Detecting and responding to threats with Microsoft security tools (SC-200)
Your security alerts should lead to relevant analysis and action. Structure detection, triage and investigation to distinguish useful signals from noise. Strengthen your ability to document incidents and coordinate their handling within your defence operations.
- Duration
- 4 days 28 hours
- Code
- SC-200 Code
- Certification
- Microsoft Certified : Security Operations Analyst Associate Certification
Accredited training for the Microsoft Certified : Security Operations Analyst Associate certification.
Presentation
Security operations analysts (SOC) are digital first responders to cyberthreats: they detect, investigate and neutralise attacks every day. As threats become increasingly sophisticated and AI becomes more integrated into Microsoft environments, strong Microsoft security tools skills are essential for professionals responsible for protecting information systems.
This course develops the skills to detect, investigate and respond to threats using Microsoft's main tools: Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Cloud, Microsoft Entra ID and Microsoft Purview. You will learn to write KQL (Kusto Query Language) queries for threat hunting, automate incident responses and use agentic AI investigation capabilities, including Microsoft Security Copilot.
By the end of the program, you will be ready to take the SC-200 certification examination, which validates your ability to reduce organisational risk through triage, incident response, threat hunting and detection engineering. Passing earns you the Microsoft Certified: Security Operations Analyst Associate certification (see the Certification tab for details).
Objectives
By the end of this Microsoft SC-200 course, you will be able to:
- configure and manage a security operations environment with Microsoft Defender XDR and Microsoft Sentinel, including automation and detection;
- ingest and use security data in Microsoft Sentinel for effective monitoring;
- investigate and remediate threats identified by Microsoft Defender for Cloud, Microsoft Defender for Identity, Microsoft Entra ID and Microsoft Purview;
- respond to complex incidents, including multistage attacks and lateral movement, using agentic AI and Microsoft Security Copilot;
- write KQL (Kusto Query Language) queries for threat hunting and create advanced hunting queries;
- pass the SC-200 examination and obtain Microsoft Certified: Security Operations Analyst Associate certification.
Program
Module 1: managing a security operations environment
- Configuring Microsoft Sentinel and creating dedicated workspaces.
- Integrating data connectors to collect logs from different sources.
- Creating detection rules and automated playbooks in Microsoft Sentinel and Microsoft Defender XDR.
- Configuring advanced Microsoft Defender for Endpoint features: attack surface reduction rules and custom data collection.
- Managing data retention and optimising the Sentinel platform.
Lab
- Configure Microsoft Sentinel, connect data sources and create detection rules.
Module 2: responding to security incidents
- Investigating and remediating threats identified by Microsoft Defender for Office 365 and Microsoft Defender for Cloud.
- Investigating compromised identities identified by Microsoft Entra ID and Microsoft Defender for Identity.
- Investigating security risks identified by Microsoft Defender for Cloud Apps and Microsoft Purview.
- Investigating complex attacks, including multistage attacks and lateral movement, and managing incidents through case management.
- Agentic AI-assisted investigation, including Microsoft Security Copilot.
Lab
- Investigate incidents, configure alerts and automate responses with Microsoft Defender XDR and Microsoft Sentinel.
Module 3: performing threat hunting
- Identifying tables and writing KQL (Kusto Query Language) queries for threat hunting.
- Creating Advanced Hunting queries in Microsoft Defender XDR.
- Creating and monitoring threat hunting queries in Microsoft Sentinel.
- Analysing relationships between entities and creating hunting graphs.
Lab
- Write KQL queries and conduct a threat hunting investigation in Microsoft Sentinel.
Module 4: automating and optimising incident response
- Designing advanced playbooks with Logic Apps to automate threat responses.
- Configuring automation rules in Microsoft Sentinel.
- Optimising security policies and centralised incident management.
- Using monitoring data to improve detection of new threats.
Lab
- Create automated playbooks and optimise incident management in Microsoft Sentinel.
Audience
This course is intended for IT security professionals, including:
- IT security analysts and professionals seeking to improve their threat detection and management skills;
- security analysts and engineers responsible for protecting Microsoft environments;
- administrators wishing to specialise in security analysis with Microsoft Sentinel, Microsoft Defender XDR and Microsoft Defender for Cloud.
Prerequisites
This course requires the following prerequisites:
- IT security knowledge: understanding of basic security concepts, including threat detection and incident response.
- Practical experience: experience with Microsoft 365 and Azure cloud services, plus familiarity with AI agents and copilots.
- System environments: knowledge of Windows, Linux and mobile operating systems.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
Course highlights
- Certification preparation: an official Microsoft program led by certified experts, preparing for SC-200 (examination not included).
- French-language materials: official learning materials available in French.
- Practical approach: labs in every module for hands-on mastery of Sentinel, Defender XDR and Defender for Cloud.
- Updated skills: content incorporating recent syllabus developments, including agentic AI-assisted investigation and Microsoft Security Copilot.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
Microsoft, Microsoft Sentinel, Microsoft Defender, Microsoft Entra, Microsoft Purview and Microsoft Security Copilot are registered trademarks of Microsoft Corporation (page in French).
fr
en