Microsoft Security Operations

Master Microsoft Security Operations

Configure, operate, and optimize the full Microsoft Security stack to run a modern, effective Security Operations Center (SOC). Detect, investigate, respond to, and recover from threats across Microsoft 365, Entra ID, Defender XDR, Sentinel, Intune, and Purview, turning alerts into outcomes and reactive monitoring into proactive defense.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 40 CPE Credits

What you'll be able to do

✓Configure and tune the full Microsoft Security stack (Defender XDR, Sentinel, Entra ID Protection, Defender for Cloud Apps, and Purview) for optimal detection and response
✓Build and operationalise efficient SOC workflows for alert triage, investigation, automation, and remediation
✓Create and maintain detection rules, analytics rules, and automated playbooks in Microsoft Sentinel
✓Investigate and respond to cross-domain incidents across identities, endpoints, email, and cloud workloads
✓Integrate Microsoft 365 security tools into a unified operations platform with clear visibility and reporting
✓Measure, optimise, and continuously mature your security operations with meaningful metrics and reporting
SEC301 | Premium tier | 17 modules across 4 phases | 36–40 hours at your own pace | 40 CPE credits | SC-200 aligned

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Phase 1: Foundations

Module 0Course OrientationCourse Preview

What Microsoft Security Operations teaches: operate the full Microsoft security stack, Defender XDR, Sentinel, Purview, Defender for Cloud, and Security Copilot, as one SOC, running the detect, investigate, respond, and recover lifecycle and finishing on real investigation scenarios. The operation you'll run, the playbook and detections you walk away with, and how the course is structured. Start here.

Show 8 lessonsHide lessons
  1. 0.10.1 Mission, Course Structure, and Who This Is ForPreview
  2. 0.20.2 SC-200 Exam Overview and Study StrategyPreview
  3. 0.30.3 How to Learn from This CoursePreview
  4. 0.40.4 Lab Setup: M365 E5 Developer TenantPreview
  5. 0.50.5 Lab Setup: Azure Subscription and Sentinel WorkspacePreview
  6. 0.60.6 Lab Setup: Sample Data and ValidationPreview
  7. 0.7Module SummaryPreview
  8. 0.8Check My KnowledgePreview
Module 2Mitigate Threats Using Microsoft Defender for Endpoint

Deploy, configure, and operate Microsoft Defender for Endpoint as a preventive and investigative platform. Architecture and licensing decisions. Device onboarding across Windows, macOS, Linux, and down-level servers. Attack surface reduction rules. Next-generation protection and EDR configuration. Device investigation with timelines and live response. Automated investigation with progressive automation levels.

Show 10 lessonsHide lessons
  1. 2.12.1 MDE Architecture and Deployment Planning
  2. 2.22.2 Onboarding Devices Across Platforms
  3. 2.32.3 Attack Surface Reduction Rules
  4. 2.42.4 Next-Generation Protection and EDR Configuration
  5. 2.52.5 Device Investigation: Timelines, Forensics, and Evidence Collection
  6. 2.62.6 Response Actions and Live Response
  7. 2.72.7 Automated Investigation and Response (AIR)
  8. 2.82.8 Threat and Vulnerability Management
  9. 2.9Module Summary
  10. 2.10Check My Knowledge

Phase 2: Microsoft Security Stack

Module 8Connect Logs to Microsoft Sentinel

Connect every data source in your environment to Sentinel, Microsoft first-party services, Defender XDR, Windows hosts, third-party devices via Syslog and CEF, and custom applications via API ingestion. Build Data Collection Rules to filter, transform, and route data before it reaches the workspace. Troubleshoot connector failures, validate data flow, and optimize ingestion cost at the source.

