Microsoft 365 SOC Engineering

Master Microsoft 365 SOC Engineering

Build and run a high-performing Security Operations Center in Microsoft 365. Design, implement, and optimize modern SOC infrastructure, processes, and workflows using Microsoft Defender XDR, Microsoft Sentinel, Entra ID, and the full Microsoft security stack; so you can detect, respond, and mature your operations at enterprise scale.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Practice included: scored investigation scenarios, plus the Practice Hub.
View Pricing Take End of Course Exam → 36 CPE Credits

What you'll be able to do

Design and implement a complete SOC architecture and operating model in Microsoft 365 environments
Deploy, configure, and optimise Microsoft Defender XDR, Microsoft Sentinel, Entra ID, and supporting security tools
Build and run efficient SOC workflows for alert triage, investigation, threat hunting, and response
Establish automation, playbooks, and processes that scale operations effectively
Define and track meaningful SOC metrics to measure performance and drive continuous improvement
Mature your SOC from reactive monitoring to a proactive, high-performing security capability
SEC302 | Premium tier | 14 modules across 4 phases | 36–40 hours at your own pace | 36 CPE credits | Updated June 2026

Course Syllabus

Every module and every lesson. Open a module to see its lessons.

Download the full syllabus (PDF)

Phase 1: Foundation

S0
Course OrientationCourse Preview

What Microsoft 365 SOC Engineering teaches: how to build and run a security operation that detects, responds, and matures.

8 lessonsHide lessons
  1. 0.1 What a SOC Actually DoesPreview
  2. 0.2 The Four Security Operations FunctionsPreview
  3. 0.3 Where Most SOCs FailPreview
  4. 0.4 The SOC Maturity SpectrumPreview
  5. 0.5 The Detection-and-Response PipelinePreview
  6. 0.6 What This Course BuildsPreview
  7. 0.7 Lab Environment and How to StudyPreview
  8. Module SummaryPreview
S2
Detection Engineering Methodology

Build the detection engineering methodology that governs every rule in the course, threat modeling, detection rule specifications, quality metrics, false positive management, detection-as-code practices, and the...

10 lessonsHide lessons
  1. 2.1 The Detection Engineering Lifecycle
  2. 2.2 Threat Modeling for Detection Prioritization
  3. 2.3 MITRE ATT&CK as a Detection Framework
  4. 2.4 Writing Detection Rule Specifications
  5. 2.5 Detection Rule Quality Metrics
  6. 2.6 False Positive Management
  7. 2.7 Detection-as-Code
  8. 2.8 Building and Managing a Detection Backlog
  9. Module Summary
  10. Check My Knowledge

Phase 2: Detection Libraries

Phase 4: Operational Maturity

S12
Building a Threat Intelligence Program

Threat intelligence program design, indicator lifecycle management, STIX/TAXII feed integration, hunting hypothesis generation from TI, and the operational workflow that converts intelligence into detection and...

10 lessonsHide lessons
  1. 12.1 Threat Intelligence Fundamentals for SOC Analysts
  2. 12.2 Building a TI Collection Program
  3. 12.3 Indicator Lifecycle Management
  4. 12.4 STIX/TAXII Integration with Sentinel
  5. 12.5 Converting TI into Detection Hypotheses
  6. 12.6 TI-Driven Threat Hunting
  7. 12.7 TI Operations Playbook
  8. 12.8 TI Maturity Assessment
  9. Module Summary
  10. Check My Knowledge
S13
Copilot for Security in SOC Operations

Using Microsoft Copilot for Security as the AI layer across the SOC operational model, incident investigation, KQL generation, threat hunting, promptbook automation, agent-driven triage, and the governance framework...

10 lessonsHide lessons
  1. 13.1 What Copilot for Security Is (and Isn't)
  2. 13.2 Embedded Experience: Incident Investigation
  3. 13.3 Natural Language to KQL
  4. 13.4 AI-Augmented Threat Hunting
  5. 13.5 Promptbooks for SOC Workflows
  6. 13.6 Copilot Agents and Automation
  7. 13.7 Governance, Cost, and Limitations
  8. 13.8 Building AI-Augmented SOC Operations
  9. Module Summary
  10. Check My Knowledge

Phase 0: Course Resources

S91
Cookbooks

Seven procedures a SOC engineer repeats: building a detection, tuning it, deploying it to both surfaces, and the cycles around them.

7 lessonsHide lessons
  1. Building a Detection
  2. Tuning a Noisy Rule
  3. Working an Incident to a Report
  4. Onboarding a Log Source
  5. Running a Detection Sprint
  6. Retiring a Detection
  7. The Monthly Reporting Cycle
S92
Lab Setup

A complete SOC lab: tenant, workspace, Sentinel, connectors, detectable activity, and the cost controls that stop it running away.

5 lessonsHide lessons
  1. Workspace and Sentinel
  2. Connecting the Sources
  3. Generating Detectable Activity
  4. Deploying and Proving a Rule
  5. Verify, Costs and Limits
S93
Walkthroughs

Worked detection engineering cases end to end, including the wrong turns, the queries that looked right and were not, and what would have changed each answer.

7 lessonsHide lessons
  1. The Rule That Fired on Everything
  2. The Rule That Missed It
  3. The Alert Nobody Could Work
  4. The Quarter That Looked Good
  5. Three Incidents That Were One
  6. The Rule That Did Not Translate
  7. The Fix That Broke the Detection
S94
Playbooks

Seven events that arrive at a SOC engineer with a decision attached, each with prerequisites, a pre-flight, a numbered sequence and a worked handoff.

