Microsoft Security Operations
Master Microsoft Security Operations
Configure, operate, and optimize the full Microsoft Security stack to run a modern, effective Security Operations Center (SOC). Detect, investigate, respond to, and recover from threats across Microsoft 365, Entra ID, Defender XDR, Sentinel, Intune, and Purview, turning alerts into outcomes and reactive monitoring into proactive defense.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Phase 1: Foundations
What Microsoft Security Operations teaches: operate the full Microsoft security stack, Defender XDR, Sentinel, Purview, Defender for Cloud, and Security Copilot, as one SOC, running the detect, investigate, respond, and recover lifecycle and finishing on real investigation scenarios. The operation you'll run, the playbook and detections you walk away with, and how the course is structured. Start here.
Show 8 lessonsHide lessons
- 0.10.1 Mission, Course Structure, and Who This Is ForPreview
- 0.20.2 SC-200 Exam Overview and Study StrategyPreview
- 0.30.3 How to Learn from This CoursePreview
- 0.40.4 Lab Setup: M365 E5 Developer TenantPreview
- 0.50.5 Lab Setup: Azure Subscription and Sentinel WorkspacePreview
- 0.60.6 Lab Setup: Sample Data and ValidationPreview
- 0.7Module SummaryPreview
- 0.8Check My KnowledgePreview
Operate the unified Microsoft Defender XDR platform as an integrated investigation and response tool. Incident triage, cross-product correlation, remediation actions across email, endpoint, identity, and cloud apps. Daily SOC workflow. Advanced Hunting queries that trace multi-stage attacks across the full kill chain.
Show 10 lessonsHide lessons
- 1.11.1 Introduction to Microsoft Defender XDR Threat Protection
- 1.21.2 Mitigate Incidents Using Microsoft Defender XDR
- 1.31.3 Remediate Risks with Microsoft Defender for Office 365
- 1.41.4 Manage Microsoft Defender for Endpoint Investigations
- 1.51.5 Mitigate Threats Using Microsoft Defender for Identity
- 1.61.6 Secure Cloud Apps with Microsoft Defender for Cloud Apps
- 1.71.7 Unified Portal Operations: Daily SOC Workflow
- 1.81.8 Cross-Product Incident Correlation
- 1.9Module Summary
- 1.10Check My Knowledge
Deploy, configure, and operate Microsoft Defender for Endpoint as a preventive and investigative platform. Architecture and licensing decisions. Device onboarding across Windows, macOS, Linux, and down-level servers. Attack surface reduction rules. Next-generation protection and EDR configuration. Device investigation with timelines and live response. Automated investigation with progressive automation levels.
Show 10 lessonsHide lessons
- 2.12.1 MDE Architecture and Deployment Planning
- 2.22.2 Onboarding Devices Across Platforms
- 2.32.3 Attack Surface Reduction Rules
- 2.42.4 Next-Generation Protection and EDR Configuration
- 2.52.5 Device Investigation: Timelines, Forensics, and Evidence Collection
- 2.62.6 Response Actions and Live Response
- 2.72.7 Automated Investigation and Response (AIR)
- 2.82.8 Threat and Vulnerability Management
- 2.9Module Summary
- 2.10Check My Knowledge
Phase 2: Microsoft Security Stack
Investigate DLP alerts, insider risk incidents, audit log anomalies, and eDiscovery content searches. Master the data protection and compliance investigation capabilities that the SC-200 exam tests and that SOC analysts use when threat investigations extend beyond endpoint and identity into data access, exfiltration, and policy violations.
Show 11 lessonsHide lessons
- 3.13.1 Microsoft Purview for Security Operations
- 3.23.2 Data Loss Prevention: Policy Architecture and Alert Pipeline
- 3.33.3 Investigating DLP Alerts in the Defender Portal
- 3.43.4 Insider Risk Management: Policies, Indicators, and Risk Signals
- 3.53.5 Investigating Insider Risk Alerts and Managing Cases
- 3.63.6 Microsoft Purview Audit: Standard vs Premium
- 3.73.7 Investigating with Audit Log Search
- 3.83.8 eDiscovery: Content Search for Security Investigations
- 3.93.9 Cross-Product Investigation: Purview + Defender XDR + Sentinel
- 3.10Module Summary
- 3.11Check My Knowledge
Plan, deploy, and operationally manage Microsoft Defender for Cloud across Azure, hybrid, and multi-cloud environments. Configure cloud security posture management, enable workload protections for servers, storage, SQL, containers, and app services, investigate and remediate security alerts, and integrate Defender for Cloud with Sentinel for cross-product cloud security operations.
