Welcome to Microsoft Sentinel, Microsoft Defender XDR & Threat Protection, a deep-dive course designed for cloud security engineers, SOC analysts, and IT professionals who want to master Microsoft’s advanced detection, response, and threat protection ecosystem.
This course covers the end-to-end workflow of cloud security operations using Microsoft Sentinel (SIEM & SOAR) and Microsoft Defender XDR. You’ll explore workspace planning, SIEM roles, SOAR automation, threat detection, and hunting queries in Sentinel. You’ll then move into Defender XDR configuration, integration with Sentinel, and best practices for incident response. Finally, you’ll learn about the entire Microsoft Defender product family (Defender for Cloud Apps, Office 365, Identity, and Endpoint) to build a unified threat protection strategy.
By the end of this course, you’ll be confident in deploying, configuring, and managing Microsoft Sentinel and Microsoft Defender XDR to detect, investigate, and respond to modern cloud threats.
Who Should Take This Course?
SOC Analysts and Incident Responders
Cloud Security Engineers and Azure Administrators
IT Security Professionals looking to implement SIEM + XDR
Learners preparing for SC-200 or seeking advanced Microsoft security skills
Course Format
This course delivers 6–7 hours of expert-led video content, split across four modules. Each module includes demos, configuration guides, and best practices. Knowledge checks and in-video questions are included to help reinforce learning.
Course Modules:
Module 1: Azure Security Foundations: Networking, Key Vault & Defender
Module 2: Microsoft Sentinel: SIEM & SOAR for Cloud Security Operations
Module 3: Microsoft Defender XDR: Configuration, Integration & Best Practices
Welcome to Week 1 of this course! We’ll begin with the essential building blocks for securing Azure workloads. You’ll explore Azure networking security, including Azure DDoS Protection, Azure Bastion, and Azure Firewall, to understand how to defend your resources at the network edge. Next, we’ll dive into network segmentation using Azure Virtual Networks, and configure Network Security Groups (NSG) and Application Security Groups (ASG) with hands-on demos. You’ll also explore Azure Key Vault and see how to secure application secrets and configuration data using App Configuration and Key Vault demos. Finally, we’ll introduce Microsoft Defender for Cloud, its Cloud Security Posture Management (CSPM) capabilities, and workload protection features to help you proactively strengthen your cloud security posture.
涵盖的内容
13个视频3篇阅读材料3个作业
显示有关单元内容的信息
13个视频•总计77分钟
Azure DDoS and Bastion Service - Overview•5分钟
Azure Firewall•3分钟
Network Segmentation with Azure Virtual Networks•4分钟
Network Security Groups - Demo•3分钟
Applicaiton Security Groups - Demo•9分钟
Azure Key Vault - Overview•3分钟
Secure App Configuration data by using App Configuration or Azure Key Vault - Demo•13分钟
Microsoft Defender for Cloud - Overview•6分钟
Microsoft Defender for Cloud - Demo•4分钟
Cloud Security Posture Management (CSPM)•5分钟
Security policies and initiatives improve the cloud security posture•7分钟
Microsoft Defender for Cloud Workload Protection•5分钟
Enhanced security features provided by cloud workload protection•9分钟
Microsoft Sentinel: SIEM & SOAR for Cloud Security Operations
第 2 单元•小时 后完成
单元详情
Welcome to Week 2! this week, we’ll focus on Microsoft Sentinel and its role as a cloud-native SIEM and SOAR solution. You’ll learn how to plan and deploy workspaces, align Sentinel implementation with Microsoft’s Cloud Adoption Framework (CAF) security design phases, and understand the role of SIEM in modern security operations. We’ll then explore Sentinel’s automation capabilities with SOAR, threat detection, and mitigation features. By the end of this week, we’ll dive into threat hunting, reviewing sample KQL queries and walking through a hands-on demo to see how to proactively hunt for threats in your environment.
涵盖的内容
8个视频1篇阅读材料2个作业
显示有关单元内容的信息
8个视频•总计49分钟
What is Microsoft Sentinel?•5分钟
Workspace Planning in Microsoft Sentinel•6分钟
Aligning security with the CAF design phases•8分钟
The Role of SIEM in Security Operations•7分钟
Automating Security Tasks with SOAR•5分钟
Threat detection and mitigation capabilities in Microsoft Sentinel•7分钟
Explore Threat Hunting Queries - Overview•5分钟
Explore Threat Hunting Queries - Demo•7分钟
1篇阅读材料•总计20分钟
Microsoft Sentinel: SIEM & SOAR for Cloud Security Operations - Course Overview•20分钟
2个作业•总计90分钟
Microsoft Sentinel Capabilities - Practice Assessment•40分钟
Microsoft Sentinel: SIEM & SOAR for Cloud Security Operations - Graded Assessment•50分钟
Microsoft Defender XDR: Configuration, Integration & Best Practices
第 3 单元•小时 后完成
单元详情
Welcome to Week 3! this week focuses on governance and identity protection features of Microsoft Entra ID. You’ll explore Privileged Identity Management (PIM) to enforce just-in-time (JIT) access, conduct access reviews, and automate provisioning/deprovisioning. This week also covers Microsoft Entra ID Protection, showing how to detect and mitigate identity risks with real-time monitoring. By the end of the week, you will be able to Configure MFA and passwordless authentication methods, Design Conditional Access policies for secure access and Implement RBAC effectively at tenant, group, or resource scope.
涵盖的内容
17个视频3篇阅读材料3个作业
显示有关单元内容的信息
17个视频•总计89分钟
What is Microsoft Defender XDR?•4分钟
Key Benefits of Microsoft Defener XDR•4分钟
Microsoft Defender XDR vs. Traditional Security Tools•4分钟
Threat Analytics Overview•4分钟
Creating Lab Environment - Step by Step•8分钟
Connecting Microsoft Defender XDR to Microsoft Sentinel•9分钟
Best Practices for Microsoft Defender XDR•4分钟
Microsoft Defender Family - Overview•6分钟
Microsoft Defender for Cloud Apps•6分钟
Microsoft Defender for Office 365•6分钟
Defender Vulnerability Management - Overview•6分钟
Defender Vulnerability Management - Demo•4分钟
Microsoft Defender for Identity•7分钟
Microsoft Defender Threat Intelligence (Defender TI)•5分钟
Microsoft Defender portal•3分钟
Microsoft Defender for Endpoint Overview•6分钟
Advanced Features of Defender for Endpoint•5分钟
3篇阅读材料•总计65分钟
Microsoft Defender XDR: Configuration, Integration & Best Practices - Course Overview•25分钟
Specialization: Course 3 Summary•20分钟
What's Next + Best Practices•20分钟
3个作业•总计150分钟
Microsoft Defender XDR - Overview - Practice Assessment•50分钟
Threat Protection with Microsoft Defender XDR - Practice Assessment•40分钟
Microsoft Defender XDR: Configuration, Integration & Best Practices - Graded Assessment•60分钟
Providing certification training since the year 2000, Whizlabs is the pioneer among online training providers across the globe. We are dedicated to helping you learn the skills you need to transform your career in the IT industry.
We provide certification training in the form of Video Courses, Practice Tests, Hands-on Labs and Sandbox in various disciplines such as Cloud Computing, DevOps, Cyber Security, Java, Big Data, Snowflake, CompTIA, Agile, Linux, CCNA, Blockchain, and much more.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I subscribe to this Specialization?
When you enroll in the course, you get access to all of the courses in the Specialization, and you earn a certificate when you complete the work. Your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.