Build the skills to detect, investigate, and respond to modern cyber threats.
SC-200 Microsoft Security Operations Analyst prepares security professionals to identify, analyze, and respond to cybersecurity incidents using Microsoft's security ecosystem. Throughout this course, you'll gain hands-on experience with Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, and Microsoft Defender for Cloud, enabling you to protect modern organizations against evolving threats.
Why this program?
Industry-recognized Microsoft certification aligned with real-world Security Operations Center (SOC) roles.
Hands-on labs using Microsoft Sentinel and Defender security solutions.
Learn incident investigation, threat hunting, detection engineering, and automated response.
Build practical skills for monitoring identities, endpoints, cloud resources, and applications.
Designed for IT professionals, security analysts, SOC engineers, and cybersecurity specialists.
Program outline
Introduction to Security Operations
Microsoft Sentinel Configuration & Management
Threat Detection and Incident Investigation
Threat Hunting with Kusto Query Language (KQL)
Microsoft Defender XDR
Microsoft Defender for Endpoint
Microsoft Defender for Cloud
Identity Protection with Microsoft Entra ID
Incident Response & Automation
Security Operations Best Practices
What you'll walk away with
Practical experience using Microsoft Sentinel and Microsoft Defender security tools.
Ability to detect, investigate, and respond to cyber threats effectively.
Hands-on knowledge of threat hunting using KQL.
Skills to automate security workflows and improve incident response.
Preparation for the Microsoft SC-200: Microsoft Security Operations Analyst certification exam.
Learning Objectives
Target Audience
Skills & Competencies
Prerequisites



