Microsoft 365 SOC Engineering
Master Microsoft 365 SOC Engineering
Build and run a high-performing Security Operations Center in Microsoft 365. Design, implement, and optimize modern SOC infrastructure, processes, and workflows using Microsoft Defender XDR, Microsoft Sentinel, Entra ID, and the full Microsoft security stack; so you can detect, respond, and mature your operations at enterprise scale.
What you'll be able to do
Course Syllabus
Every module and every lesson. Open a module to see its lessons.
Download the full syllabus (PDF)
Phase 1: Foundation
What Microsoft 365 SOC Engineering teaches: how to build and run a security operation that detects, responds, and matures.
8 lessonsHide lessons
- 0.1 What a SOC Actually DoesPreview
- 0.2 The Four Security Operations FunctionsPreview
- 0.3 Where Most SOCs FailPreview
- 0.4 The SOC Maturity SpectrumPreview
- 0.5 The Detection-and-Response PipelinePreview
- 0.6 What This Course BuildsPreview
- 0.7 Lab Environment and How to StudyPreview
- Module SummaryPreview
The operational foundation that turns a team running on habits into a team running on documented, measurable process.
12 lessonsHide lessons
- 1.1 SOC Operating Models
- 1.2 Analyst Tiers and Role Architecture
- 1.3 Shift Handover Design
- 1.4 Escalation Framework
- 1.5 The Triage Decision Framework
- 1.6 Operational Metrics. Speed vs Quality
- 1.7 The SOC Charter
- 1.8 Tool Stack Integration
- 1.9 SOC Maturity Assessment
- 1.10 Incident Classification Framework
- Module Summary
- Check My Knowledge
Build the detection engineering methodology that governs every rule in the course, threat modeling, detection rule specifications, quality metrics, false positive management, detection-as-code practices, and the...
10 lessonsHide lessons
- 2.1 The Detection Engineering Lifecycle
- 2.2 Threat Modeling for Detection Prioritization
- 2.3 MITRE ATT&CK as a Detection Framework
- 2.4 Writing Detection Rule Specifications
- 2.5 Detection Rule Quality Metrics
- 2.6 False Positive Management
- 2.7 Detection-as-Code
- 2.8 Building and Managing a Detection Backlog
- Module Summary
- Check My Knowledge
Phase 2: Detection Libraries
Build seven production detection rules for identity-based attacks in Entra ID, anomalous sign-ins, MFA fatigue, impossible travel, privileged role assignment, service principal credential abuse, Conditional Access...
10 lessonsHide lessons
- 3.1 SigninLogs Deep Dive. Schema, Fields, and Query Patterns
- 3.2 Detection: Anomalous Sign-In from Unfamiliar Infrastructure
- 3.3 Detection: MFA Fatigue and Push Notification Abuse
- 3.4 Detection: Impossible Travel
- 3.5 Detection: Privileged Role Assignment Outside PIM
- 3.6 Detection: Service Principal Credential Manipulation
- 3.7 Detection: Conditional Access Policy Modification
- 3.8 Detection: Bulk Sign-In Failures Indicating Password Spray
- Module Summary
- Check My Knowledge
Build seven production detection rules for BEC operations in Microsoft 365, inbox forwarding, hiding rules, transport rule manipulation, bulk mailbox access, AiTM phishing, mailbox delegation, and outbound BEC execution.
10 lessonsHide lessons
- 4.1 Email Data Sources in Sentinel. OfficeActivity, EmailEvents, and CloudAppEvents
- 4.2 Detection: Inbox Forwarding Rule to External Domain After Anomalous Sign-In
- 4.3 Detection: Inbox Rule Deleting or Moving Items to Hide Adversary Activity
- 4.4 Detection: Mail Flow Transport Rule Manipulation
- 4.5 Detection: Bulk Mailbox Access After Account Compromise
- 4.6 Detection: Email Containing AiTM Phishing Indicators
- 4.7 Detection: Mailbox Delegation and Permission Changes
- 4.8 Detection: Suspicious Outbound Email Patterns Indicating BEC Execution
- Module Summary
- Check My Knowledge
Build seven detection rules for endpoint attack surfaces, LOLBin execution chains, credential dumping, lateral movement, persistence mechanisms, ransomware pre-encryption, data staging and exfiltration, and...
10 lessonsHide lessons
- 5.1 Defender for Endpoint Data Sources. Schema and Query Patterns
- 5.2 Detection: LOLBin Execution Chains
- 5.3 Detection: Credential Dumping Indicators
- 5.4 Detection: Lateral Movement via SMB, WinRM, and RDP
- 5.5 Detection: Persistence via Scheduled Tasks, Services, and Registry
- 5.6 Detection: Ransomware Pre-Encryption Indicators
- 5.7 Detection: Data Staging and Exfiltration Indicators
- 5.8 Detection: PowerShell and Script-Based Execution
- Module Summary
- Check My Knowledge
Build seven detection rules for cloud and SaaS attack surfaces, OAuth consent phishing, shadow IT, Azure resource manipulation, storage exfiltration, cross-tenant access, application permission escalation, and cloud...
