MicrosoftAssociate· Microsoft Security Associate

Microsoft Security Operations Analyst

Official MOC SC-200 course. Trains analysts to mitigate threats with Microsoft Sentinel, Defender XDR, and Defender for Cloud.

Duration
32h
Modality
Online live
Exam code
SC-200
Certification
Microsoft Certified: Security Operations Analyst Associate
Class confirmed
Next class
Aug 31, 2026

Audience

SOC analysts operating Microsoft Defender and Sentinel.

Learning objectives

  • Investigate and respond to alerts in Defender XDR
  • Operate Microsoft Sentinel (KQL, hunting, playbooks)
  • Apply Defender for Cloud to protect workloads

Prerequisites

To get the most from this course, we recommend prior mastery of the fundamentals covered in AZ-900 (Microsoft Azure Fundamentals) or equivalent knowledge acquired through professional experience or self-study. Holding the previous certification is not required — what matters is mastering the topics below:

  • Describe cloud concepts and service models
  • Identify Azure architecture, compute, networking, and storage
  • Understand identity, governance, compliance, and cost

Syllabus

01

Defender XDR

In this module of SC-200 — Microsoft Security Operations Analyst, you deepen defender xdr within the Microsoft ecosystem, with practical focus on the topics required by the official SC-200 blueprint. Content combines theoretical fundamentals, instructor-led demonstrations and lab exercises to consolidate Defender for Endpoint, for Office 365, for Identity, for Cloud Apps.

Topics covered

  • Defender for Endpoint
  • for Office 365
  • for Identity
  • for Cloud Apps
02

Defender for Cloud

In this module of SC-200 — Microsoft Security Operations Analyst, you deepen defender for cloud within the Microsoft ecosystem, with practical focus on the topics required by the official SC-200 blueprint. Content combines theoretical fundamentals, instructor-led demonstrations and lab exercises to consolidate Posture, CWPP.

Topics covered

  • Posture
  • CWPP
03

Sentinel

In this module of SC-200 — Microsoft Security Operations Analyst, you deepen sentinel within the Microsoft ecosystem, with practical focus on the topics required by the official SC-200 blueprint. Content combines theoretical fundamentals, instructor-led demonstrations and lab exercises to consolidate Data connectors, Analytics rules, KQL, SOAR.

Topics covered

  • Data connectors
  • Analytics rules
  • KQL
  • SOAR
04

Threat Hunting

In this module of SC-200 — Microsoft Security Operations Analyst, you deepen threat hunting within the Microsoft ecosystem, with practical focus on the topics required by the official SC-200 blueprint. Content combines theoretical fundamentals, instructor-led demonstrations and lab exercises to consolidate Hunting queries, MITRE ATT&CK, Notebooks.

Topics covered

  • Hunting queries
  • MITRE ATT&CK
  • Notebooks

Upcoming classes

StatusDateModalityHoursContact
ConfirmedAug 31, 2026 Online live32h
See all classes Microsoft (all courses)Full calendar Microsoft