Show 13 lessonsHide lessons
  1. 8.18.1 Ingestion Strategy and Connector Architecture
  2. 8.28.2 Microsoft First-Party Connectors
  3. 8.38.3 Connecting Microsoft Defender XDR
  4. 8.48.4 Connecting Windows Hosts to Sentinel
  5. 8.58.5 Common Event Format (CEF) Connectors
  6. 8.68.6 Syslog Data Sources
  7. 8.78.7 Data Collection Rules: Filter, Transform, Route
  8. 8.88.8 Custom Logs and API Ingestion
  9. 8.98.9 Connector Troubleshooting and Validation
  10. 8.108.10 Ingestion Cost Optimization at the Connector Level
  11. 8.118.11 Building the Complete Ingestion Pipeline
  12. 8.12Module Summary
  13. 8.13Check My Knowledge

Phase 3: Detection & Hunting

Module 10Create Detections and Perform Investigations Using Microsoft Sentinel

Build the detection and investigation layer that turns raw data into actionable security incidents. Create scheduled analytics rules, near-real-time rules, and Microsoft Security rules. Configure entity mapping for alert correlation. Manage incidents through the investigation lifecycle. Automate response with automation rules and Logic Apps playbooks. Deploy UEBA for behavioral anomaly detection. Build workbooks for security reporting. Normalize data with ASIM parsers.

Show 13 lessonsHide lessons
  1. 10.110.1 Analytics Rules: Architecture and Rule Types
  2. 10.210.2 Creating Scheduled Analytics Rules
  3. 10.310.3 Near-Real-Time (NRT) and Microsoft Security Rules
  4. 10.410.4 Entity Mapping and Alert Enrichment
  5. 10.510.5 Incident Management and Investigation Workflow
  6. 10.610.6 Automation Rules
  7. 10.710.7 Playbooks with Logic Apps
  8. 10.810.8 User and Entity Behavior Analytics (UEBA)
  9. 10.910.9 Workbooks and Security Reporting
  10. 10.1010.10 ASIM Parsers and Data Normalization
  11. 10.1110.11 Detection Engineering Lifecycle
  12. 10.12Module Summary
  13. 10.13Check My Knowledge
Module 11Perform Threat Hunting in Microsoft Sentinel

Move from reactive detection to proactive threat discovery. Learn hypothesis-driven hunting methodology, write hunting queries that find threats analytics rules miss, use bookmarks to collect and preserve evidence, deploy Livestream for real-time hunting, run search jobs against archived data, and build a structured hunting program with MITRE ATT&CK coverage tracking.

Show 13 lessonsHide lessons
  1. 11.111.1 Threat Hunting Concepts and Methodology
  2. 11.211.2 The Sentinel Hunting Experience
  3. 11.311.3 Writing Effective Hunting Queries
  4. 11.411.4 Hypothesis-Driven Hunting
  5. 11.511.5 Hunting Bookmarks and Evidence Collection
  6. 11.611.6 Livestream: Real-Time Hunting
  7. 11.711.7 Search Jobs and Archived Data
  8. 11.811.8 Hunt Management and Collaboration
  9. 11.911.9 MITRE ATT&CK-Driven Hunting
  10. 11.1011.10 Hunting with Notebooks
  11. 11.1111.11 Building a Hunting Program
  12. 11.12Module Summary
  13. 11.13Check My Knowledge

Phase 4: Investigation Scenarios

Module 12Investigating AiTM Credential Phishing

Full incident response on a real five-wave AiTM phishing campaign. You will investigate from first alert through containment, eradication, scope assessment, CISO reporting, hardening, and detection engineering. Every KQL query, containment action, and investigation decision is drawn from a production incident. You leave with: a complete AiTM investigation playbook, 8 deployable detection rules, an IR report template, and a hardening checklist.

