
What this section covers and how to get the most from the course, the labs and the SC-200 mapping.
The roles this course prepares you for, the skills employers ask for in 2026, and how every section maps to the SC-200 exam.
Identity attacks, ransomware, cloud intrusions and AI-assisted phishing, using recent public reports to show what a SOC defends against today.
What makes Sentinel different from on-premises SIEMs, where it fits with Defender XDR, and how the 2026 platform is organised.
How the free Azure account and the 31-day Sentinel trial work, which data sources are free, and the budget alerts that keep the labs at zero cost.
The people, processes and technology of a SOC, and why each matters before you touch Sentinel.
The mission of a SOC, in-house versus outsourced models, and the business risks a SOC exists to reduce.
Tier 1 to Tier 3 analysts, threat hunters and detection engineers, and how AI agents are changing who does what.
How a raw event becomes an alert, an incident and a closed case, with the decisions made at each stage.
The incident response phases in NIST SP 800-61 Revision 3 and the SANS model, and how they map to Sentinel features.
The numbers SOC leaders track, why alert fatigue happens, and how tuning and automation improve the figures.
Learn threat intelligence operationalization through ATT&CK, TTPs, and threat actors. Master the Pyramid of Pain, intelligence sources (OSINT, MDTI, STIX/TAXII), and intelligence-driven defense strate
The difference between a threat, a vulnerability and a risk, and why behaviour-based detections hurt attackers more than hash lists.
Nation-state, financially motivated and hacktivist groups, and how Microsoft's naming families help you read threat reports.
How ATT&CK describes attacker behaviour, with a real intrusion broken down tactic by tactic.
Open-source feeds, Microsoft's own intelligence, and the STIX and TAXII standards that move indicators into Sentinel.
The Azure and Entra ID building blocks every Sentinel deployment depends on.
The Azure hierarchy, where a Sentinel workspace lives, and why region choice matters for data residency.
Who secures what in IaaS, PaaS and SaaS, and how Defender for Cloud measures posture and raises workload alerts.
Users, groups, sign-in and audit logs, Identity Protection risk, and the identity signals Sentinel relies on.
Reader, Responder and Contributor roles, Defender unified RBAC, data lake permissions and row-level scoping.
How the Sentinel platform is built and the design decisions to make before deployment.
The four layers of today's Sentinel platform and how data flows from connectors to detections and AI tools.
What moves to security.microsoft.com, what the March 31, 2027 retirement means, and how onboarding works.
When one workspace is enough, when to split, and how primary and secondary workspaces behave in the Defender portal.
How Sentinel is billed, which tier suits which data, and a worked cost estimate for a mid-size company.
Deploy your first production-ready Sentinel environment step-by-step in your free Azure account. Create resource group named "SentinelRG", create Log Analytics Workspace named "SentinelWorkspace" in chosen region, enable Microsoft Sentinel on workspace (takes 2-3 minutes). Access Sentinel in Defender Portal at security.microsoft.com (replaces standalone Azure portal Sentinel blade), navigate to Overview showing current incidents/data volume/rule counts/coverage statistics. Install Microsoft Sentinel Training Lab solution from Content Hub providing pre-populated sample data/analytics rules/workbooks/incidents for safe practice before live data arrives. Configure Entra ID diagnostic settings: navigate to Microsoft Entra ID → Diagnostic settings → add new setting named "SentinelEntraLogs", select AuditLogs/SignInLogs/NonInteractiveUserSignInLogs/ServicePrincipalSignInLogs, send to Log Analytics workspace, data flows within 15-30 minutes. Connect Microsoft Entra ID data connector: navigate to Data connectors → search Entra ID → configure to ingest all three log types. Verify ingestion by running KQL query: SigninLogs | take 10, confirms Entra ID authentication telemetry flowing. Set workspace retention to 90 days (free tier sufficient for lab), enable Sentinel Health monitoring providing alerts if connectors stop ingesting. Document everything: note workspace ID, tenant ID, verify all services connected, confirm you can see sample data in Logs blade. This lab establishes foundation for all subsequent labs—everything builds on this baseline Sentinel environment that you'll use to practice detection rules, playbooks, investigations, and advanced operations.
