, all automation runs in the cloud.
Watchlist seed data (5 CSVs): VIP-Users (executive accounts requiring approval gates), Known-Safe-IPs (corporate network ranges), High-Risk-Assets (servers requiring blast radius assessment), Containment-Eligible-Rules (analytics rules validated for automation tiers), CDN-Ranges (cloud provider IP exclusions).
KQL query packs (11 queries): Detection triggers, enrichment queries, evidence collection queries, health monitoring (playbook success rate, containment metrics, suppression audit), and multi-signal correlation.
Deployable automation: ARM template for SA2 enrichment playbook with staging and production parameter files. Python Azure Functions for TI enrichment and evidence packaging.
Scripts: Watchlist deployment, test incident generator (10 capstone scenarios), sample data generator (30 days of NE telemetry with planted AiTM attack), and full-stack automation deployment.
Things you need to know
What are the prerequisites for this course?
There are no prerequisites. The course teaches security automation from first principles. Familiarity with Microsoft Sentinel and KQL will help you move faster, but neither is required. Every concept is explained at first use.
What are the device requirements?
A device with a modern browser. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) and an Azure subscription for Sentinel and Logic Apps deployment. The course walks you through setup in Module 0.
How will the course benefit your career?
Security automation is how modern SOCs scale. Organizations need engineers who can build the playbooks, Logic Apps, and governance frameworks that turn manual procedures into automated workflows. This course gives you the skills to design, deploy, and govern automation across the Microsoft security stack.
The demand for SOAR-capable security engineers continues to grow as organizations move from manual incident response to automated detection, enrichment, and containment.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy playbooks, automation rules, KQL queries, and Azure Functions in your production environment. You may not redistribute course content or share account credentials.
Automation artifacts: All playbooks and functions are provided as-is. Test every automation in a staging workspace before production deployment. Automated containment actions have business impact. Ridgeline Cyber Defence is not responsible for operational impact from deployed automation.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
Version and changelog
Current version: 1.2 | Last updated: June 2026
June 2026, v1.2: Course renamed to Microsoft 365 Security Automation and Orchestration.
June 2026, v1.1: Course renamed to Sentinel Automation and Orchestration.
June 2026, v1.0: Course page restructured. 14 modules across 3 tiers. 7 deployable Logic App playbooks, 4 Azure Functions, 11 KQL query packs, 5 governance watchlists.
This course is actively maintained.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.