
Gain hands-on security operations training with 24/7 access to custom practice labs and simulations aligned to the SC-200 exam objectives, ensuring real-world practice beyond slides.
Build a solid foundation by reviewing on premise Active Directory and domain services, RAR and DMZ, virtualization, and the Microsoft 365 and Azure cloud services, including IaaS, PaaS, and SaaS.
Explore the foundations of active directory domains, including domain controllers, replication, DNS, Kerberos, NTLM, and LDAP, and see how GPOs, DNS, and file services shape authentication in a cloud-oriented environment.
Explore the foundations of remote access with RAS and VPN, secure DMZ perimeter networks, and virtualization concepts like Hyper-V, redundancy, and elastic memory for secure cloud-ready infrastructure.
Explore how cloud services emerged from data centers and examine IaaS, PaaS, and SaaS, including Azure and Microsoft 365 offerings, with key tools like Intune, Exchange Online, and Azure AD.
Understand that Microsoft cloud services constantly change, require agility, and that menus, buttons, and names move weekly, making it impossible to track every update.
Explore how Microsoft renames core portals, such as Azure Active Directory to IntraID, and how portal links are updated to admin.microsoft.com and defender.microsoft.com, with an always-updated portals.examlabpractice.com resource.
John Christopher invites questions from thousands of learners, urges patience, and points to official Microsoft docs and exam lab practice for fast answers, with Udemy for exam questions.
I structure the course objectives in a logical order, placing foundational concepts before advanced ones, and explain that exam objectives aren’t fixed and may be renamed or covered across videos.
Earn your certificate of completion by watching all the videos; assignments do not matter, and a final video explains how to obtain your certificate.
navigate assignments and simulations in the sc-200 course, understand that only videos matter for certification, and follow step-by-step guidance to run simulations and resolve occasional check-off glitches.
Set up a lab environment by obtaining a free Microsoft 365 E5 trial, activate the subscription, and explore a 30-day Teams trial while noting regional availability.
Create a free Microsoft 365 account with a new email, verify by phone, start a 30-day trial, and learn to navigate marketplace, assign a license, and cancel.
Start the Azure free trial to receive $200 credit for 30 days and access free services for up to a year, then switch to pay-as-you-go if needed.
Configure devices to join Microsoft Entra ID and enable automatic enrollment with Microsoft Intune for device management, including MDM and Windows information protection settings.
Disable security defaults in Microsoft Entra ID to unlock granular controls, balance MFA requirements, and transition to conditional access policies. Navigate to portal.azure.com, Entra ID, properties, to disable the feature.
Explore the Microsoft 365 Defender suite, linking endpoints, identity, cloud apps, and data loss prevention to orchestrate detections, alerts, and automated responses across Microsoft 365 and Azure.
Understand how Microsoft Defender functions as an extended detection and response (XDR) platform, unifying logs, threat intelligence, and automated responses across on-prem and cloud environments.
Explore how Microsoft 365 Defender and Purview relate, navigate their admin centers on portal.azure.com, and note licensing activation delays before diving deeper into security and compliance.
Leverage Microsoft Defender for Endpoint to detect and remediate threats across devices with endpoint detection and response, threat and vulnerability management, attack surface reduction, and cloud security analytics.
Create a Microsoft Defender admin role with read and manage permissions, covering security operations, security posture, and authorization settings; assign it to a user and apply principle of least privilege.
Onboard a device to defender for endpoint using the local script method, from download to enrollment in the portal, with options across Windows, Mac, Linux, and servers.
Learn how to onboard hundreds of Windows devices automatically by enabling automatic enrollment in Microsoft Entra ID and Intune, and connect Defender for Endpoint for seamless device security.
Verify Windows device onboarding by checking Defender for Endpoint assets for an active sensor health, or confirm on the device with Task Manager services 'sense' and a registry onboarding state.
Explore Defender for Endpoint in portal security, noting that extra features appear after license activation, with emphasis on configuration management and upcoming vulnerability management topics.
Explore configuring Defender for Endpoint in Microsoft 365 Defender, including advanced settings, device groups, alert rules, licenses, roles, SIEM integration, and Intune enforcement.
Review and respond to endpoint vulnerabilities in defender for endpoint by running a PowerShell test script, then view incidents and the plan two vulnerability dashboard.