Getting the right data into Sentinel, at the right cost, is the foundation of every detection.
How connectors are packaged in Content Hub solutions, the main connector types, and how to pick sources by detection value.
Connecting Microsoft sources, which ones are free, and collecting Azure activity logs with Azure Policy and diagnostic settings.
Transition your Sentinel environment from initial deployment to live security monitoring. Connect Azure Activity logs using Azure Policy assignment wizard: policy auto-configures diagnostic settings across all resources, logs begin flowing within 15-30 minutes, validate with query: AzureActivity | take 10. Connect Microsoft 365 Defender connector aggregating Endpoint/Identity/Office/Cloud Apps alerts: unified feed brings all Defender product signals into single queue, verify with query: SecurityAlert | where TimeGenerated > ago(1d). Validate Entra ID sign-in log quality by projecting key fields: verify UserPrincipalName contains real accounts, IPAddress shows actual IPs, Location shows city/country, ResultType shows success/failure codes. Understand validation goes beyond confirming data arrives—verify schema field population, check for unexpected null/empty patterns, confirm data freshness (recent timestamps not days old). Run Usage table analysis: Usage | where TimeGenerated > ago(7d) | summarise TotalGB = sum(Quantity)/1000 by DataType | sort by TotalGB desc shows ingestion volume by table, identifies which connectors are most active. Connect Office 365 connector bringing Exchange/SharePoint/Teams audit logs: enables phishing email detection, suspicious file access, Teams meeting recording misuse detection. Write cross-source correlation query demonstrating Sentinel's power: find users with >5 failed logins in 24 hours, then show their Azure management activity detecting if compromised credentials used for infrastructure attacks. Build connector health dashboard query: Setup monitoring alerts firing if any critical connector stops ingesting, prevents silent blind spots. By end of this lab you have multi-source data pipeline flowing, validated data quality, confirmed ingestion freshness, and baseline for measuring health—foundation for all downstream detection engineering.
Collecting Windows Security events with the Azure Monitor Agent, choosing event sets, writing DCRs and planning WEF.
The log forwarder pattern, Syslog versus CEF, and collecting firewall and appliance logs with AMA.
Creating custom tables, sending data with the Logs Ingestion API, and why the HTTP Data Collector API is retired.
Moving tables between tiers, setting retention, and cutting noise with ingestion-time transformations.
How detections turn data into incidents and how analysts work those incidents.
The rule types that remain, what happens to Fusion and Microsoft security rules in the Defender portal, and when to use each.
Why Microsoft now recommends custom detections, how they compare with analytics rules, and how to create one.
Writing the rule query, mapping entities, surfacing custom details, and grouping alerts into incidents.
Build your first custom analytics rule from scratch establishing complete detection engineering workflow. Create scheduled analytics rule named "Suspicious Sign-In from Multiple Countries" with clear description explaining detection logic. Write KQL query: SigninLogs | where TimeGenerated > ago(1h) | summarise CountriesCount = dcount(Location), Countries = make_set(Location) by UserPrincipalName | where CountriesCount > 2 (detects users authenticating from >2 countries within one hour indicating credential sharing or compromise). Review query results confirming it returns expected data, note that in lab environment with limited activity may return empty results (expected). Configure alert enrichment adding custom details: include Countries list in alert providing immediate investigative context. Add entity mapping: UserPrincipalName to Account entity (connects incident to user's full history), IPAddress to IP entity (links to threat intelligence and other activity). Set query scheduling: run every 1 hour, lookback data from last 1 hour. Set alert threshold: generate alert when query results > 0 (meaningful since query itself already filters to suspicious activity). Configure event grouping: group all events into single alert per hour (prevents 10 alerts for 10 users in same hour creating queue noise). Enable incident creation: check "Create incidents from alerts", enable grouping by entity (Account), 1-hour grouping window. Deploy rule to production. Navigate to Analytics confirming rule appears in Active list with enabled status. First run occurs within minutes of deployment. Test rule by reviewing any generated incidents, open incident investigation page seeing incident title/severity/affected entities/alert count/MITRE ATT&CK techniques. Click "Investigate" to open investigation graph visualizing entity relationships. Use entity pages exploring full history of affected users. Add analyst notes documenting your assessment. Change incident status to Active. This lab transitions you from consuming Sentinel to building it—every detection rule, playbook, and configuration change you make going forward follows this same pattern you've now practiced end-to-end.
