Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
05Configure your Microsoft Sentinel environment6 modules · 42 units · SIEM architecture, workspaces, logs, watchlists, threat intelligence, and unified SIEM/XDR0/42 units complete
Learning path 05 · Configure your Microsoft Sentinel environment

6 modules · 42 units · SIEM architecture, workspaces, logs, watchlists, threat intelligence, and unified SIEM/XDR

0%

Study focus

Sentinel foundation

Understand the SIEM workflow and design workspaces, permissions, retention, and data tiers.

Security context

Use logs, watchlists, threat intelligence, and Defender XDR integration to support operations.

6 modules · 42 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

01

Module 1

Introduction to Microsoft Sentinel

Focus: cloud-native SIEM and SOAR, the end-to-end Sentinel workflow, and appropriate use cases.
0/6
01 / 06Introduction

Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration, automation, and response (SOAR) platform. It collects signals across cloud, on-premises, and multicloud environments for detection, investigation, hunting, and response.

Official moduleObjectives and prerequisites
02 / 06What is Microsoft Sentinel?

A SIEM centralizes log management, queries, correlation and anomaly detection, alerts, visualization, and incident management. Sentinel provides these capabilities as an Azure service without dedicated SIEM servers.

  • Collect: ingest security data from Microsoft and third-party sources.
  • Detect: use analytics, machine learning, and threat intelligence.
  • Investigate: correlate alerts into incidents and examine entities.
  • Respond: orchestrate actions with automation rules and Logic Apps playbooks.
Official lessonSIEM and Microsoft Sentinel
03 / 06How Microsoft Sentinel works
1 · IngestContent Hub solutions and data connectors bring data into the workspace.
2 · AnalyzeKQL, analytics rules, UEBA, and threat intelligence identify suspicious behavior.
3 · InvestigateAlerts become correlated incidents with entities and timelines.
4 · RespondAutomation rules and playbooks enrich, route, contain, or remediate.

Workbooks visualize KQL results; hunting queries and notebooks support proactive investigation. Content Hub packages connectors, analytics, workbooks, hunting queries, and automation content for a product or scenario.

Exam takeaway: connector → table → analytics alert → incident → automation is the core operational chain.
Official lessonSentinel components and workflow
04 / 06When to use Microsoft Sentinel

Use Sentinel when a SOC needs security collection and analytics across diverse sources, threat hunting, incident investigation, and automated response without managing SIEM infrastructure. It supports hybrid and multicloud data and integrates with hundreds of Logic Apps connectors.

Use Azure Monitor and Log Analytics primarily for operational or application monitoring. Use Defender for Cloud for posture management and cloud workload protection, and forward its alerts into Sentinel when centralized SIEM correlation is needed.

Official lessonSentinel use cases and adjacent services
05 / 06Module assessment

Review the difference between SIEM and SOAR, Sentinel's cloud-native model, and which components perform ingestion, visualization, detection, investigation, hunting, and response.

Official assessmentSentinel fundamentals knowledge check
06 / 06Summary

Sentinel delivers an end-to-end cloud security operations platform: ingest broadly, detect with analytics, investigate correlated incidents, hunt proactively, and automate repeatable response.

Official moduleSummary and resources
End of learning pathConfigure your Microsoft Sentinel environment