Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
01Microsoft Defender XDR6 modules · 53 units · Defender XDR, Defender for Office 365, Entra ID Protection, Defender for Identity, and Defender for Cloud Apps0/53 units complete
Learning path 01 · Microsoft Defender XDR

6 modules · 53 units · Defender XDR, Defender for Office 365, Entra ID Protection, Defender for Identity, and Defender for Cloud Apps

0%

Study focus

Incident operations

Correlate, investigate, hunt, and remediate threats across Defender XDR.

Domain protection

Protect email, identities, Active Directory, cloud apps, and sensitive data.

6 modules · 53 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

02

Module 2

Mitigate incidents using Microsoft Defender

Focus: unified incident management, automated investigation and response, advanced hunting, reporting, and Defender portal configuration.
0/15
01 / 15Introduction

Defender XDR coordinates pre- and post-breach detection, prevention, investigation, and response. The Defender portal correlates alerts from Endpoint, Identity, Cloud Apps, and other workloads into incidents so analysts can see entry point, scope, impact, and root cause.

Exam takeaway: an incident is the cross-product attack story; an alert is one detection within that story.
Official lessonIntroduction
02 / 15Use the Microsoft Defender portal

security.microsoft.com is the central workspace for email, collaboration, identity, endpoint, application, vulnerability, IoT, and Sentinel-connected security. Home-page content is role-aware through RBAC.

  • Unified RBAC maps legacy workload permissions into common groups for security data, response, posture, and settings.
  • Apply least privilege; reserve Global Administrator for emergency scenarios.
  • Sentinel integration synchronizes Defender XDR incidents and advanced-hunting events.
  • Related portals remain accessible through More resources.
Exam takeaway: know the difference between portal unification and workload-specific permissions.
03 / 15Manage incidents

An incident aggregates correlated alerts affecting devices, users, mailboxes, and apps. The queue normally shows the last 30 days and supports prioritization by severity, impacted assets, alert sources, tactics, status, and assignment.

  • Manage ownership, status, tags, name, classification, and determination.
  • Classifications include true positive, false positive, and informational/expected activity categories.
  • Automatic investigation may resolve supported alerts; analysts can add remediation.
  • Incident naming summarizes affected endpoints, users, sources, or categories.
Exam takeaway: accurate classification improves alert quality and future correlation.
Official lesson + embedded videoIncident management overview
04 / 15Investigate incidents

The incident overview exposes attack categories mapped to MITRE ATT&CK, impacted assets, alert chronology, evidence, and remediation status. Pivot through Alerts, Devices, Users, Mailboxes, Apps, Investigations, Evidence and Responses, and the Incident graph.

  • Evidence verdicts: Malicious, Suspicious, or Clean.
  • The graph shows entry point, indicators, entities, and relationships.
  • Blast radius analysis combines post-breach impact with possible pre-breach propagation to critical assets.
  • Blast radius requires Sentinel data lake/graph and appropriate unified RBAC.
Exam takeaway: use timeline and graph for sequence; use evidence status and entity tabs for scope and remediation.
Official lessonIncident investigation and blast radius
05 / 15Manage and investigate alerts

Alert management includes severity, category, incident linkage, assignment, status, classification, determination, comments, and history. Severity reflects organizational impact, not only the absolute malware severity on one device.

  • Statuses: New, In progress, Resolved.
  • Categories align closely with MITRE ATT&CK tactics, plus categories such as Malware, Ransomware, and Unwanted software.
  • Suppression can apply to one device or the organization and affects only future matching alerts.
  • The alert story explains why the alert fired and shows related entities and events.
Exam takeaway: resolve and classify alerts after investigation; use narrow suppression for known benign activity.
Official lessonAlert metadata, story, actions, and suppression
06 / 15Manage automated investigations

Automated investigation and remediation (AIR) applies analyst-like playbooks to inspect alerts, expand across related devices, assign evidence verdicts, and take or recommend remediation actions.