Triage in the unified queue, reading the attack story and entity pages, and managing cases end to end.
Reducing false positives, acting on SOC optimization recommendations, and measuring detection coverage.
The query language behind every detection, hunt and workbook in Sentinel.
The pipe model and the core operators, written against real sign-in and security event tables.
Correlating events across tables, reusing logic with let, and working with dynamic JSON fields.
Which table holds which evidence, and how Sentinel and Defender XDR tables meet in advanced hunting.
Running hunting queries, saving evidence as bookmarks, and organising a hunt from hypothesis to findings with Hunts.
Write five progressively complex threat hunting queries building real investigative capability.
Query 1: Brute Force Detection: SigninLogs | where TimeGenerated > ago(1d) | where ResultType != 0 | summarise FailedAttempts = count(), UniqueIPs = dcount(IPAddress) by UserPrincipalName, bin(TimeGenerated, 1h) | where FailedAttempts > 20 | order by FailedAttempts desc. Identify users with >20 failed logins per hour distinguishing distributed attacks (many IPs) from targeted (single IP).
Query 2: Impossible Travel: SigninLogs | where TimeGenerated > ago(1d) | where ResultType == 0 | project TimeGenerated, UserPrincipalName, IPAddress, Location | order by UserPrincipalName, TimeGenerated | serialize | extend PrevLocation = prev(Location), PrevTime = prev(TimeGenerated), PrevUser = prev(UserPrincipalName) | where PrevUser == UserPrincipalName | extend TimeDiff = datetime_diff('minute', TimeGenerated, PrevTime) | where TimeDiff < 60. Find users authenticating from two countries within one hour indicating compromise/credential sharing.
Query 3: After-Hours Admin Activity: AzureActivity | where TimeGenerated > ago(7d) | where ActivityStatusValue == "Success" | extend HourOfDay = hourofday(TimeGenerated) | where HourOfDay < 7 or HourOfDay > 19 | where OperationNameValue contains "write" or OperationNameValue contains "delete" | summarise count by Caller, OperationNameValue. Detect administrative changes outside business hours suggesting insider threat/compromised credentials.
Query 4: New Admin Accounts: AuditLogs | where TimeGenerated > ago(7d) | where OperationName == "Add member to role" | extend TargetUser = tostring(TargetResources[0].displayName), Role = tostring(TargetResources[0].modifiedProperties[0].newValue) | where Role contains "Admin" | project TimeGenerated, InitiatedBy, TargetUser, Role. Find new privileged account creation outside approved provisioning—high-fidelity persistence indicator.
Query 5: Data Exfiltration Patterns: OfficeActivity | where TimeGenerated > ago(7d) | where Operation == "FileDownloaded" or Operation == "FileSyncDownloadedFull" | summarise DownloadCount = count(), UniqueFiles = dcount(SourceFileName) by UserId, bin(TimeGenerated, 1d) | where DownloadCount > 100 | order by DownloadCount desc. Detect users downloading unusual file volumes suggesting data staging before exfiltration. For each significant finding save a Bookmark: select suspicious rows, click "Add Bookmark", give descriptive title, add investigation notes, select MITRE ATT&CK techniques. Create a Hunting Session: name it "Investigation of [Topic]", describe hypothesis, set relevant tactics. After accumulating bookmarks, promote the most significant to formal Incidents, triggering full SOC investigation workflow. This lab teaches the complete threat hunting lifecycle: form hypothesis → write query → find evidence → bookmark findings → escalate to incident.