Show 16 lessonsHide lessons
  1. 12.112.1 Understanding AiTM Attack Mechanics
  2. 12.212.2 Incident Briefing: INC-NE-2026-0227-001
  3. 12.312.3 Investigation Setup and Scoping
  4. 12.412.4 Email Analysis: Tracing the Phishing Campaign
  5. 12.512.5 Sign-In Log Investigation
  6. 12.612.6 Post-Compromise Activity Assessment
  7. 12.712.7 Containment
  8. 12.812.8 Eradication
  9. 12.912.9 Campaign Tracking Across Waves
  10. 12.1012.10 Scope Assessment: Who Else Was Hit?
  11. 12.1112.11 CISO Report
  12. 12.1212.12 Hardening Recommendations
  13. 12.1312.13 Detection Engineering
  14. 12.1412.14 Lessons Learned and Post-Incident Review
  15. 12.15Module Summary
  16. 12.1612.16 Check My Knowledge
Module 13Investigating BEC and Financial Fraud

Full investigation of a business email compromise leading to a vendor payment diversion attempt. You will trace the attack from initial mailbox compromise through thread hijacking, invoice manipulation, and fraudulent payment request, then contain, eradicate, and report. You leave with: a BEC investigation playbook, 6 deployable detection rules, a financial fraud response checklist, and an IR report template adapted for BEC.

Show 13 lessonsHide lessons
  1. 13.113.1 Understanding BEC Attack Mechanics
  2. 13.213.2 Incident Briefing: INC-NE-2026-0315-002
  3. 13.313.3 Mailbox Compromise Assessment
  4. 13.413.4 Email Thread Analysis
  5. 13.513.5 The Fraudulent Email
  6. 13.613.6 Financial Impact Assessment
  7. 13.713.7 Containment and Evidence Preservation
  8. 13.813.8 Law Enforcement and Banking Coordination
  9. 13.913.9 Eradication
  10. 13.1013.10 Detection Engineering
  11. 13.1113.11 Hardening Against BEC
  12. 13.12Module Summary
  13. 13.1313.13 Check My Knowledge
Module 14Investigating Token Replay and Session Hijacking

Deep investigation of post-authentication token abuse, the persistence technique that survives password resets and MFA re-registration. You will trace stolen tokens through interactive and non-interactive sign-in logs, identify token replay vs legitimate multi-device usage, assess Continuous Access Evaluation effectiveness, and deploy token-binding conditional access policies.

Show 11 lessonsHide lessons
  1. 14.114.1 How M365 Tokens Work
  2. 14.214.2 Incident Briefing: INC-NE-2026-0320-003
  3. 14.314.3 Identifying Token Replay in Sign-In Logs
  4. 14.414.4 Tracing Token Lifecycle
  5. 14.514.5 Non-Interactive Sign-In Deep Dive
  6. 14.614.6 Token-Specific Containment
  7. 14.714.7 Continuous Access Evaluation (CAE)
  8. 14.814.8 Token Protection (Token Binding)
  9. 14.914.9 Detection Engineering
  10. 14.10Module Summary
  11. 14.1114.11 Check My Knowledge
Module 15Investigating Consent Phishing and Illicit OAuth Grants

Investigate malicious OAuth application consent, the attack that grants an attacker persistent API access to mailboxes, files, and directory data without stealing any credential. You will trace the consent grant, assess the application's permissions, determine what data was accessed, revoke the grant, and deploy preventive controls.

Show 10 lessonsHide lessons
  1. 15.115.1 How OAuth Consent Works in M365
  2. 15.215.2 Incident Briefing: INC-NE-2026-0325-004
  3. 15.315.3 Identifying Malicious Consent Grants
  4. 15.415.4 Assessing What the Application Accessed
  5. 15.515.5 Revocation and Cleanup
  6. 15.615.6 Tenant-Wide Consent Audit
  7. 15.715.7 Preventive Controls
  8. 15.815.8 Detection Engineering
  9. 15.9Module Summary
  10. 15.1015.10 Check My Knowledge
Module 16Investigating Insider Threats

Investigate data exfiltration by an authorized user, the investigation type that involves HR, legal, and evidence standards that external-attacker incidents do not. You will trace file downloads, email forwarding, cloud storage uploads, and USB transfers using M365 and endpoint telemetry. You leave with: an insider threat investigation playbook, 5 deployable detection rules, an evidence preservation checklist, and an HR/legal coordination guide.