Learn to configure device groups in Defender for Endpoint, choose remediation levels from no automated response to full remediation, and assign admin access to NYC device admins.
Identify unmanaged devices with Microsoft Defender for Endpoint's device discovery. Explore basic and standard discovery modes, Intune, network discovery, log analytics, and authenticated scans to uncover unmonitored devices.
Explore attack surface reduction rules in Microsoft Defender for Endpoint, configuring an ASR policy for Windows, auditing first, and reviewing audit reports to reduce the device attack surface.
Centralize and normalize logs from Azure, Microsoft 365, on-premises, and third-party sources with Microsoft Sentinel’s CIM/SIEM and SOAR. Automate detection, investigation, and response using AI-powered analytics, playbooks, and data connectors.
Plan and configure a Microsoft Sentinel workspace by creating a Log Analytics workspace, review prerequisites and pricing, and enable the Sentinel integration, including the 30-day free trial.
Learn how to redo simulations in the course by navigating from the assignment screen: go to summary, return to assignment, open instructions, and access the simulation link anytime.
Configure Microsoft Sentinel roles and Azure RBAC by selecting roles like Microsoft Sentinel reader, responder, contributor, and Playbook Operator, then assign them via access control IAM in Sentinel resource group.
Sentinel stores log types in a log analytics workspace and organizes data into tables from connected resources, with retention adjustable from 30 days to up to 12 years.
Activate and customize workbook templates in Microsoft Sentinel to visualize data from audit logs and role management, with templates sourced from Content Hub and AWS.
Create a custom workbook in Microsoft Sentinel by adding text, parameters, actions, and a KQL data source visualization to display sign-in logs in interactive charts.
Explore visualization options in Sentinel workbooks, including adding images and videos, editing queries, and applying visual formatting such as pie charts. Customize colors and values, then save the workbook.
Identify data connectors to ingest and normalize diverse logs into a central sentinel workspace for unified cloud and on-premises analysis.
Explore Content Hub in Microsoft Sentinel to discover data connectors, learn how to access Content Hub from the Azure and Defender portals, and connect sources for security telemetry.
Discover how Kusto Query Language (KQL), a SQL-like language, enables querying information within Microsoft Defender and Microsoft Sentinel for investigations, incidents, alerts, and hunting data.
Configure and use Microsoft Sentinel connectors from Azure and Defender, install Azure Activity, and manage Content Hub data sources to ingest diagnostic settings and Sentinel data.
Plan and configure the azure monitor agent (ama) to collect logs from windows and linux devices, and define data collection rules to control what is ingested into azure monitor logs.
Explore syslog and the common event format (CEF), and configure their data connectors in Microsoft Sentinel using the Azure Monitor agent (AMA) and a Linux forwarder.
Explore how windows security events are collected via Event Viewer and forwarded with Windows Event Forwarding (WEF) into Microsoft Sentinel through data connectors and the Azure Monitor Agent.
Create custom log tables in a Log Analytics workspace to store ingested data, then use a data collection rule to route logs to the Microsoft Sentinel workspace.
Configure sentinel to ingest azure activity and entra id data by setting up diagnostic exports to log analytics, launching an azure policy, and enabling sign-in, audit, and graph activity logs.
Visualize and optimize data ingestion in Microsoft Sentinel using workbooks and templates. Explore data sources, apply data connectors and data collection rules to filter and refine what gets ingested.
Run a phishing simulation using the attack simulator in Microsoft 365 Defender to test users, trigger training, and reinforce secure behavior through built-in training and reporting.
Explore the actions and submissions area of Microsoft 365 Defender, submit files or messages for analysis, and manage automated or manual investigations with actions like isolate, quarantine, or remove.
Identify and remediate security risks with Microsoft Secure Score in Defender, tracking security posture across identity, data, device, and apps, and following actionable recommendations to improve over time.
Analyze the latest threats in the microsoft 365 defender threat analytics dashboard, including ransomware and phishing, and assess their impact on your environment with analyst reports and recommended actions.
Configure and manage custom alert detections in Microsoft Defender by creating alert policies, selecting threat activities like detected malware in email, setting severity, triggers, and notifications.