7 lessonsHide lessons
  1. A Rule Stopped Firing
  2. A Connector Degraded
  3. An Incident Was Missed
  4. An Automation Took a Wrong Action
  5. A Threat Advisory Arrived
  6. Somebody Asked If We Are Covered
  7. The Workspace Bill Jumped
S95
Playground

Where to practice the detection engineering in this course against populated data and real deployment surfaces.

Resources

References

The quick reference and field manual for this course: the queries, configuration steps and procedures, organized for use during live work.

3 lessonsHide lessons
  1. Microsoft 365 SOC Engineering Quick Reference
  2. References & Further Reading
  3. Microsoft 365 SOC Engineering Field Manual

Course Completion

Course Exam

Microsoft 365 SOC Engineering end-of-course exam, a simulation-based assessment testing your ability to triage, investigate, and respond to a multi-stage incident using the skills built across all 14 modules.

1 lessonsHide lessons
  1. Course Completion. Microsoft 365 SOC Engineering

Course overview

The Microsoft 365 SOC Engineering course is built specifically for Security Engineers, Detection Engineers, and Operations Managers responsible for building SOC infrastructure in Microsoft 365 environments. You'll gain hands-on expertise to:

Design and implement a complete Microsoft 365 SOC architecture and operating model
Deploy, configure, and optimize Microsoft Defender XDR, Microsoft Sentinel, and supporting security services
Build efficient SOC workflows for triage, investigation, hunting, automation, and reporting
Establish metrics, playbooks, and processes that drive continuous SOC maturity

By the end, you'll have the strategic and technical skills to build, run, and mature a modern, effective Microsoft 365 Security Operations Center that delivers real security outcomes.

How this course works

A SOC is an engineering product: detections, playbooks, automation and the measurements that tell you whether any of it works. This course runs the same loop for every capability it builds.

1. Establish readiness before capability. Coverage, data sources, roles and escalation paths. Detections built on top of an unclear operating model produce alerts nobody owns.

2. Engineer detections by surface. Identity, email, endpoint, cloud. Each has its own telemetry, its own false positive profile and its own tuning problem.

3. Write the playbook the detection needs. An alert with no investigation path is an alert that gets closed on instinct.

4. Automate what the playbook proved repetitive. Automation built before the manual process is understood automates a guess.

5. Measure, then improve something specific. SOC metrics that nobody acts on are a reporting habit. The measurement exists to change a decision.

What this course assumes

No minimum experience and no prerequisite course. The detection model, the Sentinel surface and the operating concepts are built up from nothing.

What makes it go faster: a workspace you can build in and an alert queue you have seen. Neither is required.

What this course does not cover: forensics, architecture design and GRC. This course builds and runs the SOC as an engineering function.

Who this course is for

You're a Security Engineer, Detection Engineer, or Operations Manager responsible for building or running a Security Operations Center in Microsoft 365 environments. This course is built for you if you want to:

Move from fragmented tool deployment to a well-designed, integrated SOC infrastructure
Master the configuration and daily operations of the full Microsoft security stack
Build scalable processes, automation, and workflows that improve SOC efficiency
Develop both technical depth and operational maturity for your security program

In short: if you're responsible for designing, building, or optimizing a modern Microsoft 365 SOC, this course is for you.

What you'll learn

By the end of this Microsoft 365 SOC Engineering course you will be able to:

Architect and implement a modern Microsoft 365 SOC operating model and technology stack
Deploy and tune Microsoft Defender XDR, Microsoft Sentinel, Entra ID Protection, and related services
Design and operationalize effective SOC workflows for triage, investigation, hunting, and automation
Integrate Microsoft security tools into unified processes with clear visibility and handoffs
Establish SOC metrics, reporting, and continuous improvement frameworks
Build playbooks, runbooks, and automation that reduce response times and operational overhead

Key course takeaways

Build and run a production-grade Microsoft 365 SOC infrastructure that delivers real results
Master the integration and operation of Defender XDR, Sentinel, and the broader Microsoft security stack
Create scalable, efficient SOC processes and automation that reduce alert fatigue and improve outcomes
Establish clear metrics and maturity models to continuously improve your security operations
Develop both the technical and operational skills needed to lead a high-performing SOC
Become the SOC leader who transforms tools and people into a cohesive, effective security capability

Things you need to know

What are the prerequisites for this course?

There are no prerequisites. The course teaches SOC operations from first principles. Familiarity with Microsoft 365, Sentinel, and KQL will help you move faster, but neither is required. Every concept, tool, and process is explained at first use.

What are the device requirements?

A device with a modern browser. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) with Sentinel and Defender XDR for hands-on exercises. The course walks you through setup in Module 0.

How will the course benefit your career?

SOC operations is the foundation of enterprise security. Organizations need people who can design the SOC architecture, build the detection library, create the investigation playbooks, and measure the outcomes. This course gives you the complete toolkit, from SOC design through operational maturity.

SOC operations capability is a prerequisite for SOC management, security engineering, and security leadership roles.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy detection rules, playbooks, and operational frameworks in your production environment. You may not redistribute course content or share account credentials.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

Version and changelog

Current version: 1.1  |  Last updated: June 2026

June 2026, v1.1: Course renamed to Microsoft 365 SOC Engineering.

June 2026, v1.0: Course page restructured. 14 modules across 4 phases. 28 detection rules, 3 investigation playbooks, operational metrics framework.

This course is actively maintained.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.