Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
05Configure your Microsoft Sentinel environment6 modules · 42 units · SIEM architecture, workspaces, logs, watchlists, threat intelligence, and unified SIEM/XDR0/42 units complete
Learning path 05 · Configure your Microsoft Sentinel environment

6 modules · 42 units · SIEM architecture, workspaces, logs, watchlists, threat intelligence, and unified SIEM/XDR

0%

Study focus

Sentinel foundation

Understand the SIEM workflow and design workspaces, permissions, retention, and data tiers.

Security context

Use logs, watchlists, threat intelligence, and Defender XDR integration to support operations.

6 modules · 42 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

02

Module 2

Create and manage Microsoft Sentinel workspaces

Focus: workspace architecture, region and tenancy, onboarding, RBAC, retention, table plans, and data tiers.
0/9
01 / 09Introduction

Microsoft Sentinel is enabled on a Log Analytics workspace. Workspace architecture therefore determines data residency, query scope, access control, retention, cost allocation, and how content is managed.

Official moduleWorkspace objectives
02 / 09Plan for the Microsoft Sentinel workspace
ArchitectureStrengthTradeoff
Single tenant, one workspaceCentral view, simpler content and cross-source queries.Cross-region bandwidth and data-residency concerns.
Single tenant, regional workspacesRegional governance, granular retention, access, and billing.Content must be deployed repeatedly; cross-workspace queries are required.
Multiple tenantsSupports service providers and distributed organizations.Requires delegated management such as Azure Lighthouse.
SecurityEvent
| union workspace("Regional-SOC").SecurityEvent

Region is the critical creation choice: it determines where ingested log data resides, and a workspace cannot be moved to another region. A deliberately created workspace can be shared with Defender for Cloud; its default workspace is not available for Sentinel onboarding.

Official lessonSingle, regional, and multitenant designs
03 / 09Create a Microsoft Sentinel workspace
  1. Create or select a Log Analytics workspace with the correct subscription, resource group, name, and region.
  2. Open Microsoft Sentinel, choose Add, select the workspace, and enable Sentinel.
  3. Verify Overview, Content Hub, connectors, analytics, incidents, and configuration areas.

Enabling Sentinel requires subscription Contributor permissions; using it requires suitable permissions on the workspace's resource group. Workspace creation and data ingestion can incur cost. The lesson includes an interactive lab simulation.

Exam takeaway: the Microsoft Sentinel workspace name and region come from its underlying Log Analytics workspace.
Official lesson and simulationCreate the workspace and enable Sentinel
04 / 09Manage workspaces across tenants using Azure Lighthouse

Workspace manager uses a central workspace to publish content at scale to member workspaces across one or more tenants. Azure Lighthouse delegates Azure resource access across tenants so authorized analysts or service providers can manage customer workspaces without switching accounts.

Use Workspace manager for centralized content operations; use Lighthouse for delegated cross-tenant resource administration. They can complement each other.

Official lessonWorkspace manager and Azure Lighthouse
05 / 09Understand Microsoft Sentinel permissions and roles
RolePrimary capability
Microsoft Sentinel ReaderView data, incidents, workbooks, and Sentinel resources.
Microsoft Sentinel ResponderReader capabilities plus incident assignment and management.
Microsoft Sentinel ContributorCreate and edit analytics, workbooks, and other Sentinel content; manage incidents.
Microsoft Sentinel Automation ContributorService role allowing Sentinel to add playbooks to automation rules; not intended for users.

Playbook authors or operators may also need Logic App Contributor. Sentinel's service account needs explicit permission on the playbook resource group. Guest responders need the Microsoft Entra Directory Readers role to assign incidents. Workbook creation can require Workbook Contributor.

Exam takeaway: Azure RBAC assignments inherit from subscription and resource group; a broader Azure role can grant more access than a Sentinel-specific role suggests.
Official lessonSentinel RBAC and supporting roles
06 / 09Manage Microsoft Sentinel settings

Sentinel-specific settings and the underlying Log Analytics workspace both govern the environment. Pricing, feature settings, and workspace links appear in Sentinel, while most ingestion, usage, retention, and table configuration is managed in Log Analytics or the Defender portal's Sentinel settings.

The lesson's workspace-level retention range is 30 to 730 days for supported plans. Table-level settings can override workspace defaults where available.

Official lessonWorkspace and retention settings
07 / 09Configure logs

Plan log storage by data state, table plan, and tier. Analytics retention supports interactive queries, alerts, hunting, and workbooks. Long-term retention lowers storage cost and is accessed through search jobs, restore, or lake jobs.

Plan / tierBest forKey limitation
Analytics plan / tierContinuous monitoring, detections, joins, hunting, and workbooks.Higher ingestion and retention cost.
Basic planOccasional troubleshooting with single-table queries.Restricted KQL; no join, union, or summarize in the lesson.
Auxiliary planVerbose, low-touch audit or compliance data.Unoptimized single-table access.
Data lake tierLow-cost secondary and long-term data.No real-time analytics or threat hunting; use KQL/Spark jobs and summaries.
XDR default tierDefender XDR hunting data included for 30 days.Not stored in Sentinel tiers unless supported retention is extended.

Analytics retention can be 30 days to two years; total lake retention can extend to 12 years where supported. Moving a table out of analytics can stop alerts, advanced hunting, analytics rules, and custom detections that depend on it.

Official lessonTable plans, tiers, and retention
08 / 09Module assessment

Review region and residency, single versus regional versus multitenant design, Workspace manager versus Lighthouse, Sentinel RBAC, and the operational consequences of table plans and tiers.

Official assessmentWorkspace knowledge check
09 / 09Summary and resources

A sound workspace design places data in the correct region, balances central visibility with governance, applies least privilege, and aligns each table's cost and retention with its detection and investigation use.

Official moduleSummary and resources
End of learning pathConfigure your Microsoft Sentinel environment