top of page
SC-5001: Configure SIEM Security Operations Using Microsoft Sentinel
A focused day standing up Microsoft Sentinel: workspace, data connectors, analytics rules, and incident handling.
Duration
Formats
1 day
day(s)
Instructor-led,Virtual,On-site
Category
Security

About this course
One hands-on day configuring SIEM operations in Microsoft Sentinel: deploying the workspace, connecting data sources, creating analytics rules and automation, and managing incidents — with instructor field guidance on ingestion cost control from real deployments.
What you'll learn
- Deploy and configure a Sentinel workspace
- Connect data sources and validate ingestion
- Create analytics rules and automation
- Manage and investigate incidents
Course syllabus
- Module 1 — Workspace deployment
- Module 2 — Data connectors
- Module 3 — Analytics and automation
- Module 4 — Incident management lab
Who should attend
- SOC analysts and engineers new to Sentinel
- Teams piloting Sentinel before full adoption
Prerequisites
Basic Azure and security operations familiarity.
What's included
- Official Microsoft workshop materials
- Hands-on exercises in a live tenant/demo environment
- Certificate of attendance

Certification
Practical workshop — no exam attached. Attendees receive a Kloudatech certificate of attendance.
bottom of page
