Microsoft Cloud Incident Response

Investigate, Contain, and Recover from M365 Incidents

Build the complete incident response capability for Microsoft 365 environments. From configuring the environment that preserves evidence to running the investigation that finds the attacker to executing the containment that stops them.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Practice included: forensic cases, plus the Practice Hub.
View Pricing Download Lab Pack Take End of Course Exam → 40 CPE Credits

What you'll be able to do

✓Lead full-scope incident response investigations using a proven forensic methodology
✓Collect and analyze digital evidence from Windows systems, Microsoft 365, Entra ID, and hybrid environments
✓Reconstruct accurate attacker timelines and root cause analysis
✓Perform effective containment, eradication, and recovery while preserving evidence integrity
✓Document investigations clearly for internal stakeholders, legal, or compliance requirements
✓Translate investigation findings into actionable improvements in detection and prevention
FOR401 | Premium tier | 11 modules across 5 phases | 36–40 hours at your own pace | 40 CPE credits

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Phase 1: Orientation and Foundations

Module 0Course OrientationCourse Preview

What a Microsoft 365 investigation can physically reach, how to work through the course, the estate every example runs on, where the evidence lives, and the toolkit.

Show 5 lessonsHide lessons
  1. 0.1IR0.1 What This Course Covers, and What It Does NotPreview
  2. 0.2IR0.2 How to Work Through This CoursePreview
  3. 0.3IR0.3 The Estate This Course Runs OnPreview
  4. 0.4IR0.4 Where the Evidence LivesPreview
  5. 0.5IR0.5 The Toolkit, and Where to PracticePreview

Phase 2: Detection, Investigation, and Containment

Phase 4: Hunting and the Aftermath

Phase 0: Course Resources

ResourcesLab Setup

Five pages to a tenant you can respond in, including what it costs and when, and how to produce an incident worth investigating.

Show 5 lessonsHide lessons
  1. 1The Tenant, and What It Costs
  2. 2The Endpoint and Server Layers
  3. 3Producing an Incident to Respond To
  4. 4Practicing Containment Safely
  5. 5Verify, and What the Lab Cannot Teach
ResourcesPlayground

Where to practice responding, and the two things about this discipline no practice surface can give you.

ResourcesOperational Reference

The consolidated lookup and the step-by-step procedures from this course, in one place.

Show 2 lessonsHide lessons
  1. 1Investigation Quick Reference
  2. 2Incident Response Field Manual
ResourcesReferences & Further Reading

External sources this course draws on: vendor documentation, frameworks, standards, and research.

Course Completion

CompletionCourse Exam

Microsoft Cloud Incident Response end-of-course exam, a simulation-based assessment testing your ability to triage, investigate, contain, and report on a multi-stage Microsoft 365 incident using the skills built across all ten modules.

Show 1 lessonHide lessons
  1. 1Course Completion. Microsoft Cloud Incident Response

Course overview

Microsoft Cloud Incident Response teaches the complete incident response lifecycle for Microsoft 365 environments. Every module produces a capability you can execute during a real incident. You configure the environment that preserves evidence before you need it. You build the playbooks and runbooks that eliminate improvisation under pressure. You run investigations using KQL, Graph API, and PowerShell against the same log sources and evidence tables you'll query during a real compromise. You execute containment through Conditional Access, session revocation, and OAuth grant removal. You hunt for what the detections missed and convert a finding into a rule that runs without you. You handle the notification, the legal coordination and the post-incident improvement. And you recover the tenant, which is the phase most courses name and skip: what Microsoft 365 can restore, what it cannot, and why a completed recovery is a partial resolution of most modern incidents.

The course follows the incident response lifecycle across five phases: orientation and foundations, detection and investigation and containment, responding by attack type, hunting and the aftermath, and recovery. Guided walkthroughs in every module put you through end-to-end scenarios. Incident Lab scenarios let you practice investigation queries against synthetic data with known answers.

How this course works

Every module in this course runs the same six-step loop against a Microsoft 365 tenant. It is the habit the course is built to install, because it is the sequence that produces a claim somebody else can check rather than an account somebody has to take on trust.

1. Establish what the tenant recorded. Before any query, know which operations are collected at your license tier, how long they are kept, and what was never written down. An empty result means one of three things and only one of them is about the incident.

2. Scope from the record rather than from the alert. The alert is where the case reached you. The scope comes from reading the audit trail, both sign-in tables and the file and mail activity, and it is almost always larger than the alert suggested.

3. Preserve before you collect. Preservation stops a clock; collection takes a copy. Doing the second without the first means the material can expire between the decision and the export.

4. Contain across the four paths. Sessions, credentials, application identities and sharing links fail independently. Closing three properly still leaves the fourth open, and it is usually the one nobody looked at.

5. Verify that the action landed. Taking an action and proving it worked are separate pieces of work. Every check needs a positive control, because an empty result is a claim about your query as much as about the tenant.

6. State what the evidence supports, and what it does not. A figure without its basis is a figure somebody else will derive differently. A gap in the record is a finding with an owner rather than an apology.

