top of page

SC-5001: Configure SIEM Security Operations Using Microsoft Sentinel

A focused day standing up Microsoft Sentinel: workspace, data connectors, analytics rules, and incident handling.

Duration

Formats

1 day

day(s)

Instructor-led,Virtual,On-site

Category

Security

Security

About this course

One hands-on day configuring SIEM operations in Microsoft Sentinel: deploying the workspace, connecting data sources, creating analytics rules and automation, and managing incidents — with instructor field guidance on ingestion cost control from real deployments.

What you'll learn

  • Deploy and configure a Sentinel workspace
  • Connect data sources and validate ingestion
  • Create analytics rules and automation
  • Manage and investigate incidents

Course syllabus

  • Module 1 — Workspace deployment
  • Module 2 — Data connectors
  • Module 3 — Analytics and automation
  • Module 4 — Incident management lab

Who should attend

  • SOC analysts and engineers new to Sentinel
  • Teams piloting Sentinel before full adoption

Prerequisites

Basic Azure and security operations familiarity.

What's included

  • Official Microsoft workshop materials
  • Hands-on exercises in a live tenant/demo environment
  • Certificate of attendance
Certification badge-ribbon_edited_edited

Certification

Practical workshop — no exam attached. Attendees receive a Kloudatech certificate of attendance.

bottom of page