Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
02Microsoft Defender for Endpoint9 modules · 60 units · 5 hr 49 min · Deployment, attack surface reduction, investigations, response, automation, detections, and vulnerability management0/60 units complete
Learning path 02 · Microsoft Defender for Endpoint

9 modules · 60 units · 5 hr 49 min · Deployment, attack surface reduction, investigations, response, automation, detections, and vulnerability management

0%

Study focus

Endpoint readiness

Deploy, onboard, configure, and harden devices with Microsoft Defender for Endpoint.

Investigation and response

Investigate devices and evidence, take response actions, automate remediation, and tune detections.

9 modules · 60 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

06

Module 6

Perform evidence and entities investigations using Microsoft Defender for Endpoint

Focus: file, user, IP address, and domain entity pages and the pivots between them.
0/7
01 / 07Introduction

Entity investigation builds scope by pivoting from evidence to related alerts, incidents, devices, users, processes, network destinations, prevalence, and threat intelligence.

Official moduleEntity investigation objectives
02 / 07Investigate a file

The file page uses a hash as the entity key and shows verdict, prevalence, first/last seen, signer and certificate information, observed devices, related alerts, file names and paths, and execution behavior. Low prevalence, unsigned status, suspicious origin, or links to active alerts increase concern.

Available actions can include stop and quarantine, add an indicator, download, deep analysis, or go hunt. Always validate scope and business impact before blocking a hash.

Official lessonFile evidence, prevalence, and response
03 / 07Investigate a user account

The user page shows identity details, risk and investigation context, related alerts and incidents, observed devices, and user activity. Use it to determine whether activity is isolated to one endpoint or follows the identity across devices and services.

Exam takeaway: a user pivot broadens an endpoint investigation into identity scope; correlate with Entra ID and Defender for Identity signals in Defender XDR.
Official lessonUser entity investigation
04 / 07Investigate an IP address

The IP page combines Microsoft threat intelligence with internal observations: reputation, registration and location context, related alerts, contacted devices, and observed network events. Distinguish external infrastructure from internal addresses and proxies before creating an indicator.

Official lessonIP reputation and device observations
05 / 07Investigate a domain

The domain page shows verdict and reputation, related alerts, resolved IPs, communicating devices, and observed URLs or events. Check whether the domain is newly observed, rare, connected to suspicious processes, or part of known infrastructure.

Official lessonDomain evidence and pivots
06 / 07Module assessment

Know which entity page answers each question: file prevalence and signer, user/device relationships, IP reputation and contacted devices, or domain resolution and communications.

Official assessmentEvidence and entities knowledge check
07 / 07Summary and resources

Entity pivots turn a single alert into a scoped investigation. Build a relationship graph, establish prevalence and reputation, hunt for additional observations, then contain the smallest justified scope.

Official moduleSummary and resources
End of learning pathMicrosoft Defender for Endpoint