  • Views: graph, alerts, devices, evidence, entities, log, and pending actions.
  • Verdicts: Malicious, Suspicious, No threats found.
  • Actions can quarantine files, stop services, remove scheduled tasks, and more.
  • Full automation is recommended; semi-automation requires approval based on configured folder scope.
  • Expansion to ten or more devices from the same entity requires approval.
Exam takeaway: automation level determines whether AIR remediation is automatic or waits for approval.
Official lessonAIR workflow and automation levels
07 / 15Use the action center

The unified Action center tracks remediation for devices, email/collaboration content, and identities. Pending contains actions awaiting approval; History is the audit trail for automated, approved, Live Response, and antivirus actions.

  • Approve or reject pending remediation after reviewing evidence and investigation context.
  • Some completed actions, including file quarantine, can be undone.
  • Always verify whether an action is pending, completed, failed, or reversible.
Official lessonPending and historical remediation actions
08 / 15Explore advanced hunting

Advanced hunting uses KQL to query up to 30 days of raw Defender XDR data across Endpoint, Office 365, Cloud Apps, and Identity. Event data arrives near real time; entity data refreshes incrementally and consolidates daily. Timestamps are UTC.

  • Learn schema families: Device*, Email*, Identity*, CloudAppEvents, AlertInfo, and AlertEvidence.
  • Custom detection queries must return Timestamp, DeviceId, and ReportId for device-based actions.
  • Rules can run every 24/12/3/1 hours or continuously (NRT), create alerts, and act on devices or files.
  • Hunting graph visualizes nodes and relationships for lateral movement and exposure analysis.
DeviceEvents
| where Timestamp > ago(7d)
| where ActionType == "AntivirusDetection"
| summarize (Timestamp, ReportId)=arg_max(Timestamp, ReportId), count() by DeviceId
| where count_ > 5
Exam takeaway: choose the correct table, preserve required event identifiers, tune results, then configure frequency, entities, actions, and scope.
Official lessonKQL, custom detections, and Hunting graph
09 / 15Investigate Microsoft Entra sign-in logs
LocationKQL table
Defender XDR Advanced HuntingAADSignInEventsBeta
Entra ID Log AnalyticsSigninLogs

Review date, user, application, status, Conditional Access result, location, device, and authentication details.

Official lessonSign-in log investigation
10 / 15Understand Microsoft Secure Score

Secure Score measures security posture and the implementation of recommended actions across identities, apps, devices, email, and third-party integrations. It is an Exposure Management tool—not proof that the organization is breach-free.

Recommended-action states include To address, Planned, Risk accepted, Resolved through third party, Resolved through alternate mitigation, and Completed.

Exam takeaway: a higher score means more recommendations addressed; use the recommendations to prioritize posture improvements.
Official lessonSecure Score and recommended actions
11 / 15Threat Intelligence Briefing Agent

The embedded Security Copilot agent generates prioritized briefings from recent threat-actor activity and organizational vulnerability context. It can summarize threats, exposures, and business impact, retain reports in Security Copilot Activity, and expose its activity for review.

  • Requires Security Copilot, Microsoft Threat Intelligence plugins, Defender Vulnerability Management access, and appropriate Security Reader/Admin permissions.
  • Briefings can be copied or downloaded as Markdown.
  • Analysts should review agent reasoning and provide feedback.
Official lesson + embedded videoThreat Intelligence Briefing Agent
12 / 15Analyze reports

The Reports blade centralizes security trends plus endpoint and email/collaboration reports. Key endpoint reports cover threat protection, device health, vulnerable devices, web protection, firewall, device control, and attack surface reduction. Email reports can be scheduled or downloaded.

Official lessonDefender reports
13 / 15Configure the Microsoft Defender portal

Defender XDR email notifications have two primary types: Incidents for newly created incidents and Threat Analytics for new reports. Configure criteria and recipients under Settings → Microsoft Defender XDR → Email notifications.

Official lessonEmail notification rules
14 / 15Module assessment
Incident-page tab → Assets
Incident classification → True positive
Devices page source → Microsoft Defender for Endpoint
Official assessmentThree questions
15 / 15Summary and resources

You should be able to manage and investigate Defender XDR incidents and alerts, review automated actions, hunt with KQL, and configure the portal.

End of learning pathMicrosoft Defender XDR