Microsoft 365 Security Automation and Orchestration

Master Microsoft 365 Security Automation and Orchestration

Scale your security operations without scaling headcount. Design, build, and operationalize powerful automation and orchestration workflows using Microsoft Sentinel, Logic Apps, Playbooks, and Defender XDR, so you can respond to threats faster, reduce manual work, and run a more efficient, effective SOC.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Download Lab Pack Take End of Course Exam → 40 CPE Credits

What you'll be able to do

Design and build end-to-end security automation workflows that scale your SOC without adding headcount
Create powerful playbooks in Microsoft Sentinel using Logic Apps, KQL, and automation connectors
Automate alert triage, enrichment, investigation, and response actions across Microsoft security tools
Orchestrate cross-tool and cross-platform responses (M365, Entra ID, Defender XDR, endpoints, and external systems)
Implement SOAR capabilities that reduce manual work and accelerate mean time to respond (MTTR)
Measure, monitor, and continuously improve your security automation maturity and ROI
SEC202 | Premium tier | 14 modules across 3 tiers | 36–40 hours at your own pace | 36 CPE credits | Updated June 2026

Course Syllabus

Every module and every lesson. Open a module to see its lessons.

Download the full syllabus (PDF)

Phase 2: Enrichment & Collection

Phase 3: Response Automation

Phase 4: Operational Mastery

Phase 0: Course Resources

SA92
Lab Setup

A lab with disposable targets, so containment automation can be tested without locking you out of the tenant running it.

5 lessonsHide lessons
  1. Workspace and Logic Apps
  2. Disposable Targets
  3. Your First Playbook
  4. Testing Containment Safely
  5. Verify and Limits
SA95
Playground

Where to practice building automation, and the one thing about this discipline no practice surface can give you.

SA96
Operational Reference

The consolidated lookup and the step-by-step procedures from this course, in one place.

2 lessonsHide lessons
  1. Automation Quick Reference
  2. Security Automation Field Manual
SA97
References & Further Reading

External sources this course draws on: vendor documentation, frameworks, standards, and research.

Course Completion

Course Exam

Security Automation end-of-course exam, a simulation-based assessment testing whether you can diagnose, contain, and remediate an automation failure under pressure, using the engineering and judgment built across all...

1 lessonsHide lessons
  1. Course Completion. Security Automation

Course overview

The Microsoft 365 Security Automation and Orchestration course is built specifically for Security Engineers, Detection Engineers, and Architects who need to scale operations without scaling headcount. You'll gain hands-on expertise to:

Design and implement automated detection, investigation, and response workflows
Build powerful playbooks in Microsoft Sentinel using Logic Apps and KQL
Orchestrate cross-tool actions across Microsoft 365, Entra ID, Defender XDR, and external systems
Create SOAR capabilities that reduce alert fatigue and accelerate incident response

By the end, you'll have the practical skills and engineering mindset to automate repetitive tasks, standardize response processes, and dramatically improve your organization's security efficiency and effectiveness.

How this course works

Automation in a SOC is a decision about what a machine may do without asking. This course runs the same loop for every playbook it builds, because the failure mode is not a playbook that breaks but one that acts confidently on a wrong input.

1. Automate the reading before the acting. Enrichment and evidence collection are safe, immediately valuable and reversible. Start there and the containment playbooks arrive with a track record behind them.

2. Define the trigger precisely. A playbook is only as good as the condition that fires it. Most bad automation is a good action on an over-broad trigger.

3. Decide what it may do unattended. Enrich, notify, contain. Each step outward needs a stated reason and a documented rollback, not a feature flag.

4. Test the failure path, not the happy one. What happens when the API is down, the identity is stale, the entity is missing. A playbook that has only been tested when everything works is untested.

5. Govern it as code. Version it, review changes and measure what it did. Automation nobody audits becomes automation nobody trusts, and then automation somebody disables.

What this course assumes

No minimum experience and no prerequisite course. Logic Apps, the connector model and the Sentinel automation surface are explained from the first playbook.

What makes it go faster: an Azure subscription and a Sentinel workspace you can build in. Not required, and every playbook is shown as a definition you can read.

What this course does not cover: investigation technique, detection rule writing, and incident response process. This course automates the response those disciplines decide on.