Show 10 lessonsHide lessons
  1. 16.116.1 Insider Threat Fundamentals
  2. 16.216.2 Incident Briefing: INC-NE-2026-0401-005
  3. 16.316.3 Activity Reconstruction
  4. 16.416.4 Identifying Exfiltration Channels
  5. 16.516.5 Evidence Preservation
  6. 16.616.6 HR and Legal Coordination
  7. 16.716.7 Containment Without Tipping Off
  8. 16.816.8 Detection Engineering
  9. 16.9Module Summary
  10. 16.1016.10 Check My Knowledge

Phase 0: Course Resources

ResourcesCookbooks

Ordered procedures for the work an M365 security operations analyst does: shift start, triage, investigation, containment, deployment and reporting.

Show 7 lessonsHide lessons
  1. 1Starting a Shift
  2. 2Triaging an Incident
  3. 3Containing a Compromised Identity
  4. 4Investigating Across Workloads
  5. 5Deploying a Detection Rule
  6. 6Running a Threat Hunt
  7. 7Writing the Monthly Report
ResourcesLab Setup

A trial tenant with real telemetry, the connectors that matter, and every silent failure produced on purpose.

Show 3 lessonsHide lessons
  1. 1Building the Tenant
  2. 2Producing the Silent Failures
  3. 3Verify, and What the Lab Cannot Teach
ResourcesWalkthroughs

Six investigations reasoned end to end, including the ones where the answer was that the evidence did not exist.

Show 6 lessonsHide lessons
  1. 1The Impossible Travel That Was a VPN
  2. 2The Mailbox Nobody Could Scope
  3. 3The Application Nobody Revoked
  4. 4The Rule That Never Could Have Fired
  5. 5The Departure Nobody Could Prove
  6. 6The One That Was Real
ResourcesPlaybooks

What to do when an identity alert fires, a phishing campaign lands, a rule goes quiet, or somebody asks what was exposed.

Show 7 lessonsHide lessons
  1. 1An Identity Alert Fires
  2. 2A Phishing Campaign Lands
  3. 3A Rule Has Gone Quiet
  4. 4Somebody Asks What Was Exposed
  5. 5The Queue Has Filled Up
  6. 6An Application You Do Not Recognize
  7. 7HR Asks About an Employee
ResourcesPlayground

Four Incident Lab scenarios, a three-part exam, a lab pack and your own tenant, with what each one is good for.

ResourcesOperational Reference

The commands, queries and configuration references from this course in one place, organized for lookup during live work.

Show 1 lessonHide lessons
  1. 1Operational Quick Reference
ResourcesReferences & Further Reading

External sources this course draws on: Microsoft documentation, frameworks, standards and community research.

Show 1 lessonHide lessons
  1. 1References & Further Reading

Course Completion

CompletionCourse Exam

Microsoft Security Operations end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.

Show 1 lessonHide lessons
  1. 1Course Completion. Microsoft Security Operations

Course overview

The Microsoft Security Operations course is the core training track for Security Engineers, Administrators, and Architects responsible for configuring and operating the Microsoft Security stack. You'll gain hands-on expertise to:

✓ Configure and tune Microsoft Defender XDR, Microsoft Sentinel, Entra ID Protection, and Defender for Cloud Apps for effective detection
✓ Build and run efficient security operations workflows including incident triage, investigation, automation, and response
✓ Integrate Microsoft 365 security tools into a unified SOC platform that delivers clear visibility and fast remediation
✓ Measure, optimize, and mature your security operations with actionable metrics and playbooks

By the end, you'll have the practical skills and operational mindset to run a high-performing Microsoft 365 SOC, reducing mean time to detect and respond while confidently operating the entire Microsoft security ecosystem.

How this course works

This course covers the Microsoft security stack as an operator uses it, and then works five real intrusions through it end to end. The loop is the same for each.

