IntermediateSC-200-001

SC-200 Microsoft Security Operations Analyst

Threat detection, investigation and response with Microsoft Defender XDR and Sentinel

Security operations teams using Microsoft Sentinel and Defender XDR need engineers who can detect, investigate, and contain threats across endpoints, identities, email, and cloud workloads. This programme prepares analysts for the SC-200 exam while building practical SOC skills mapped to the ACSC Australian Signals Directorate threat intelligence frameworks and Essential Eight Maturity Level 2 detection controls.

32 hours (4 days intensive or 8 weeks part-time)
New course
Certificate Included
SC-200 Microsoft Security Operations Analyst

At a Glance

Who it's for

  • SOC analysts and tier 2/3 security engineers operating Microsoft Sentinel or Defender XDR
  • Incident response practitioners handling Microsoft 365 and Azure threats
  • Security engineers building detection rules and SOAR playbooks
  • IT security staff preparing for the SC-200 Microsoft Associate certification

Course Details

Duration:32 hours (4 days intensive or 8 weeks part-time)
Format:Live online training with a dedicated lab tenant — 4 days intensive or 8 weeks part-time
Next intake:September 2026 — register your interest at educ4te.com
Alignment:Preparation for Microsoft Certified: Security Operations Analyst Associate (Exam SC-200)

Course Overview

The SC-200 Microsoft Security Operations Analyst programme trains practitioners to mitigate threats using Microsoft Defender XDR, Microsoft Sentinel, and the broader Microsoft security stack. The four exam domains — mitigate threats using Defender XDR, Defender for Cloud, Microsoft Sentinel, and manage SIEM/SOAR — are covered in sequence with hands-on KQL threat hunting labs throughout. In the Australian context, detection rules and investigation playbooks are mapped to ACSC threat intelligence priorities (ransomware, BEC, credential theft) and to the Essential Eight Maturity Level 2 detection requirements for patch compliance and privileged access monitoring. ACSC advisories and ASD-published threat reports are used as investigation scenario sources throughout the programme.

What You'll Learn

Detect and investigate endpoint threats using Microsoft Defender for Endpoint across Windows, macOS, Linux, and mobile
Investigate email and collaboration threats using Microsoft Defender for Office 365 and Attack Simulator
Manage identity-based attack investigations using Microsoft Defender for Identity and Entra ID Protection
Write KQL detection rules and hunting queries in Microsoft Sentinel for Australian SOC threat scenarios
Configure SOAR playbooks using Logic Apps to automate incident triage and response steps
Investigate multi-stage attack chains using Microsoft Sentinel incidents and Defender XDR correlation
Map detections to MITRE ATT&CK techniques prioritised by ASD Essential Eight and ACSC threat intelligence
Pass the Microsoft SC-200 Security Operations Analyst Associate exam

Course Curriculum

Module 1: Mitigate Threats Using Microsoft Defender XDR

8 hours
  • Microsoft Defender XDR unified portal: incident queue, advanced hunting, and alert correlation
  • Defender for Endpoint: endpoint detection and response (EDR), device investigation, and live response
  • Defender for Office 365: anti-phishing, safe links, safe attachments, and BEC investigations
  • Defender for Identity: lateral movement detection, DCSync alerts, and Active Directory kill chain
  • Defender for Cloud Apps: session policies, OAuth app governance, and shadow IT discovery

Module 2: Mitigate Threats Using Microsoft Defender for Cloud

6 hours
  • Defender for Cloud: security posture, regulatory compliance, and workload protection plans
  • Investigate alerts for servers, containers, databases, and storage workloads
  • Just-in-time VM access and adaptive application controls for Essential Eight hardening
  • Connect Defender for Cloud alerts to Microsoft Sentinel for unified SIEM investigation
  • ASD Essential Eight Maturity Level 2 patching and hardening status via Defender for Cloud