Show 12 lessonsHide lessons
- 4.14.1 Defender for Cloud Architecture and Foundational Concepts
- 4.24.2 Enabling and Connecting Azure Resources
- 4.34.3 Connecting Hybrid and Multi-Cloud Environments
- 4.44.4 Cloud Security Posture Management (CSPM)
- 4.54.5 Defender for Servers: Workload Protection
- 4.64.6 Defender for Storage, SQL, and App Service
- 4.74.7 Defender for Containers and Kubernetes
- 4.84.8 Security Alerts: Investigation and Remediation
- 4.94.9 Regulatory Compliance and Security Standards
- 4.104.10 Cross-Product Investigation: Defender for Cloud + Sentinel + XDR
- 4.11Module Summary
- 4.12Check My Knowledge
Use Microsoft Security Copilot to accelerate incident investigation, generate KQL queries, summarize complex alerts, perform guided threat hunting, and automate routine SOC analysis. Master the standalone experience, embedded experiences across Defender XDR, Sentinel, Entra ID, and Purview, and the prompting techniques that produce investigation-quality output.
Show 12 lessonsHide lessons
- 5.15.1 Generative AI for Security Operations
- 5.25.2 Security Copilot Architecture and Setup
- 5.35.3 Prompting Security Copilot: Techniques and Promptbooks
- 5.45.4 Embedded Copilot in Defender XDR
- 5.55.5 Embedded Copilot in Sentinel
- 5.65.6 Embedded Copilot in Entra, Purview, and Defender for Cloud
- 5.75.7 Incident Investigation with Security Copilot
- 5.85.8 Threat Hunting and KQL Generation with Copilot
- 5.95.9 Copilot Governance, Plugins, and Data Security
- 5.105.10 Cross-Product Investigation: Copilot-Assisted Workflow
- 5.11Module Summary
- 5.12Check My Knowledge
Learn to write KQL from scratch, from your first query to complex multi-table investigation joins. This module builds the skill that every subsequent module depends on.
Show 10 lessonsHide lessons
- 6.16.1 Construct KQL Statements for Microsoft Sentinel
- 6.26.2 Analyze Query Results Using KQL
- 6.36.3 Build Multi-Table Statements Using KQL
- 6.46.4 Work with String Data in KQL
- 6.56.5 Security-Specific KQL Patterns
- 6.66.6 Building an Investigation Query Library
- 6.76.7 KQL Performance Optimization and Query Debugging
- 6.86.8 Real-World Query Building Exercises
- 6.9Module Summary
- 6.10Check My Knowledge
Design, deploy, and operationally manage a Microsoft Sentinel workspace from scratch. Master workspace architecture decisions, log tier assignments, data retention policies, cost management, the key security tables and their schema, watchlists, threat intelligence integration, Defender XDR unification, Content Hub solutions, workspace health monitoring, RBAC, and multi-workspace governance.
Show 14 lessonsHide lessons
- 7.17.1 Microsoft Sentinel: SIEM + SOAR Architecture
- 7.27.2 Workspace Architecture and Design Decisions
- 7.37.3 Creating and Configuring a Sentinel Workspace
- 7.47.4 Log Types: Analytics, Basic, and Archive Tiers
- 7.57.5 Data Retention and Cost Management
- 7.67.6 Key Tables and Schema for Security Operations
- 7.77.7 Watchlists: Named Data for KQL Enrichment
- 7.87.8 Threat Intelligence in Sentinel
- 7.97.9 Integrating Defender XDR with Sentinel
- 7.107.10 Content Hub and Solutions
- 7.117.11 Workspace Health and Operational Monitoring
- 7.127.12 RBAC, Multi-Workspace, and Governance
- 7.13Module Summary
- 7.14Check My Knowledge
Connect every data source in your environment to Sentinel, Microsoft first-party services, Defender XDR, Windows hosts, third-party devices via Syslog and CEF, and custom applications via API ingestion. Build Data Collection Rules to filter, transform, and route data before it reaches the workspace. Troubleshoot connector failures, validate data flow, and optimize ingestion cost at the source.
