Perform a search on the site.

Your currency
Labs inclus
Real-world practice environments to test what you’ve learnt
Formateurs
certifiés
Formation dispensée par un formateur spécialisé
Supports
Printed materials & books provided (depending on your geographic area)
Cours officiel
Official training from an Accredited Training Provider

Detecting and responding to threats with Microsoft security tools (SC-200)

Your security alerts should lead to relevant analysis and action. Structure detection, triage and investigation to distinguish useful signals from noise. Strengthen your ability to document incidents and coordinate their handling within your defence operations.

Duration
4 days 28 hours
Code
SC-200 Code
Microsoft Certified : Security Operations Analyst Associate

Accredited training for the Microsoft Certified : Security Operations Analyst Associate certification.

Presentation


Security operations analysts (SOC) are digital first responders to cyberthreats: they detect, investigate and neutralise attacks every day. As threats become increasingly sophisticated and AI becomes more integrated into Microsoft environments, strong Microsoft security tools skills are essential for professionals responsible for protecting information systems.

This course develops the skills to detect, investigate and respond to threats using Microsoft's main tools: Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Cloud, Microsoft Entra ID and Microsoft Purview. You will learn to write KQL (Kusto Query Language) queries for threat hunting, automate incident responses and use agentic AI investigation capabilities, including Microsoft Security Copilot.

By the end of the program, you will be ready to take the SC-200 certification examination, which validates your ability to reduce organisational risk through triage, incident response, threat hunting and detection engineering. Passing earns you the Microsoft Certified: Security Operations Analyst Associate certification (see the Certification tab for details).

Objectives

By the end of this Microsoft SC-200 course, you will be able to:

  • configure and manage a security operations environment with Microsoft Defender XDR and Microsoft Sentinel, including automation and detection;
  • ingest and use security data in Microsoft Sentinel for effective monitoring;
  • investigate and remediate threats identified by Microsoft Defender for Cloud, Microsoft Defender for Identity, Microsoft Entra ID and Microsoft Purview;
  • respond to complex incidents, including multistage attacks and lateral movement, using agentic AI and Microsoft Security Copilot;
  • write KQL (Kusto Query Language) queries for threat hunting and create advanced hunting queries;
  • pass the SC-200 examination and obtain Microsoft Certified: Security Operations Analyst Associate certification.
Last update: 24/09/2026

Microsoft, Microsoft Sentinel, Microsoft Defender, Microsoft Entra, Microsoft Purview and Microsoft Security Copilot are registered trademarks of Microsoft Corporation (page in French).