SC-200 Microsoft Security Operations Analyst
Threat detection, investigation and response with Microsoft Defender XDR and Sentinel
Security operations teams using Microsoft Sentinel and Defender XDR need engineers who can detect, investigate, and contain threats across endpoints, identities, email, and cloud workloads. This programme prepares analysts for the SC-200 exam while building practical SOC skills mapped to the ACSC Australian Signals Directorate threat intelligence frameworks and Essential Eight Maturity Level 2 detection controls.

At a Glance
Who it's for
- SOC analysts and tier 2/3 security engineers operating Microsoft Sentinel or Defender XDR
- Incident response practitioners handling Microsoft 365 and Azure threats
- Security engineers building detection rules and SOAR playbooks
- IT security staff preparing for the SC-200 Microsoft Associate certification
Course Details
Course Overview
The SC-200 Microsoft Security Operations Analyst programme trains practitioners to mitigate threats using Microsoft Defender XDR, Microsoft Sentinel, and the broader Microsoft security stack. The four exam domains — mitigate threats using Defender XDR, Defender for Cloud, Microsoft Sentinel, and manage SIEM/SOAR — are covered in sequence with hands-on KQL threat hunting labs throughout. In the Australian context, detection rules and investigation playbooks are mapped to ACSC threat intelligence priorities (ransomware, BEC, credential theft) and to the Essential Eight Maturity Level 2 detection requirements for patch compliance and privileged access monitoring. ACSC advisories and ASD-published threat reports are used as investigation scenario sources throughout the programme.
What You'll Learn
Course Curriculum
Module 1: Mitigate Threats Using Microsoft Defender XDR
8 hours- Microsoft Defender XDR unified portal: incident queue, advanced hunting, and alert correlation
- Defender for Endpoint: endpoint detection and response (EDR), device investigation, and live response
- Defender for Office 365: anti-phishing, safe links, safe attachments, and BEC investigations
- Defender for Identity: lateral movement detection, DCSync alerts, and Active Directory kill chain
- Defender for Cloud Apps: session policies, OAuth app governance, and shadow IT discovery
Module 2: Mitigate Threats Using Microsoft Defender for Cloud
6 hours- Defender for Cloud: security posture, regulatory compliance, and workload protection plans
- Investigate alerts for servers, containers, databases, and storage workloads
- Just-in-time VM access and adaptive application controls for Essential Eight hardening
- Connect Defender for Cloud alerts to Microsoft Sentinel for unified SIEM investigation
- ASD Essential Eight Maturity Level 2 patching and hardening status via Defender for Cloud
Module 3: Microsoft Sentinel — SIEM Architecture and Detection
10 hours- Sentinel workspace design: data connectors, log retention, and cost management for Australian SOCs
- KQL fundamentals to advanced: summarise, join, externaldata, and hunt queries
- Analytics rules: scheduled, NRT, and fusion rules for multi-stage attack detection
- Threat intelligence: STIX/TAXII feeds, ACSC indicators, and Microsoft Defender Threat Intelligence
- Workbooks and reporting: Essential Eight coverage dashboards and executive security metrics
Module 4: Incident Response and SOAR Playbooks
8 hours- Sentinel incident management: triage, assignment, investigation graph, and entity timelines
- SOAR playbooks with Logic Apps: automated enrichment, containment, and notification workflows
- Ransomware response playbook: isolation, forensic preservation, and ASD notification workflow
- Business email compromise investigation: Office 365 audit logs, message trace, and consent phishing
- SC-200 exam preparation: mock exam walkthrough and KQL lab capstone
Who Should Attend
- Tier 1 to tier 3 SOC analysts working incidents in Microsoft Sentinel or Defender XDR
- Incident responders investigating ransomware, business email compromise and credential theft
- Detection engineers writing KQL analytics rules and tuning alert fidelity
- MSSP analysts operating multi-tenant Sentinel workspaces for Australian clients
- Infrastructure and Microsoft 365 administrators moving into a dedicated security operations role
- Security engineers preparing for the SC-200 Microsoft Associate certification
Prerequisites
Before enrolling, please ensure you meet these requirements:
- • Working knowledge of Microsoft 365 and Azure fundamentals (AZ-900 or SC-900 level)
- • Basic networking literacy — TCP/IP, DNS, authentication flows and log sources
- • Access to a Microsoft 365 E5 Security trial or existing Defender XDR tenant for labs
- • An Azure subscription (free tier is sufficient) for the Microsoft Sentinel workspace labs
- • No prior KQL experience required — Module 3 starts from fundamentals
Delivery, Format and Logistics
Delivery Mode
Live online training with a dedicated lab tenant — 4 days intensive or 8 weeks part-time
Maximum 12 participants with live lab environment per analyst
What You'll Need
- Working knowledge of Microsoft 365, Azure fundamentals, and basic networking concepts
- Microsoft 365 E5 Security trial or existing Defender XDR access for labs
- Familiarity with KQL (Kusto Query Language) is beneficial but not required
- Reliable internet connection for streaming lab console access
What You'll Receive
- 32 hours of instructor-led SOC instruction with a live lab environment per analyst
- Hands-on KQL threat hunting labs building from fundamentals to cross-workspace correlation
- Investigation scenarios sourced from published ACSC advisories and OAIC breach reports
- Reusable Sentinel analytics rules, hunting queries and Logic Apps playbook templates
- Ransomware and business email compromise response runbooks you keep
- Timed SC-200 mock exam with domain-by-domain answer explanations
- Recorded sessions and lab guides for 6 months
- Certificate of completion and 30 days of post-course email support
Frequently Asked Questions
Not Ready to Enrol?
Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.
Early-bird rate — apply your promo code at checkout.
Secure payment via Stripe · Promo codes accepted
Next Intake
September 2026 — register your interest at educ4te.com
Format
Live online training with a dedicated lab tenant — 4 days intensive or 8 weeks part-time
Group & Enterprise Options
Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.
What's Included
- 32 hours of instructor-led SOC instruction with a live lab environment per analyst
- Hands-on KQL threat hunting labs building from fundamentals to cross-workspace correlation
- Investigation scenarios sourced from published ACSC advisories and OAIC breach reports
- Reusable Sentinel analytics rules, hunting queries and Logic Apps playbook templates
- Ransomware and business email compromise response runbooks you keep
- Timed SC-200 mock exam with domain-by-domain answer explanations
- Recorded sessions and lab guides for 6 months
- Certificate of completion and 30 days of post-course email support
Have questions about this course?