top of page

SC-5004: Defend Against Cyberthreats with Microsoft Defender XDR

Applied Skills day: incident investigation and response in Microsoft Defender XDR, end to end.

Duration

Formats

1 day

day(s)

Instructor-led,Virtual,On-site

Category

Security

Security

About this course

One day inside the Defender portal: mitigating threats with Microsoft Defender XDR, investigating incidents and alerts across endpoints, identity, and email, using advanced hunting with KQL, and taking response actions — a compact, practical complement to the full SC-200 course.

What you'll learn

  • Investigate incidents across the Defender XDR portal
  • Run advanced hunting queries with KQL
  • Execute response and remediation actions

Course syllabus

  • Module 1 — Defender XDR portal and incidents
  • Module 2 — Investigation lab
  • Module 3 — Advanced hunting with KQL
  • Applied Skills assessment preparation

Who should attend

  • SOC analysts working in Defender XDR daily
  • IT security staff adding incident response skills

Prerequisites

Basic Microsoft 365 security familiarity.

What's included

  • Official Microsoft Learn path with hands-on lab environment
  • Guided walkthrough by the instructor
  • Certificate of attendance
Certification badge-ribbon_edited_edited

Certification

Aligned to the SC-5004 Microsoft Applied Skills assessment — a scenario-based, hands-on credential you can complete free on Microsoft Learn after the course.

bottom of page