Show 13 lessonsHide lessons
- 8.18.1 Ingestion Strategy and Connector Architecture
- 8.28.2 Microsoft First-Party Connectors
- 8.38.3 Connecting Microsoft Defender XDR
- 8.48.4 Connecting Windows Hosts to Sentinel
- 8.58.5 Common Event Format (CEF) Connectors
- 8.68.6 Syslog Data Sources
- 8.78.7 Data Collection Rules: Filter, Transform, Route
- 8.88.8 Custom Logs and API Ingestion
- 8.98.9 Connector Troubleshooting and Validation
- 8.108.10 Ingestion Cost Optimization at the Connector Level
- 8.118.11 Building the Complete Ingestion Pipeline
- 8.12Module Summary
- 8.13Check My Knowledge
Configure anti-phishing, Safe Links, Safe Attachments, ZAP, email authentication, transport rules, and Threat Explorer, the complete email protection stack for a Microsoft 365 environment.
Show 11 lessonsHide lessons
- 9.19.1 Email Threat Landscape and Architecture
- 9.29.2 Anti-Phishing Policies
- 9.39.3 Safe Links Policies
- 9.49.4 Safe Attachments Policies
- 9.59.5 Zero-Hour Auto Purge (ZAP)
- 9.69.6 Email Authentication: SPF, DKIM, DMARC
- 9.79.7 Transport Rules for Security
- 9.89.8 Threat Explorer Deep Dive
- 9.99.9 Automated Investigation and Response for Email
- 9.10Module Summary
- 9.119.11 Module Assessment
Phase 3: Detection & Hunting
Build the detection and investigation layer that turns raw data into actionable security incidents. Create scheduled analytics rules, near-real-time rules, and Microsoft Security rules. Configure entity mapping for alert correlation. Manage incidents through the investigation lifecycle. Automate response with automation rules and Logic Apps playbooks. Deploy UEBA for behavioral anomaly detection. Build workbooks for security reporting. Normalize data with ASIM parsers.
Show 13 lessonsHide lessons
- 10.110.1 Analytics Rules: Architecture and Rule Types
- 10.210.2 Creating Scheduled Analytics Rules
- 10.310.3 Near-Real-Time (NRT) and Microsoft Security Rules
- 10.410.4 Entity Mapping and Alert Enrichment
- 10.510.5 Incident Management and Investigation Workflow
- 10.610.6 Automation Rules
- 10.710.7 Playbooks with Logic Apps
- 10.810.8 User and Entity Behavior Analytics (UEBA)
- 10.910.9 Workbooks and Security Reporting
- 10.1010.10 ASIM Parsers and Data Normalization
- 10.1110.11 Detection Engineering Lifecycle
- 10.12Module Summary
- 10.13Check My Knowledge
Move from reactive detection to proactive threat discovery. Learn hypothesis-driven hunting methodology, write hunting queries that find threats analytics rules miss, use bookmarks to collect and preserve evidence, deploy Livestream for real-time hunting, run search jobs against archived data, and build a structured hunting program with MITRE ATT&CK coverage tracking.
Show 13 lessonsHide lessons
- 11.111.1 Threat Hunting Concepts and Methodology
- 11.211.2 The Sentinel Hunting Experience
- 11.311.3 Writing Effective Hunting Queries
- 11.411.4 Hypothesis-Driven Hunting
- 11.511.5 Hunting Bookmarks and Evidence Collection
- 11.611.6 Livestream: Real-Time Hunting
- 11.711.7 Search Jobs and Archived Data
- 11.811.8 Hunt Management and Collaboration
- 11.911.9 MITRE ATT&CK-Driven Hunting
- 11.1011.10 Hunting with Notebooks
- 11.1111.11 Building a Hunting Program
- 11.12Module Summary
- 11.13Check My Knowledge
Phase 4: Investigation Scenarios
Full incident response on a real five-wave AiTM phishing campaign. You will investigate from first alert through containment, eradication, scope assessment, CISO reporting, hardening, and detection engineering. Every KQL query, containment action, and investigation decision is drawn from a production incident. You leave with: a complete AiTM investigation playbook, 8 deployable detection rules, an IR report template, and a hardening checklist.