Explore how Microsoft Sentinel uses entities to classify and enrich security data, map fields to accounts and IPs, and enable incident investigations, threat hunting, and automated responses.
Understand how sentinel analytics rules detect threats and anomalies using scheduled query rules, fusion, ml behavior analytics, and near real-time analytics, with customizable thresholds and automated responses via playbooks.
Create and manage analytics rules in Microsoft Sentinel using KQL queries to detect threats and generate alerts or incidents. Compare scheduled and near real-time queries, configure thresholds, and alert details.
Learn how ASIM normalizes diverse sources in Microsoft Sentinel with custom parsers and built-in schemas for cross-source detection, using kql-based queries.
Turn on behavioral analytics (ueba) in Microsoft Sentinel to create baselines for users, devices, and identities, and detect anomalies, reduce false positives, and catch insider threats or compromised accounts.
Learn how to configure threat policies in Microsoft Defender for Office 365, including anti-phishing, anti-spam, anti-malware, safe attachments and safe links, plus impersonation protection and quarantine management.
Investigate threats in Defender for Office 365 using Threat Explorer and threat analytics. Take actions to block, delete, or report emails, and remediate with automated investigations.
Explore how data loss prevention in Microsoft 365 Defender detects and blocks sensitive data across email, SharePoint, Teams, and endpoints, with policy tips and regulatory use cases.
Learn data loss prevention roles and permissions in Microsoft Purview, including compliance administrator, compliance data administrator, information protection admin, role groups, and custom roles, for assigning DLP privileges in admin.microsoft.com.
Create and customize a data loss prevention policy in Microsoft Purview, selecting U.S. financial data, applying to Exchange, SharePoint, OneDrive, and more, with policy tips, alerts, and simulation before activation.
Implement adaptive protection for data loss prevention in Microsoft Purview using Insider Risk Management, a dynamic ML-based system that adjusts enforcement by user risk levels.
Discover how data loss prevention policies use lower-numbered priorities to set precedence, with the most restrictive rule resolving conflicts across policies and their low volume and high volume rules.
Discover insider risk management in the Microsoft Purview toolset, defining policies, detecting and investigating insider threats, triaging alerts, and escalating cases to eDiscovery Premium for legal action.
Configure insider risk management connectors to ingest third-party data into Microsoft Purview, review permissions, and add 17a-4 connectors via the wizard to support policies, e-discovery, and retention.
Configure a custom insider risk policy in Microsoft Purview, selecting templates like data leaks, setting thresholds, prioritizing sensitive info types, and enabling alerts across users.
Explore Microsoft Defender for cloud, a cloud-native protection platform (CNAP) for multi-cloud environments that unifies DevSecOps, cloud security posture management, and cloud workload protection across Azure, AWS, and Google Cloud.
Explore Microsoft Defender for cloud, the cloud workload protection platform shielding servers, storage, containers, databases, and APIs. Learn to enable and manage protection plans in the Azure portal.
Discover and manage cloud apps with Defender for Cloud Apps, a cloud access security broker that monitors user activity, prevents shadow IT, and enforces data sensitivity and regulatory compliance.
Identify, investigate, and remediate security risks using Defender for cloud apps; learn policy management, app discovery, and incident investigation across cloud services.
Learn to investigate incidents in Microsoft Sentinel by configuring access with the Microsoft Sentinel Responder role, reviewing incidents and alerts in Defender, and understanding incident details, assets, and evidence.
Learn how automation rules automatically trigger actions on alerts and incidents to standardize triage and speed responses, and how playbooks built with Azure Logic Apps perform enrichment, remediation, and notifications.
Create an automation rule in Microsoft Sentinel to auto assign medium or high incidents on creation, based on severity, with playbook actions, ownership assignment, and serial execution by priority.
Create and configure Microsoft Sentinel playbooks using incident, alert, or entity triggers, leveraging Logic Apps templates and authorization steps to automate responses.
Microsoft Sentinel playbooks run automation on premises via a hybrid runbook worker linked to an Azure Automation account, enabling on-premises tasks through a cloud-based logic app.
Understand security compute units powering Microsoft Security Copilot, including provisioned capacity billed hourly and on-demand overage, managed via an Azure subscription and a usage monitor dashboard.