Recovery closes the loop and does not undo it. What can be restored, in what order, and why the copy that already left is unaffected by any of it.

What this course assumes

No minimum experience and no prerequisite course. Every concept is explained where it is first used, including the ones a syllabus like this would normally assume: what the unified audit log is, why there are two sign-in tables, what a refresh token does. If you have never opened the Defender portal, start at module zero and nothing will be missing.

What does make it go faster: a Microsoft 365 tenant you can read, even a developer one, and enough comfort with a command line to run a PowerShell cmdlet and read what comes back. Neither is required. Every query in the course can be practiced against the Practice Hub instead, which holds populated tables and known answers, and the lab module walks through building a tenant from nothing if you want one.

What the course does not cover, deliberately: endpoint forensics beyond what Microsoft 365 reaches, memory analysis, and malware reverse engineering. Those are separate disciplines with their own courses, and a cloud investigation that pretends to teach them alongside teaches neither properly.

Who this course is for

Anyone who wants to learn cloud incident response. The course is built for security analysts, SOC engineers, IT administrators responsible for M365 security, and anyone who needs to investigate or respond to incidents in Microsoft 365 and Entra ID environments. No minimum experience required. Every concept is explained at first use, and experienced cybersecurity professionals can skip ahead using the module structure.

✓ SOC analysts who triage alerts and need to investigate beyond the alert summary
✓ Security engineers responsible for M365 security who need IR capability
✓ IT administrators who are the first responder when something goes wrong
✓ IR cybersecurity professionals expanding from on-premises into cloud investigation

What you'll learn

✓ Configure M365 for IR readiness: diagnostic settings, log retention, break-glass accounts, and emergency Conditional Access policies
✓ Triage alerts from Identity Protection, Defender XDR, and Sentinel and determine whether they require investigation
✓ Investigate identity compromise, BEC, OAuth abuse, and insider threat using KQL against all four sign-in log tables and the Unified Audit Log
✓ Scope incidents: determine how many accounts are compromised, what the attacker accessed, and what data was exfiltrated
✓ Contain across the four access paths that fail independently: sessions, credentials, application identities, and sharing links
✓ Derive a notifiable figure your evidence supports, and know which clock started when, across the reporting regimes that run in parallel
✓ Hunt without an alert: build a hypothesis you can be wrong about, establish how far back your tenant lets you look, and report an empty result as coverage rather than as nothing
✓ Recover the tenant and know the limits: what Microsoft 365 restores, the order that stops a restore reinviting the actor, and why the copy that already left is unaffected by any of it

Key course takeaways

✓ A complete, repeatable IR methodology for M365 that you can execute under pressure
✓ Production-ready KQL investigation queries for every phase of the response lifecycle
✓ Playbooks and runbooks for BEC, identity compromise, ransomware, insider threat, and OAuth abuse
✓ The ability to configure an environment for IR readiness and verify the configuration works
✓ Confidence to lead incident response in M365 environments and produce defensible investigation reports

Course Resources - what comes with the modules

Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.

✓ Walkthroughs take a response failure and show where it went wrong: the containment that held nothing, the scope that stopped where the logs did, the clean check that could not fail, two incidents that read as one, and the evidence that could not be used.
✓ Playbooks for the situations that arrive rather than the ones you plan: the clock is running and the scope is open, the actor is still moving, a supplier tells you they were breached, a legal hold arrives mid-response, a restore brought the damage back.
✓ A cookbook for the arc of a response: working an incident to scope, containing without losing the evidence, proving eradication rather than declaring it, preparing the notification input, and writing the report.
✓ A command cheatsheet across acquisition, threat-specific response, coverage before and after, and the clocks and retention windows you are working against.
✓ An investigation quick reference and a field manual for the two different moments: looking something up, and working without the site in front of you.
✓ A lab setup guide that includes producing an incident to respond to, and practicing containment safely.
✓ A playground pointing at your own lab, the query Practice surface, the SOC Simulator for estate scale, and the Playbook Suite.

Things you need to know

What are the prerequisites?

None. The course teaches cloud incident response from first principles. Familiarity with Microsoft 365, Entra ID, and KQL will help you move faster, but none are required. Every tool, technique, and concept is explained at first use.

What tools does this course use?

KQL (Kusto Query Language) for investigation queries in Sentinel and Defender XDR. Microsoft Graph PowerShell for evidence collection and containment. The Microsoft Extractor Suite for bulk evidence export. All tools are free. The course walks through installation and configuration.

Do I need an M365 tenant?

An M365 E5 developer tenant is recommended for hands-on practice. The course provides setup guidance. Investigation queries can also be practiced against the Incident Lab's synthetic NE Corpus data without a tenant.

How will this course benefit your career?

Cloud incident response is one of the most in-demand skills in cybersecurity. Organizations running M365 need people who can investigate a compromise, contain the attacker, determine what was accessed, and produce a report that leadership and legal can act on. This course builds that capability end to end.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy investigation queries, PowerShell scripts, playbooks, and containment runbooks in your production environment. You may not redistribute course content or share account credentials.

Fictional environment: All scenarios use Northgate Engineering (NE). Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
3scenarios
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.