Our cloud training videos have over 15M Impr on YouTube

SC-200: Microsoft Security Operations Analyst

Last Updated: 30-06-2026

As cyber threats continue to grow in volume and complexity, organizations rely on skilled professionals to detect, investigate, and respond to threats across hybrid environments. This hands-on training focuses on using key Microsoft security tools such as Microsoft Defender, KQL and Microsoft Sentinel. You’ll learn how to implement threat detection, automate response strategies, and monitor security operations effectively.

  • Secure Your Investment: Our No Questions Asked Refund Policy.

  • Enterprise Grade LMS: Perform real labs, don't just watch videos and read pdf.

  • Industry Equivalent Labs: Develop real world technical skills (180 Days Access).

  • 100% Live Sessions: Stay focused and upskill today, not "someday."   

thumbnail

450K+

Career Transformation

40+

Workshop Every Month

60+

Countries and Counting

July 25th - 02nd
09:00 AM - 05:00 PM (CST)
Live Online (32 Hrs.)
10% Off
$768
$691
Fast Filling! Hurry Up.
July 27th - 30th
09:00 AM - 05:00 PM (CST)
Live Online (32 Hrs.)
Guaranteed-to-Run
10% Off
$768
$691
August 03rd - 06th
09:00 AM - 05:00 PM (CST)
Live Online (32 Hrs.)
20% Off
$768
$614
August 08th - 16th
09:00 AM - 05:00 PM (CST)
Live Online (32 Hrs.)
20% Off
$768
$614
August 10th - 13th
09:00 AM - 05:00 PM (CST)
Live Online (32 Hrs.)
20% Off
$768
$614
August 17th - 26th
06:00 PM - 10:00 PM (CST)
Live Online (32 Hrs.)
20% Off
$768
$614
August 24th - 27th
09:00 AM - 05:00 PM (CST)
Live Online (32 Hrs.)
Guaranteed-to-Run
20% Off
$768
$614

Course Prerequisites

It is recommended that participants have:

  • A basic understanding of Azure and Microsoft 365 services.
  • Familiarity with general IT security principles and practices.
  • Experience with Microsoft Entra ID, network security, and threat management.

Having prior experience in IT administration or security operations will be helpful for understanding the course content more effectively.

Learning Objectives

Manage a Security Operations Environment

  • Configure Defender XDR settings, alerts, automation, and attack disruption
  • Manage devices, permissions, exposure, and vulnerabilities
  • Plan and configure Microsoft Sentinel: roles, storage, data ingestion
  • Integrate data sources (Syslog, CEF, WEF, Azure resources)
  • Monitor and optimize data ingestion

 Configure Protections and Detections

  • Set policies in Defender for Endpoint, Cloud Apps, Office 365, Cloud
  • Create/manage custom detections, alert tuning, deception in XDR
  • Configure analytics rules, behavioral analytics, and ASIM in Sentinel

 Manage Incident Response

  • Investigate/remediate threats across Defender XDR and Microsoft 365
  • Use audit logs, Graph logs, content search
  • Respond to incidents in Sentinel with playbooks and automation
  • Use Microsoft Security Copilot for threat analysis and response

 Manage Security Threats

  • Threat hunting in XDR and Sentinel using KQL and MITRE ATT&CK
  • Manage threat indicators, bookmarks, archived logs
  • Create custom hunting queries and workbooks in Sentinel

Target Audience

  • Security Operations Analysts
  • IT Security Professionals
  • Cloud Security Engineers and Cloud Architects
  • Security Consultants and Advisors
  • IT Administrators
  • Network Security Engineers
  • Security Managers and Compliance Officers
  • Professionals preparing for the SC-200 certification exam

Course Modules

Learning Path 1: Mitigate threats using Microsoft Defender XDR

  • Introduction to Microsoft 365 threat protection
  • Mitigate incidents using Microsoft Defender XDR
  • Protect your identities with Entra ID Protection
  • Remediate risks with Microsoft Defender for Office 365
  • Safeguard your environment with Microsoft Defender for Identity
  • Secure your cloud apps and services with Microsoft Defender for Cloud Apps
  • Lab: Explore Microsoft Defender XDR

Learning Path 2: Get started with Microsoft Copilot for Security

  • Fundamentals of Generative AI
  • Describe Microsoft Copilot for Security
  • Describe core features of Microsoft Copilot for Security
  • Describe the Microsoft Copilot for Security embedded experience
  • Lab: Explore use cases in Microsoft Security Copilot

Learning Path 3: Mitigate threats using Microsoft Purview

  • Microsoft Purview Compliance Solutions
  • Respond to data loss prevention alerts using Microsoft Purview
  • Manage insider risk in Microsoft Purview
  • Investigate threats using Content search in Microsoft Purview
  • Investigate threats using Microsoft Purview Audit
  • Lab: Explore Microsoft Purview Audit Logs

