Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
01Microsoft Defender XDR6 modules · 53 units · Defender XDR, Defender for Office 365, Entra ID Protection, Defender for Identity, and Defender for Cloud Apps0/53 units complete
Learning path 01 · Microsoft Defender XDR

6 modules · 53 units · Defender XDR, Defender for Office 365, Entra ID Protection, Defender for Identity, and Defender for Cloud Apps

0%

Study focus

Incident operations

Correlate, investigate, hunt, and remediate threats across Defender XDR.

Domain protection

Protect email, identities, Active Directory, cloud apps, and sensitive data.

6 modules · 53 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

03

Module 3

Remediate threats using Microsoft Defender

Focus: Defender for Office 365, AIR, Safe Attachments, Safe Links, anti-phishing, Security Copilot phishing triage, and attack simulation.
0/6
01 / 06Introduction to Defender for Office 365

Defender for Office 365 is a cloud email-security service providing zero-day malware protection, time-of-click URL defense, investigation, reporting, automated response, and user training. It can protect Exchange Online, on-premises SMTP environments, and hybrid deployments.

Official lessonDefender for Office 365 capabilities
02 / 06Automate, investigate, and remediate

Office 365 AIR playbooks start automatically from alerts or manually from Explorer. The investigation graph correlates URLs, messages, users, sign-ins, devices, and activities.

  • Possible actions: soft-delete messages/clusters, block URLs at time of click, disable external forwarding, and remove delegation.
  • Compromised-user workflows can trigger password reset and MFA.
  • Actions may run automatically or await approval in Pending actions.
Official lessonOffice 365 AIR and remediation
03 / 06Configure, protect, and detect

Safe Attachments

Unknown attachments are detonated in an isolated environment. Actions include Off, Monitor, Block, Replace, and Dynamic delivery. Dynamic delivery releases the body first and attaches the file only after a safe verdict.

Safe Links

URLs are rewritten and checked at click time across email, Office apps, and Teams. Policies can scan downloadable content, protect internal messages, track clicks, prevent user click-through, and exclude trusted URLs.

Anti-phishing

Policies detect user/domain impersonation and spoofing using machine-learning models, protected users/domains, actions, safety tips, and trusted senders.

Exam takeaway: Safe Attachments protects files; Safe Links protects URLs; anti-phishing protects against spoofing and impersonation.
04 / 06Security Copilot Phishing Triage Agent

The agent analyzes user-reported suspicious messages, applies contextual LLM reasoning, and classifies alerts as true phishing threats or false positives. It records rationale, assigns itself, tags incidents, resolves false positives, and leaves true positives open for analyst action.

  • Requires Security Copilot capacity, Defender for Office 365 Plan 2, unified RBAC, user-reported message monitoring, and the relevant alert policy.
  • Suppressed alerts are not classified by the agent.
  • Analyst feedback helps improve future classifications.
05 / 06Simulate attacks

Threat Explorer analyzes recent threats, families, targeted users, sender data, delivery action, and user interaction. Attack Simulation Training runs realistic scenarios such as spear phishing, credential harvest, malicious attachments, password spray, and brute force to identify weaknesses and train users.

Official lessonThreat Explorer and attack simulations
06 / 06Summary and knowledge check
Requires endpoint agent → False
Defender for Office 365 is a cloud email-security service.
Safe Attachments → routes messages and attachments to an isolated analysis environment
Not an Attack Simulator scenario → Bitcoin mining
Official assessmentSummary and three questions
End of learning pathMicrosoft Defender XDR