10 lessonsHide lessons
- 6.1 Cloud Application Data Sources
- 6.2 Detection: Illicit OAuth Application Consent
- 6.3 Detection: Shadow IT and Unsanctioned Application Usage
- 6.4 Detection: Azure Resource Manipulation
- 6.5 Detection: Storage Account Exfiltration Indicators
- 6.6 Detection: Cross-Tenant Access Anomalies
- 6.7 Detection: Application Permission Escalation
- 6.8 Detection: Cloud Session Anomalies
- Module Summary
- Check My Knowledge
Phase 3: Investigation & Response
Structured investigation workflows for SOC analysts.
10 lessonsHide lessons
- 7.1 Playbook Architecture. Structure, Standards, and Design Principles
- 7.2 Evidence Collection and Preservation Standards
- 7.3 Containment Decision Framework
- 7.4 Playbook: AiTM Credential Phishing Investigation
- 7.5 Playbook: BEC Financial Fraud Investigation
- 7.6 Playbook: Ransomware Pre-Encryption Detection and Response
- 7.7 Playbook Maintenance and Continuous Improvement
- 7.8 Building Custom Playbooks for Your Environment
- Module Summary
- Check My Knowledge
Formal incident response documentation from initial notification through post-incident review.
10 lessonsHide lessons
- 8.1 The Incident Documentation Lifecycle
- 8.2 Writing the Executive Incident Summary
- 8.3 Building the Technical Investigation Timeline
- 8.4 Evidence Documentation and Chain of Custody
- 8.5 Regulatory Notification Assessment
- 8.6 Third-Party and Stakeholder Communication
- 8.7 Post-Incident Review Framework
- 8.8 IR Report Template Pack
- Module Summary
- Check My Knowledge
Phase 4: Operational Maturity
M365 tenant hardening checklists, Exchange Online protection baselines, Entra ID conditional access templates, endpoint security baselines, and validation KQL queries, the preventive controls that reduce your...
12 lessonsHide lessons
- 9.1 The Relationship Between Hardening and Detection
- 9.2 Entra ID Hardening Baseline
- 9.3 Exchange Online Hardening Baseline
- 9.4 Endpoint Security Baseline
- 9.5 Cloud Application Hardening
- 9.6 Hardening Validation Queries
- 9.7 Hardening Change Management
- 9.8 Hardening Checklist Pack
- 9.9 Network Segmentation and Firewall Hardening
- Module Summary
- 9.10 SharePoint and OneDrive Hardening
- Check My Knowledge
Automation rules, playbook design patterns, SOAR integration, and notification workflows that accelerate SOC response.
11 lessonsHide lessons
- 10.1 Automation Strategy. What to Automate and What to Keep Manual
- 10.2 Sentinel Automation Rules
- 10.3 Logic App Playbooks for Enrichment
- 10.4 Logic App Playbooks for Notification
- 10.5 Logic App Playbooks for Containment
- 10.6 SOAR Integration Patterns
- 10.7 Automation Testing and Monitoring
- 10.8 Automation Runbook Pack
- 10.9 Automated Enrichment Playbooks
- Module Summary
- Check My Knowledge
KPI frameworks, Sentinel workbook dashboards, detection coverage tracking, SOC maturity scoring, and monthly reporting templates.
10 lessonsHide lessons
- 11.1 From Metrics to Dashboards
- 11.2 Building the SOC Operations Workbook
- 11.3 Detection Coverage Dashboard
- 11.4 Monthly SOC Report Template
- 11.5 Quarterly SOC Maturity Review
- 11.6 Continuous Improvement Cycle
- 11.7 Benchmarking Against Industry Standards
- 11.8 Reporting to Non-Technical Stakeholders
- Module Summary
- Check My Knowledge
Threat intelligence program design, indicator lifecycle management, STIX/TAXII feed integration, hunting hypothesis generation from TI, and the operational workflow that converts intelligence into detection and...
10 lessonsHide lessons
- 12.1 Threat Intelligence Fundamentals for SOC Analysts
- 12.2 Building a TI Collection Program
- 12.3 Indicator Lifecycle Management
- 12.4 STIX/TAXII Integration with Sentinel
- 12.5 Converting TI into Detection Hypotheses
- 12.6 TI-Driven Threat Hunting
- 12.7 TI Operations Playbook
- 12.8 TI Maturity Assessment
- Module Summary
- Check My Knowledge
Using Microsoft Copilot for Security as the AI layer across the SOC operational model, incident investigation, KQL generation, threat hunting, promptbook automation, agent-driven triage, and the governance framework...
