Microsoft Security Operations Analyst

Microsoft Security Operations Analyst

About This Course

Learn how to investigate, respond to, and hunt for threats using Microsoft Sentinel, Microsoft Defender XDR and  Microsoft Defender for Cloud. In this course you will learn how to mitigate cyberthreats using these technologies. Specifically, you will configure and use Microsoft Sentinel as well as utilize Kusto Query Language (KQL) to perform detection, analysis, and reporting. The course was designed for people who work in a Security Operations job role and helps learners prepare for the exam SC-200: Microsoft Security Operations Analyst.

Audience Profile

The Microsoft Security Operations Analyst collaborates with organizational stakeholders to secure information technology systems for the organization. Their goal is to reduce organizational risk by rapidly remediating active attacks in the environment, advising on improvements to threat protection practices, and referring violations of organizational policies to appropriate stakeholders. Responsibilities include threat management, monitoring, and response by using a variety of security solutions across their environment. The role primarily investigates, responds to, and hunts for threats using Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Cloud, and third-party security products. Since the Security Operations Analyst consumes the operational output of these tools, they are also a critical stakeholder in the configuration and deployment of these technologies.

Intermediate
Security Engineer
Security Operations Analyst
Azure
M365

Choose a package for learning Microsoft Security Operations Analyst course

Non Certification Package
  • PSA Learning Platform Access
  • Hosted Online Lab Access (Where applicable)
  • Attend Official Instructor-Led Course
Bronze Package
  • PSA Learning Platfom Access

Related Learning Paths

SC-200: Mitigate threats using Microsoft Defender XDR
  • intermediate
  • MS Learn
Cloud Security
Security
SC-200: Mitigate threats using Microsoft Security Copilot
  • intermediate
  • MS Learn
Cloud Security
Security
SC-200: Mitigate threats using Microsoft Purview
  • intermediate
  • MS Learn
Compliance
Information Protection Governance
SC-200: Mitigate threats using Microsoft Defender for Endpoint
  • intermediate
  • MS Learn
Compliance
Device Management
SC-200: Mitigate threats using Microsoft Defender for Cloud
  • intermediate
  • MS Learn
Compliance
Threat Protection
SC-200: Create queries for Microsoft Sentinel using Kusto Query Language (KQL)
  • intermediate
  • MS Learn
Threat Protection
Data Analytics
SC-200: Configure your Microsoft Sentinel environment
  • intermediate
  • MS Learn
Threat Protection
Intermediate
SC-200: Connect logs to Microsoft Sentinel
  • intermediate
  • MS Learn
Cloud Security
Intermediate
SC-200: Create detections and perform investigations using Microsoft Sentinel
  • intermediate
  • MS Learn
Threat Protection
Intermediate
SC-200: Perform threat hunting in Microsoft Sentinel
  • intermediate
  • MS Learn
Threat Protection
Intermediate