1. Know what each product actually sees. Defender XDR, Defender for Endpoint, Purview, Defender for Cloud and Sentinel overlap and disagree. Knowing which one holds the answer is most of the speed.

2. Get the data in before writing the query. Connectors, workspace design and retention decide what a hunt can reach. Configuration is not the boring part; it is the ceiling.

3. Query for a question you can state. KQL against a hypothesis rather than a table full of everything.

4. Investigate the intrusion, not the alert. The five worked investigations, adversary-in-the-middle, business email compromise, token replay, consent phishing and insider threat, each start where an alert did and end somewhere else.

5. Turn the finding into a rule and a document. An investigation that changes nothing has produced one closed ticket.

What this course assumes

No minimum experience and no prerequisite course. Every product surface and KQL itself are introduced from the beginning.

What makes it go faster: a tenant with Defender and Sentinel, and any prior query experience. Neither is required; the investigations run against data the course provides.

What this course does not cover: architecture and design decisions, which are a separate course, and deep forensics. This is operating the stack and investigating in it.

Who this course is for

You're a Security Engineer, Administrator, or Architect responsible for configuring and operating the Microsoft Security stack as part of your organization's Security Operations Center (SOC). This course is built for you if you want to:

✓ Move from fragmented tool management to operating a unified, high-performing Microsoft 365 SOC
✓ Master the configuration and daily operations of Defender XDR, Sentinel, Entra ID, and related security services
✓ Develop practical skills in threat detection, incident response, automation, and SOC optimization
✓ Reduce alert fatigue while dramatically improving detection and response times

In short: if you're ready to own and run effective Microsoft 365 security operations that deliver real security outcomes, this course is for you.

What you'll learn

By the end of this Microsoft Security Operations course you will be able to:

✓ Deploy, configure, and optimize Microsoft Defender XDR and Microsoft Sentinel for enterprise-scale operations
✓ Build and tune high-fidelity detections, analytics rules, and automated response playbooks
✓ Perform effective incident triage, investigation, and cross-domain threat hunting across the Microsoft security ecosystem
✓ Operationalize Identity Protection, Defender for Cloud Apps, Intune, and Purview within daily SOC workflows
✓ Integrate Microsoft security tools into cohesive processes that reduce mean time to detect (MTTD) and respond (MTTR)
✓ Measure, report on, and continuously improve your security operations maturity and effectiveness

Key course takeaways

✓ Run a production-grade Microsoft 365 SOC using the full Microsoft Security stack with confidence
✓ Master configuration and operational best practices for Defender XDR, Sentinel, Entra ID Protection, and related tools
✓ Build automated detection, investigation, and response capabilities that scale with your organization
✓ Significantly reduce alert noise while improving threat visibility and response speed
✓ Create reusable playbooks, workflows, and metrics that mature your security operations program
✓ Become the Microsoft Security Operations expert who turns tools into real, measurable defense

Things you need to know

What are the prerequisites for this course?

There are no prerequisites. The course teaches Microsoft 365 security operations from first principles. Familiarity with the Microsoft 365 admin center will help you move faster through the early modules, but is not required. Every concept is explained at first use.

What are the device requirements?

A device with a modern browser. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) for hands-on Defender XDR, Sentinel, and Entra ID configuration. The course walks you through tenant setup in Module 0.

How will the course benefit your career?

Security operations is the backbone of every organization's defense. Employers need people who can operate the Microsoft security stack as an integrated platform, not just manage individual products. This course gives you the skills to run a SOC, investigate real attack types end-to-end, and measure operational effectiveness. SC-200 exam objectives are fully covered, the certification is a side effect of operational competence.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy scripts, queries, detection rules, and playbooks in your production environment. You may not redistribute course content or share account credentials.

Security configurations: All KQL queries, detection rules, Sentinel playbooks, and Defender policies are provided as-is. Test every configuration in a non-production environment before deployment. Ridgeline Cyber Defence is not responsible for operational impact from deployed configurations.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
3scenarios
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.