Module 3: Microsoft Sentinel — SIEM Architecture and Detection

10 hours
  • Sentinel workspace design: data connectors, log retention, and cost management for Australian SOCs
  • KQL fundamentals to advanced: summarise, join, externaldata, and hunt queries
  • Analytics rules: scheduled, NRT, and fusion rules for multi-stage attack detection
  • Threat intelligence: STIX/TAXII feeds, ACSC indicators, and Microsoft Defender Threat Intelligence
  • Workbooks and reporting: Essential Eight coverage dashboards and executive security metrics

Module 4: Incident Response and SOAR Playbooks

8 hours
  • Sentinel incident management: triage, assignment, investigation graph, and entity timelines
  • SOAR playbooks with Logic Apps: automated enrichment, containment, and notification workflows
  • Ransomware response playbook: isolation, forensic preservation, and ASD notification workflow
  • Business email compromise investigation: Office 365 audit logs, message trace, and consent phishing
  • SC-200 exam preparation: mock exam walkthrough and KQL lab capstone

Who Should Attend

  • Tier 1 to tier 3 SOC analysts working incidents in Microsoft Sentinel or Defender XDR
  • Incident responders investigating ransomware, business email compromise and credential theft
  • Detection engineers writing KQL analytics rules and tuning alert fidelity
  • MSSP analysts operating multi-tenant Sentinel workspaces for Australian clients
  • Infrastructure and Microsoft 365 administrators moving into a dedicated security operations role
  • Security engineers preparing for the SC-200 Microsoft Associate certification

Prerequisites

Before enrolling, please ensure you meet these requirements:

  • • Working knowledge of Microsoft 365 and Azure fundamentals (AZ-900 or SC-900 level)
  • • Basic networking literacy — TCP/IP, DNS, authentication flows and log sources
  • • Access to a Microsoft 365 E5 Security trial or existing Defender XDR tenant for labs
  • • An Azure subscription (free tier is sufficient) for the Microsoft Sentinel workspace labs
  • • No prior KQL experience required — Module 3 starts from fundamentals

Delivery, Format and Logistics

Delivery Mode

Live online training with a dedicated lab tenant — 4 days intensive or 8 weeks part-time

Maximum 12 participants with live lab environment per analyst

What You'll Need

  • Working knowledge of Microsoft 365, Azure fundamentals, and basic networking concepts
  • Microsoft 365 E5 Security trial or existing Defender XDR access for labs
  • Familiarity with KQL (Kusto Query Language) is beneficial but not required
  • Reliable internet connection for streaming lab console access

What You'll Receive

  • 32 hours of instructor-led SOC instruction with a live lab environment per analyst
  • Hands-on KQL threat hunting labs building from fundamentals to cross-workspace correlation
  • Investigation scenarios sourced from published ACSC advisories and OAIC breach reports
  • Reusable Sentinel analytics rules, hunting queries and Logic Apps playbook templates
  • Ransomware and business email compromise response runbooks you keep
  • Timed SC-200 mock exam with domain-by-domain answer explanations
  • Recorded sessions and lab guides for 6 months
  • Certificate of completion and 30 days of post-course email support

Frequently Asked Questions

Not Ready to Enrol?

Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.

By subscribing, you agree to receive email updates from Educ4te. You can unsubscribe at any time. We respect your privacy and will never share your information.

$1199AUD
$1499EARLY BIRD

Early-bird rate — apply your promo code at checkout.

1

Secure payment via Stripe · Promo codes accepted

Next Intake

September 2026 — register your interest at educ4te.com

Format

Live online training with a dedicated lab tenant — 4 days intensive or 8 weeks part-time

Group & Enterprise Options

Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.

What's Included

  • 32 hours of instructor-led SOC instruction with a live lab environment per analyst
  • Hands-on KQL threat hunting labs building from fundamentals to cross-workspace correlation
  • Investigation scenarios sourced from published ACSC advisories and OAIC breach reports
  • Reusable Sentinel analytics rules, hunting queries and Logic Apps playbook templates
  • Ransomware and business email compromise response runbooks you keep
  • Timed SC-200 mock exam with domain-by-domain answer explanations
  • Recorded sessions and lab guides for 6 months
  • Certificate of completion and 30 days of post-course email support

Have questions about this course?