top of page

SC-200: Microsoft Security Operations Analyst

Four days of hands-on SOC skills: investigate, respond, and hunt threats with Microsoft Sentinel, Defender XDR, and KQL.

Duration

Formats

4 days

day(s)

Instructor-led,Virtual,On-site,Bootcamp

Category

Security,Cloud

Security,Cloud

About this course

This four-day, lab-intensive course builds practical security operations skills on the Microsoft platform. You will mitigate threats with Microsoft Defender XDR, protect multicloud workloads with Microsoft Defender for Cloud, and master Microsoft Sentinel — from cost-optimised data ingestion and analytics rules to incident investigation, automation, and threat hunting with KQL.

The course is delivered by an instructor who runs these tools in real engagements, and includes field guidance on ingestion cost control and alert tuning that goes beyond the official curriculum.

What you'll learn

  • Investigate and remediate threats with Microsoft Defender XDR across endpoints, identity, email, and cloud apps
  • Manage cloud security posture and workload protection with Defender for Cloud
  • Design cost-effective data ingestion for Microsoft Sentinel
  • Build analytics rules, automation rules, and playbooks
  • Hunt threats with Kusto Query Language (KQL)

Course syllabus

  • Module 1 — Mitigate threats using Microsoft Defender XDR
  • Module 2 — Mitigate threats using Microsoft Defender for Endpoint
  • Module 3 — Mitigate threats using Microsoft Defender for Cloud
  • Module 4 — Create queries with Kusto Query Language (KQL)
  • Module 5 — Configure your Microsoft Sentinel environment and connect data
  • Module 6 — Detections, investigations, automation (SOAR)
  • Module 7 — Threat hunting in Microsoft Sentinel

Who should attend

  • SOC analysts and security engineers working in Microsoft environments
  • IT professionals moving into a security operations role
  • Teams adopting Microsoft Sentinel or Defender XDR

Prerequisites

Fundamental understanding of Microsoft 365, Azure services, and basic security concepts. SC-900 or equivalent knowledge is recommended. Prior KQL experience is not required.

What's included

  • Official Microsoft courseware (SC-200T00) and hands-on labs
  • Kloudatech hyperlinked SC-200 study guide
  • Instructor field notes on Sentinel ingestion cost optimisation
  • Certificate of attendance
Certification badge-ribbon_edited_edited

Certification

Prepares for exam SC-200, leading to the Microsoft Certified: Security Operations Analyst Associate certification.

bottom of page