Show 16 lessonsHide lessons
- 12.112.1 Understanding AiTM Attack Mechanics
- 12.212.2 Incident Briefing: INC-NE-2026-0227-001
- 12.312.3 Investigation Setup and Scoping
- 12.412.4 Email Analysis: Tracing the Phishing Campaign
- 12.512.5 Sign-In Log Investigation
- 12.612.6 Post-Compromise Activity Assessment
- 12.712.7 Containment
- 12.812.8 Eradication
- 12.912.9 Campaign Tracking Across Waves
- 12.1012.10 Scope Assessment: Who Else Was Hit?
- 12.1112.11 CISO Report
- 12.1212.12 Hardening Recommendations
- 12.1312.13 Detection Engineering
- 12.1412.14 Lessons Learned and Post-Incident Review
- 12.15Module Summary
- 12.1612.16 Check My Knowledge
Full investigation of a business email compromise leading to a vendor payment diversion attempt. You will trace the attack from initial mailbox compromise through thread hijacking, invoice manipulation, and fraudulent payment request, then contain, eradicate, and report. You leave with: a BEC investigation playbook, 6 deployable detection rules, a financial fraud response checklist, and an IR report template adapted for BEC.
Show 13 lessonsHide lessons
- 13.113.1 Understanding BEC Attack Mechanics
- 13.213.2 Incident Briefing: INC-NE-2026-0315-002
- 13.313.3 Mailbox Compromise Assessment
- 13.413.4 Email Thread Analysis
- 13.513.5 The Fraudulent Email
- 13.613.6 Financial Impact Assessment
- 13.713.7 Containment and Evidence Preservation
- 13.813.8 Law Enforcement and Banking Coordination
- 13.913.9 Eradication
- 13.1013.10 Detection Engineering
- 13.1113.11 Hardening Against BEC
- 13.12Module Summary
- 13.1313.13 Check My Knowledge
Deep investigation of post-authentication token abuse, the persistence technique that survives password resets and MFA re-registration. You will trace stolen tokens through interactive and non-interactive sign-in logs, identify token replay vs legitimate multi-device usage, assess Continuous Access Evaluation effectiveness, and deploy token-binding conditional access policies.
Show 11 lessonsHide lessons
- 14.114.1 How M365 Tokens Work
- 14.214.2 Incident Briefing: INC-NE-2026-0320-003
- 14.314.3 Identifying Token Replay in Sign-In Logs
- 14.414.4 Tracing Token Lifecycle
- 14.514.5 Non-Interactive Sign-In Deep Dive
- 14.614.6 Token-Specific Containment
- 14.714.7 Continuous Access Evaluation (CAE)
- 14.814.8 Token Protection (Token Binding)
- 14.914.9 Detection Engineering
- 14.10Module Summary
- 14.1114.11 Check My Knowledge
Investigate malicious OAuth application consent, the attack that grants an attacker persistent API access to mailboxes, files, and directory data without stealing any credential. You will trace the consent grant, assess the application's permissions, determine what data was accessed, revoke the grant, and deploy preventive controls.
Show 10 lessonsHide lessons
- 15.115.1 How OAuth Consent Works in M365
- 15.215.2 Incident Briefing: INC-NE-2026-0325-004
- 15.315.3 Identifying Malicious Consent Grants
- 15.415.4 Assessing What the Application Accessed
- 15.515.5 Revocation and Cleanup
- 15.615.6 Tenant-Wide Consent Audit
- 15.715.7 Preventive Controls
- 15.815.8 Detection Engineering
- 15.9Module Summary
- 15.1015.10 Check My Knowledge
Investigate data exfiltration by an authorized user, the investigation type that involves HR, legal, and evidence standards that external-attacker incidents do not. You will trace file downloads, email forwarding, cloud storage uploads, and USB transfers using M365 and endpoint telemetry. You leave with: an insider threat investigation playbook, 5 deployable detection rules, an evidence preservation checklist, and an HR/legal coordination guide.
Show 10 lessonsHide lessons
- 16.116.1 Insider Threat Fundamentals
- 16.216.2 Incident Briefing: INC-NE-2026-0401-005
- 16.316.3 Activity Reconstruction
- 16.416.4 Identifying Exfiltration Channels
- 16.516.5 Evidence Preservation
- 16.616.6 HR and Legal Coordination
- 16.716.7 Containment Without Tipping Off
- 16.816.8 Detection Engineering
- 16.9Module Summary
- 16.1016.10 Check My Knowledge
Phase 0: Course Resources
The KQL, the workspace, the connectors and the investigation pivots, one sheet per part of the stack.