Configure anomaly-based analytics rules in Microsoft Sentinel, exploring the anomalies tab and UEBA anomalies, then build near real-time KQL rules to detect failed logon attempts with baseline and threshold.
Trigger and analyze security incidents in a Defender for Endpoint lab by using attack surface reduction demonstrations, PowerShell scripts, and synchronized logs to study threat activity.
Explore the incident investigation workflow in Microsoft Defender, view incidents, analyze attack stories, and review file, URL, and evidence and response details across a compromised device.
Explore Microsoft Purview auditing capabilities, comparing standard and premium licenses (E3/E5, E5 compliance, and the eDiscovery and audit add-on), with retention up to 10 years and intelligent insights.
Explore auditing in Microsoft Purview by navigating admin.microsoft.com, accessing audit, applying filters by dates, activities, users, and workloads to investigate events, view details, and export results.
Explore content search in Microsoft Purview to conduct eDiscovery for forensics, create cases, place holds, undelete deleted data, and run queries with sources and keywords to discover and preserve information.
Pull Microsoft Graph activity logs into Azure by creating a log analytics workspace and enabling diagnostic settings, then use Kusto query language to analyze the ingested data.
Learn how the Kusto query language (KQL) analyzes security data across Microsoft Defender XDR, Microsoft Sentinel, and Microsoft Purview using table-based queries, pipes, filters, and time-based aggregations.
Explore the Microsoft KQL demo environment, download the provided resources, and use AI copilots to craft and run KQL queries on the security event table.
Explore kql in azure’s demo environment, querying the security event table with where and event id 4624, using pipes and intellisense to filter by computer, user, and process.
Learn to summarize kcl results and filter by time ranges in security events. Use where, summarize, dcount, and by to count and surface top event sources.
Learn to use KQL to display security event data by columns, perform time-based calculations, and sort results. Project time generated and filter by IP and keywords like PowerShell.
Use let to declare temporary variables in KQL, such as logon events, and append counting by account, then merge data with union and join for integrated security outputs.
Learn to perform advanced hunting in Defender with KQL, query device and email events, apply filters, and interpret alert evidence for security insights.
Explore Microsoft Sentinel hunting queries from the Microsoft Defender repository, including device inventory, copy these KCL queries, and paste them into Defender advanced hunting to run and customize time ranges.
We really hope you'll agree, this training is way more then the average course on Udemy!
Have access to the following:
Training from an instructor of over 20 years who has trained thousands of people and also a Microsoft Certified Trainer
Lecture that explains the concepts in an easy to learn method for someone that is just starting out with this material
Instructor led hands on and simulations to practice that can be followed even if you have little to no experience
TOPICS COVERED INCLUDING HANDS ON LECTURE AND PRACTICE TUTORIALS:
Introduction
Welcome to the course
Understanding the Microsoft Environment
Foundations of Active Directory Domains
Foundations of RAS, DMZ, and Virtualization
Foundations of the Microsoft Cloud Services
DONT SKIP: The first thing to know about Microsoft cloud services
DONT SKIP: Azure AD is now renamed to Entra ID
Questions for John Christopher
Order of concepts covered in the course
Performing hands on activities
DONT SKIP: Using Assignments in the course
Creating a free Microsoft 365 Account
Activating licenses for Defender for Endpoint and Vulnerabilities
Getting your free Azure credit
Setting up Microsoft Entra for device management
Disable Security Defaults in Entra ID before proceeding
How to setup an Azure virtual machine for practicing hands on
Setting up Microsoft Entra for device management
How to join our test virtual machine to Microsoft Entra
Configure automation for Microsoft Defender XDR and Microsoft Sentinel
Introduction to Microsoft 365 Defender
Concepts of the purpose of extended detection and response (XDR)
Microsoft Defender and Microsoft Purview admin centers
Concepts of management with Microsoft Defender for Endpoint
Vulnerability Management has been moved
Setting up a Microsoft Defender Admin role for permissions
Onboarding to manage devices using Defender for Endpoint
Bulk automatic onboarding with Microsoft Intune
How to verify Windows devices have been onboarded
A note about extra features in your Defender for Endpoint
Incidents, alert notifications, and advanced feature for endpoints