How automation turns detections into consistent, fast responses.
How automation rules run on incidents and alerts, and how to use them for assignment, tagging and suppression.
Building playbooks, authenticating with managed identity, and granting Sentinel the rights to run them.
Build your first production-grade automation playbook integrating Sentinel incidents with external systems. Create Logic App with incident trigger: navigate to Automation → Playbooks → Create → select "Playbook with incident trigger", name it "Notify-Incident-Email". Enable system-assigned Managed Identity on Logic App: go to Azure portal → Identity → System Assigned → On, note Object ID. Assign RBAC role to Managed Identity: Sentinel workspace → Access Control (IAM) → Add role assignment → select Microsoft Sentinel Automation Contributor → assign to Notify-Incident-Email Managed Identity. Add email action to playbook: search Office 365 Outlook → Send email V2, configure To field with your email, Subject field with dynamic content incident title (click lightning bolt selecting Incident Title), Body field with incident severity/status/alerts/description from dynamic content. Add Sentinel comment action: search Microsoft Sentinel → Add comment to incident V3, map Incident ARM ID from trigger, comment message = "Automated notification email sent to SOC team on [timestamp]". Save playbook. Test playbook by creating test incident setting severity to High, confirm email received within 60 seconds, verify incident comment added. Create automation rule triggering the playbook: navigate to Automation → Automation rules → Create → name "Auto-Notify-MediumPlus-Incidents", condition: Incident severity ≥ Medium, action: Run playbook → select Notify-Incident-Email. Every new high-severity incident now automatically sends email notification and documents action in incident notes. Review Logic Apps run history showing execution log of every playbook run: click failed runs to see specific error messages enabling rapid troubleshooting. Explore Natural Language Playbook Generator: describe what you want playbook to do in English ("When High severity incident created, post message to Teams channel with incident details and direct link"), Copilot generates working Logic App workflow with documentation. This lab demonstrates complete automation workflow: design response action → build playbook → test thoroughly → integrate with automation rule → validate end-to-end → document for team.
Design Sentinel workbooks for SOC dashboards and compliance reporting. Configure UEBA, investigate anomalies, build AI-powered detection rules powered by machine learning.
Master Sentinel Workbooks as visual intelligence for SOC leadership and analyst operations. Understand Workbooks as interactive dashboards powered by KQL queries visualizing security data: not static screenshots but live data refreshing automatically. Master Workbook components: Metric tiles displaying single numbers (open incidents, closed incidents, mean response time), Line charts showing trends over time, Bar charts comparing volumes across categories, Pie charts showing proportions, Maps visualizing geographic data, Grids displaying tabular query results with sortable columns, Text blocks for documentation. Learn parameter concept: time-range picker (1 hour / 1 day / 1 week / 30 days), severity selector (High / Medium / Low), analyst selector filtering by owner, tactic selector filtering by MITRE tactic. Build Workbook for different audiences: SOC Operations (daily analyst use) showing open incident queue, incident trends, analyst workload, connector health at a glance; Management Summary (weekly leadership) showing incident closure rate, top threat categories, mean time to respond, data connector status; Compliance Audit (regulatory review) showing access control changes, user activity, retention periods, indicator coverage. Master conditional formatting making status immediately obvious: green indicator = connector healthy, yellow = degraded, red = offline enabling 5-second scan vs reading detailed metrics. Deploy Workbooks from Content Hub: 80+ built-in templates covering common data sources, customize by modifying queries/parameters/layout. Design principles: one metric per tile capturing complete thought at a glance, color coding for instant recognition, parameters enabling self-service filtering, clear titles explaining what each visualization represents. Create custom Workbook: start from blank, add metric tile querying SecurityIncident where Status == "Active" (shows open incidents), add line chart showing incident trend over past month binned by day, add grid showing active incidents with columns for severity/owner/created date, add time range parameter filtering all queries. Share Workbook: save to shared workspace making accessible to entire team, export as ARM template for version control, pin specific tiles to Azure Dashboard for at-a-glance visibility without opening full Workbook. Measure Workbook adoption: when team stops asking "how many open incidents?" because Workbook answers it at a glance, adoption is working. Update Workbooks as organization evolves: add new metrics as they become important, remove stale metrics as they stop providing value, adjust drill-down depth based on user feedback.