Show 11 lessonsHide lessons
- 1KQL That Holds Up
- 2Defender XDR and the Endpoint
- 3The Workspace and What Reaches It
- 4Purview, DLP and the Audit Log
- 5Email Security and Phishing
- 6Detection Rules That Work
- 7Hunting With a Hypothesis
- 8AiTM, Token Replay and Session Theft
- 9BEC, Consent Phishing and Insider Threat
- 10Cloud Posture and Copilot
- 11Metrics and Reporting
Ordered procedures for the work an M365 security operations analyst does: shift start, triage, investigation, containment, deployment and reporting.
A trial tenant with real telemetry, the connectors that matter, and every silent failure produced on purpose.
Show 3 lessonsHide lessons
Six investigations reasoned end to end, including the ones where the answer was that the evidence did not exist.
What to do when an identity alert fires, a phishing campaign lands, a rule goes quiet, or somebody asks what was exposed.
Four Incident Lab scenarios, a three-part exam, a lab pack and your own tenant, with what each one is good for.
The commands, queries and configuration references from this course in one place, organized for lookup during live work.
Show 1 lessonHide lessons
External sources this course draws on: Microsoft documentation, frameworks, standards and community research.
Show 1 lessonHide lessons
Course Completion
Microsoft Security Operations end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.
Show 1 lessonHide lessons
Course overview
The Microsoft Security Operations course is the core training track for Security Engineers, Administrators, and Architects responsible for configuring and operating the Microsoft Security stack. You'll gain hands-on expertise to:
By the end, you'll have the practical skills and operational mindset to run a high-performing Microsoft 365 SOC, reducing mean time to detect and respond while confidently operating the entire Microsoft security ecosystem.
How this course works
This course covers the Microsoft security stack as an operator uses it, and then works five real intrusions through it end to end. The loop is the same for each.
1. Know what each product actually sees. Defender XDR, Defender for Endpoint, Purview, Defender for Cloud and Sentinel overlap and disagree. Knowing which one holds the answer is most of the speed.
2. Get the data in before writing the query. Connectors, workspace design and retention decide what a hunt can reach. Configuration is not the boring part; it is the ceiling.
3. Query for a question you can state. KQL against a hypothesis rather than a table full of everything.
4. Investigate the intrusion, not the alert. The five worked investigations, adversary-in-the-middle, business email compromise, token replay, consent phishing and insider threat, each start where an alert did and end somewhere else.
5. Turn the finding into a rule and a document. An investigation that changes nothing has produced one closed ticket.
What this course assumes
No minimum experience and no prerequisite course. Every product surface and KQL itself are introduced from the beginning.
What makes it go faster: a tenant with Defender and Sentinel, and any prior query experience. Neither is required; the investigations run against data the course provides.
What this course does not cover: architecture and design decisions, which are a separate course, and deep forensics. This is operating the stack and investigating in it.
Who this course is for
You're a Security Engineer, Administrator, or Architect responsible for configuring and operating the Microsoft Security stack as part of your organization's Security Operations Center (SOC). This course is built for you if you want to:
In short: if you're ready to own and run effective Microsoft 365 security operations that deliver real security outcomes, this course is for you.
What you'll learn
By the end of this Microsoft Security Operations course you will be able to:
Key course takeaways
Things you need to know
What are the prerequisites for this course?
There are no prerequisites. The course teaches Microsoft 365 security operations from first principles. Familiarity with the Microsoft 365 admin center will help you move faster through the early modules, but is not required. Every concept is explained at first use.
What are the device requirements?
A device with a modern browser. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) for hands-on Defender XDR, Sentinel, and Entra ID configuration. The course walks you through tenant setup in Module 0.
How will the course benefit your career?
Security operations is the backbone of every organization's defense. Employers need people who can operate the Microsoft security stack as an integrated platform, not just manage individual products. This course gives you the skills to run a SOC, investigate real attack types end-to-end, and measure operational effectiveness. SC-200 exam objectives are fully covered, the certification is a side effect of operational competence.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy scripts, queries, detection rules, and playbooks in your production environment. You may not redistribute course content or share account credentials.
Security configurations: All KQL queries, detection rules, Sentinel playbooks, and Defender policies are provided as-is. Test every configuration in a non-production environment before deployment. Ridgeline Cyber Defence is not responsible for operational impact from deployed configurations.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.