Review and respond to endpoint vulnerabilities
Configure and manage device groups
Identify devices at risk using the Microsoft Defender Vulnerability Management
Identify unmanaged devices by using device discovery
Configure security policies including attack surface reduction (ASR) rules
Concepts of Microsoft Sentinel
Plan a Microsoft Sentinel workspace
Configure the Microsoft Sentinel SIEM and platform
Configure Microsoft Sentinel roles and specify Azure RBAC roles
Design and configure Microsoft Sentinel data storage,log types and log retention
Activate and customize workbook templates
Create custom workbooks that include KQL
Configure visualizations
Ingest data into the Microsoft Sentinel SIEM and platform
Identify data sources to be ingested for Microsoft Sentinel
Implement and use Content hub solutions
A note about Kusto Query Language (KQL)
Configure & use MS connectors for Azure, including Azure Policy & diagnostics
Plan and configure Azure Monitor Agent (AMA) and data collection rules
Plan and configure Syslog and Common Event Format (CEF) event collections
Collection of Windows Security events and Windows Event Forwarding (WEF)
Create custom log tables in the workspace to store ingested data
Configure Sentinel to ingest Azure and Entra ID data
Monitor and optimize data ingestion
Configure detections
Run an attack simulation email campaign in Microsoft 365 Defender
Manage actions and submissions in the Microsoft 365 Defender portal
Identify and remediate security risks by using Microsoft Secure Score
Analyze threat analytics in the Microsoft 365 Defender portal
Configure and manage custom detections and alerts
Classify and analyze data by using entities
Concepts of Microsoft Sentinel analytics rules
Configure and manage analytics rules
Query Microsoft Sentinel data by using ASIM parsers
Implement behavioral analytics
Respond to alerts and incidents in Microsoft Defender XDR
Using polices to remediate threats with Email, Teams, SharePoint & OneDrive
Investigate, respond, and remediate threats with Defender for Office 365
Understanding data loss prevention (DLP) in Microsoft 365 Defender
Understanding Data loss prevention roles and permissions
Implement data loss prevention policies (DLP)
Adaptive Protection with data loss prevention
Policy and rule precedence in Data Loss Prevention
Understanding insider risk policies
Implement Insider Risk Management connectors
Generating an insider risk policy
Overview of Microsoft Defender for Cloud
Assess and recommend cloud workload protection and enable plans
Investigate information identified by MS Defender for Cloud workload protection
Discover and manage apps by using Microsoft Defender for Cloud Apps
Identify, investigate, & remediate security risks by using Defender for Cloud Apps
Investigate and remediate incidents in Microsoft Sentinel
Understanding automation rules and Microsoft Sentinel playbooks
Create and configure automation rules
Create and configure Microsoft Sentinel playbooks
Run playbooks on on-premises resources
What Microsoft Security Copilot (MSC)?
Security compute units (SCUs) in Security Copilot
Warning before allocating SCUs for Security Copilot
Allocating SCUs for Security Copilot
Setting up sample alerts for querying with Security Copilot
Investigating an incident involving a VM with Security Copilot
IMPORTANT Delete your SCUs
Respond to alerts and incidents identified by Microsoft Defender for Endpoint
Configure anomaly detection analytics rules
How to trigger some incidents using a client device for testing
Investigate timeline of compromised devices
Investigate Microsoft 365 activities to identify threats
Understanding unified audit log licensing and requirements
Setting unified audit permissions and enabling support
Investigate threats by using Content Search
Perform threat hunting by using Microsoft Graph activity logs
Detect threats by using Microsoft Defender XDR
Identify purposes of using Kusto Query Language (KQL)
Practicing with KQL in Microsoft's Demo environment
Searching for information using basic KQL syntax
Summarizing KQL results and filtering based on time ranges
Using KQL to display data based on columns, amounts and characters
Implementing variables and combining output data with KQL
Identify and interpret threats analytics by using KQL in Defender
Customizing hunting queries using Microsoft's Sentinel and Defender repository
Detect threats by using the Microsoft Sentinel platform
Analyze attack vector coverage by using the MITRE ATT&CK matrix
Manage and use threat indicators
Create and manage hunts
Create and monitor hunting queries
Use hunting bookmarks for data investigations
Retrieve and manage archived log data
Create and manage search jobs
Conclusion
Cleaning up your lab environment
Getting a Udemy certificate
BONUS Where do I go from here?