Who this course is for

You're a Security Engineer, Detection Engineer, or Security Architect who needs to scale security operations without scaling headcount. This course is built for you if you want to:

Move from manual, repetitive security tasks to fully automated and orchestrated workflows
Master Microsoft Sentinel playbooks, Logic Apps, and SOAR techniques for real-world operations
Automate detection engineering, incident response, and threat hunting processes
Dramatically improve SOC efficiency while reducing alert fatigue and burnout

In short: if you're ready to engineer automation that lets your team do more with less and respond to threats at machine speed, this course is for you.

What you'll learn

By the end of this Microsoft 365 Security Automation and Orchestration course you will be able to:

Design and implement automation strategies for detection, investigation, and response
Build advanced playbooks in Microsoft Sentinel using Logic Apps, KQL, and connectors
Orchestrate automated actions across Microsoft Defender XDR, Entra ID, Microsoft 365, and external tools
Automate threat enrichment, containment, eradication, and recovery processes
Create reusable automation assets, templates, and best practices for your organization
Measure automation effectiveness and continuously mature your SOAR capabilities

Key course takeaways

Build production-grade security automation and orchestration that scales your operations efficiently
Master Microsoft Sentinel playbooks and Logic Apps to automate repetitive SOC tasks
Significantly reduce manual effort, alert fatigue, and mean time to respond
Create reliable, auditable automated workflows for detection, investigation, and response
Develop a reusable automation library that delivers long-term ROI for your security program
Become the Security Automation expert who transforms your SOC from reactive to highly efficient and proactive

Lab Pack, Build Real Automation in Your Own Sentinel Workspace

Downloadable lab pack with everything you need to build, test, and deploy the SA automation stack in your own Microsoft Sentinel environment.

Lab environment: M365 E5 tenant, a developer subscription if you qualify or a 30-day E5 trial otherwise, plus an Azure subscription and a Sentinel workspace, free for its first 31 days. No local VMs required, all automation runs in the cloud.

Watchlist seed data (5 CSVs): VIP-Users (executive accounts requiring approval gates), Known-Safe-IPs (corporate network ranges), High-Risk-Assets (servers requiring blast radius assessment), Containment-Eligible-Rules (analytics rules validated for automation tiers), CDN-Ranges (cloud provider IP exclusions).

KQL query packs (11 queries): Detection triggers, enrichment queries, evidence collection queries, health monitoring (playbook success rate, containment metrics, suppression audit), and multi-signal correlation.

Deployable automation: ARM template for SA2 enrichment playbook with staging and production parameter files. Python Azure Functions for TI enrichment and evidence packaging.

Scripts: Watchlist deployment, test incident generator (10 capstone scenarios), sample data generator (30 days of NE telemetry with planted AiTM attack), and full-stack automation deployment.

Security Automation Lab Pack
5 watchlists · 11 KQL queries · ARM templates · Azure Functions · 10 capstone scenarios
Download Lab Pack (.zip)

Things you need to know

What are the prerequisites for this course?

There are no prerequisites. The course teaches security automation from first principles. Familiarity with Microsoft Sentinel and KQL will help you move faster, but neither is required. Every concept is explained at first use.

What are the device requirements?

A device with a modern browser. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) and an Azure subscription for Sentinel and Logic Apps deployment. The course walks you through setup in Module 0.

How will the course benefit your career?

Security automation is how modern SOCs scale. Organizations need engineers who can build the playbooks, Logic Apps, and governance frameworks that turn manual procedures into automated workflows. This course gives you the skills to design, deploy, and govern automation across the Microsoft security stack.

The demand for SOAR-capable security engineers continues to grow as organizations move from manual incident response to automated detection, enrichment, and containment.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy playbooks, automation rules, KQL queries, and Azure Functions in your production environment. You may not redistribute course content or share account credentials.

Automation artifacts: All playbooks and functions are provided as-is. Test every automation in a staging workspace before production deployment. Automated containment actions have business impact. Ridgeline Cyber Defence is not responsible for operational impact from deployed automation.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

Version and changelog

Current version: 1.2  |  Last updated: June 2026

June 2026, v1.2: Course renamed to Microsoft 365 Security Automation and Orchestration.

June 2026, v1.1: Course renamed to Sentinel Automation and Orchestration.

June 2026, v1.0: Course page restructured. 14 modules across 3 tiers. 7 deployable Logic App playbooks, 4 Azure Functions, 11 KQL query packs, 5 governance watchlists.

This course is actively maintained.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.