Learning Path 4: Mitigate threats using Microsoft Defender for Endpoint

  • Protect against threats with Microsoft Defender for Endpoint
  • Deploy the Microsoft Defender for Endpoint environment
  • Implement Windows security enhancements with Microsoft Defender for Endpoint
  • Perform device investigations in Microsoft Defender for Endpoint
  • Perform actions on a device using Microsoft Defender for Endpoint
  • Perform evidence and entities investigations using Microsoft Defender for Endpoint
  • Configure and manage automation using Microsoft Defender for Endpoint
  • Configure for alerts and detections in Microsoft Defender for Endpoint
  • Utilize Vulnerability Management in Microsoft Defender for Endpoint
  • Lab: Deploy Microsoft Defender for Endpoint
  • Lab: Mitigate attacks with Microsoft Defender for Endpoint

Learning Path 5: Mitigate threats using Microsoft Defender for Cloud

  • Plan for cloud workload protections using Microsoft Defender for Cloud
  • Connect Azure assets to Microsoft Defender for Cloud
  • Connect non-Azure resources to Microsoft Defender for Cloud
  • Manage your cloud security posture management
  • Explain cloud workload protections in Microsoft Defender for Cloud
  • Remediate security alerts using Microsoft Defender for Cloud

Learning Path 6: Create queries for Microsoft Sentinel using Kusto Query Language (KQL)

  • Construct KQL statements for Microsoft Sentinel
  • Analyze query results using KQL
  • Build multi-table statements using KQL
  • Work with data in Microsoft Sentinel using Kusto Query Language
  • Lab: Create queries for Microsoft Sentinel using Kusto Query Language (KQL)

Learning Path 7: Configure your Microsoft Sentinel environment

  • Introduction to Microsoft Sentinel
  • Create and manage Microsoft Sentinel workspaces
  • Query logs in Microsoft Sentinel
  • Use watchlists in Microsoft Sentinel
  • Utilize threat intelligence in Microsoft Sentinel
  • Integrate Microsoft Defender XDR with Microsoft Sentinel
  • Lab: Configure your Microsoft Sentinel Environment
  • Lab: Connect data to Microsoft Sentinel using Data Connectors
  • Lab: Configure your Microsoft Sentinel Environment

Learning Path 8: Connect logs to Microsoft Sentinel

  • Connect data to Microsoft Sentinel using data connectors
  • Connect Microsoft services to Microsoft Sentinel
  • Connect Microsoft Defender XDR to Microsoft Sentinel
  • Connect Windows hosts to Microsoft Sentinel
  • Connect Common Event Format logs to Microsoft Sentinel
  • Connect syslog data sources to Microsoft Sentinel
  • Connect threat indicators to Microsoft Sentinel
  • Lab: Connect Windows Devices to Microsoft Sentinel using Data Connectors
  • Lab: Connect Linux Hosts to Microsoft Sentinel using Data Connectors
  • Lab: Connect Defender XDR to Microsoft Sentinel using Data Connectors

Learning Path 9: Create detections and perform investigations using Microsoft Sentinel

  • Threat detection with Microsoft Sentinel analytics
  • Automation in Microsoft Sentinel
  • Threat response with Microsoft Sentinel playbooks
  • Security incident management in Microsoft Sentinel
  • Identify threats with Entity behavioral analytics in Microsoft Sentinel
  • Data normalization in Microsoft Sentinel
  • Query, visualize, and monitor data in Microsoft Sentinel
  • Manage content in Microsoft Sentinel
  • Lab: Create a playbook
  • Lab: Create a scheduled query from a template
  • Lab: Explore entity behavior analytics
  • Lab: Prepare to perform simulated attacks
  • Lab: Connect Defender XDR to Microsoft Sentinel using Data Connectors
  • Lab: Conduct Attacks
  • Lab: Create Detections
  • Lab: Investigate Incidents
  • Lab: Create ASIM Parsers
  • Lab: Create Workbooks
  • Lab: Use Repositories in Microsoft Sentinel

Learning Path 10: Perform threat hunting in Microsoft Sentinel

  • Explain threat hunting concepts in Microsoft Sentinel
  • Threat hunting with Microsoft Sentinel
  • Use Search jobs in Microsoft Sentinel
  • Hunt for threats using notebooks in Microsoft Sentinel
  • Lab: Perform Threat Hunting in Microsoft Sentinel
  • Lab: Threat Hunting using Notebooks with Microsoft Sentinel
  • Lab: Perform Threat Hunting in Microsoft Sentinel

Course FAQs

SC-200 training is specifically designed to ensure you are fully prepared for the Microsoft SC-200 certification exam. The training covers exam objectives and includes practical labs, real-world scenarios, and exam practice questions to reinforce your learning and boost your confidence.
While we cannot guarantee you will pass the exam, our SC-200 training provides the most comprehensive preparation available. With certified expert instructors, hands-on labs, and extensive exam practice materials, you'll be fully equipped to succeed in the SC-200 certification exam.
Yes, we provide access to the official Microsoft course materials, so you can revisit courseware along with labs, and practice exams even after the course has ended. This can be a great way to stay updated with any changes to the SC-200 exam.
No, you don't need to worry about setting up your own software or accounts. We provide official labs with all the required licenses, tenants, and subscriptions for Microsoft Sentinel and Microsoft Defender. All you need is a laptop or desktop with internet access to access these labs over the web and gain hands-on experience. Our training ensures you have everything you need to successfully complete the SC-200 training without additional setup.

Register Your Interest

What Our Learners Are Saying