Master User and Entity Behavior Analytics as AI-powered detection complementing signature-based rules. Understand UEBA fundamental principle: all users/entities have normal behavioral patterns, deviations from personal baseline indicate anomaly/compromise even when individual actions appear innocent. Learn UEBA builds behavioral baselines across four dimensions: User behaviors (what hours they sign in, from which locations, to which applications, data access volumes), Device/Host behaviors (typical network connections, process execution patterns, file access), IP Address behaviors (historical users/devices from that location, expected geographic context), Application behaviors (typical user/behavior patterns for that application). Master baseline construction: UEBA analyzes 14 days of historical data understanding normal behavior, then continuously scores current actions against established baseline. Understand Investigation Priority Score combining multiple anomaly signals: high score indicates user warrants investigation priority, dynamically updates as new signals arrive. Learn UEBA detection examples: user signing in from country they've never accessed from, user downloading unusually large data volume, user accessing file share they've never accessed, user making administrative changes at 3 AM (if normal hours are 9-5), user authenticating from multiple countries within physically impossible timeframe. Master UEBA Behaviors Layer (GA 2025) synthesizing raw anomaly events: instead of presenting individual anomalous log entries, Behaviors Layer summarizes as human-readable text—"This user performed 10 successful authentications to resources they've never accessed before in this location", "This user's download volume is 15x their baseline today". Understand UEBA integration with incident investigation: entity pages show Investigation Priority Score prominently, UEBA Observations tab shows specific behavioral anomalies detected, timeline shows when anomalies occurred. Learn UEBA for insider threat detection: malicious insiders with legitimate access generate anomalous patterns (mass file downloads before resignation, access to systems outside their role), negligent insiders create anomalies through poor security practices, compromised insiders show authentication/access pattern deviations. Master UEBA false positives: legitimate travel generates impossible travel alerts (manage via travel exemptions), system migrations generate access anomalies (temporary exclusions), legitimate projects create access pattern changes (baseline adjustment). Understand UEBA role in Zero Trust verification: continuous verification of user/entity behavior ensuring deviations trigger investigation even though individual actions might pass signature checks.