10 lessonsHide lessons
- 13.1 What Copilot for Security Is (and Isn't)
- 13.2 Embedded Experience: Incident Investigation
- 13.3 Natural Language to KQL
- 13.4 AI-Augmented Threat Hunting
- 13.5 Promptbooks for SOC Workflows
- 13.6 Copilot Agents and Automation
- 13.7 Governance, Cost, and Limitations
- 13.8 Building AI-Augmented SOC Operations
- Module Summary
- Check My Knowledge
Phase 0: Course Resources
Subject-area sheets carrying the detection in both forms this course teaches, with the fields that carry the decision and the limits on each.
Seven procedures a SOC engineer repeats: building a detection, tuning it, deploying it to both surfaces, and the cycles around them.
A complete SOC lab: tenant, workspace, Sentinel, connectors, detectable activity, and the cost controls that stop it running away.
Worked detection engineering cases end to end, including the wrong turns, the queries that looked right and were not, and what would have changed each answer.
Seven events that arrive at a SOC engineer with a decision attached, each with prerequisites, a pre-flight, a numbered sequence and a worked handoff.
Where to practice the detection engineering in this course against populated data and real deployment surfaces.
Resources
The quick reference and field manual for this course: the queries, configuration steps and procedures, organized for use during live work.
Course Completion
Microsoft 365 SOC Engineering end-of-course exam, a simulation-based assessment testing your ability to triage, investigate, and respond to a multi-stage incident using the skills built across all 14 modules.
1 lessonsHide lessons
Course overview
The Microsoft 365 SOC Engineering course is built specifically for Security Engineers, Detection Engineers, and Operations Managers responsible for building SOC infrastructure in Microsoft 365 environments. You'll gain hands-on expertise to:
By the end, you'll have the strategic and technical skills to build, run, and mature a modern, effective Microsoft 365 Security Operations Center that delivers real security outcomes.
How this course works
A SOC is an engineering product: detections, playbooks, automation and the measurements that tell you whether any of it works. This course runs the same loop for every capability it builds.
1. Establish readiness before capability. Coverage, data sources, roles and escalation paths. Detections built on top of an unclear operating model produce alerts nobody owns.
2. Engineer detections by surface. Identity, email, endpoint, cloud. Each has its own telemetry, its own false positive profile and its own tuning problem.
3. Write the playbook the detection needs. An alert with no investigation path is an alert that gets closed on instinct.
4. Automate what the playbook proved repetitive. Automation built before the manual process is understood automates a guess.
5. Measure, then improve something specific. SOC metrics that nobody acts on are a reporting habit. The measurement exists to change a decision.
What this course assumes
No minimum experience and no prerequisite course. The detection model, the Sentinel surface and the operating concepts are built up from nothing.
What makes it go faster: a workspace you can build in and an alert queue you have seen. Neither is required.
What this course does not cover: forensics, architecture design and GRC. This course builds and runs the SOC as an engineering function.
Who this course is for
You're a Security Engineer, Detection Engineer, or Operations Manager responsible for building or running a Security Operations Center in Microsoft 365 environments. This course is built for you if you want to:
In short: if you're responsible for designing, building, or optimizing a modern Microsoft 365 SOC, this course is for you.
What you'll learn
By the end of this Microsoft 365 SOC Engineering course you will be able to:
Key course takeaways
Things you need to know
What are the prerequisites for this course?
There are no prerequisites. The course teaches SOC operations from first principles. Familiarity with Microsoft 365, Sentinel, and KQL will help you move faster, but neither is required. Every concept, tool, and process is explained at first use.
What are the device requirements?
A device with a modern browser. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) with Sentinel and Defender XDR for hands-on exercises. The course walks you through setup in Module 0.
How will the course benefit your career?
SOC operations is the foundation of enterprise security. Organizations need people who can design the SOC architecture, build the detection library, create the investigation playbooks, and measure the outcomes. This course gives you the complete toolkit, from SOC design through operational maturity.
SOC operations capability is a prerequisite for SOC management, security engineering, and security leadership roles.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy detection rules, playbooks, and operational frameworks in your production environment. You may not redistribute course content or share account credentials.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
Version and changelog
Current version: 1.1 | Last updated: June 2026
June 2026, v1.1: Course renamed to Microsoft 365 SOC Engineering.
June 2026, v1.0: Course page restructured. 14 modules across 4 phases. 28 detection rules, 3 investigation playbooks, operational metrics framework.
This course is actively maintained.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.