Enable User and Entity Behavior Analytics and conduct simulated insider threat investigation. Enable UEBA in Sentinel: navigate to Configuration → Entity Behavior → toggle User and Entity Behavior Analytics to Enabled, select Entra ID and Defender for Endpoint as data sources, click Apply (begins building baselines immediately). Understanding baseline building: meaningful anomaly data requires 7-14 days accumulation in production environments, lab environment has pre-staged behavioral data enabling immediate practice. Navigate to Entity Behavior → Users viewing user list ranked by Investigation Priority Score. Click highest-scoring user opening entity page showing 360-degree view: Investigation Priority Score at top with sparkline showing score history, active incidents/alerts associated with user, location anomaly card showing this user signed in from country they've never accessed from (baseline shows 90% UK activity, today from Singapore), access anomaly card showing access to sensitive file shares they've never accessed, time anomaly card showing activities at 3 AM when baseline shows 9-5 business hours. Query BehaviorAnalytics table: BehaviorAnalytics | where TimeGenerated > ago(7d) | where ActivityInsights has any ("Anomalous") | sort by InvestigationPriority descending | project TimeGenerated, UserPrincipalName, ActivityType, ActivityInsights, InvestigationPriority (see raw anomaly data). Create UEBA-powered analytics rule: new scheduled rule "High Priority UEBA Anomaly", query BehaviorAnalytics with filter InvestigationPriority > 500, set severity High, run every 4 hours, enable incident creation, save rule. When rule fires create test incident, investigate using entity page and investigation graph, see full behavioral context. Add watchlist of privileged admins (5 test accounts), modify analytics rule to fire only when anomalous user is privileged admin (using _GetWatchlist function joining watchlist), rule now targets highest-risk users. Build UEBA Summary Workbook: metric tile showing count of users with Investigation Priority > 500, bar chart showing anomaly counts by ActivityType, grid showing top 10 highest-priority users with Investigation Priority/ActivityInsights columns, add time-range parameter. Run simulated insider threat scenario: testuser@lab.local downloaded 500 MB from SharePoint in 2-hour window outside business hours following unusual IP sign-in, review BehaviorAnalytics for this user seeing multiple anomaly flags, Investigation Priority should exceed 700 (critical category). Document findings: this user shows classic insider threat pattern (off-hours access, unusual location, mass data download), would recommend manager contact, account monitoring, forensic investigation.
Build three production-quality Workbooks serving different stakeholder needs. Workbook 1: SOC Operations Dashboard for daily analyst use. Create new Workbook, add time range parameter defaulting to last 24 hours, add metric tile showing Open Incidents (SecurityIncident where Status == "Active" | count), add metric tile showing New Incidents in selected time range, add metric tile showing Mean Time to Respond calculated from CreatedTime vs CloseTime for closed incidents. Add line chart binning incidents by hour, colored by severity showing whether incident volume rising/falling and if composition shifting toward more serious alerts. Add stacked bar chart grouping by MITRE tactic showing which attack patterns most active this week (use top 5 tactics + Other category for readability). Add grid showing analyst workload: SecurityIncident grouped by Owner with columns for open incident count, closed count this period, average response time, sorted by open count descending showing overloaded analysts in red (>20 open). Save as "SOC Operations Dashboard", share with team. Workbook 2: Management Summary Workbook for weekly leadership. New Workbook defaulting to 7-day time range. Add metric tiles for Total Incidents, Closed Incidents, Closure Rate percentage. Add line chart showing 4-week trend putting current week in historical context. Add table showing top 5 threat actors/attack categories detected this week with incident count. Add connector health summary with green/yellow/red status for each data source. Keep layout clean—leaders scan dashboards, they don't read them. Workbook 3: Compliance Audit Dashboard for ISO 27001/SOC 2. Structure around five control areas. Access Monitoring: query AuditLogs for RoleManagement operations showing role assignment changes with actor/target/role/timestamp, SigninLogs for privileged admin sign-in events. Anomaly Detection: summarise count of UEBA anomalies by type, show Investigation Priority score distribution. Incident Response: SecurityIncident metrics showing creation/assignment/closure timelines. Data Retention: query workspace configuration confirming retention periods meet policy. Threat Intelligence: show active indicator count, last 7-day match count, coverage by indicator type. Export Workbooks as ARM templates: Workbook editor → Edit → Advanced Editor → copy JSON → save as "workbook-name.json" in Git repository for infrastructure-as-code deployment. Pin important tiles to Azure Dashboard for wall-screen monitoring. This lab produces three complete Workbooks you can deploy to any Sentinel workspace via ARM template.
This course contains the use of artificial intelligence: the narration voice and some slides and practice scenarios are AI-assisted.
Microsoft Sentinel Mastery 2026 teaches Microsoft Sentinel in the unified Microsoft Defender portal, where security teams run it today. The Sentinel experience in the Azure portal retires on March 31, 2027, so every lab in this course is built in the Defender portal.
2026 platform features covered
Security Copilot for AI-assisted investigation and natural language KQL
AI playbook generator for SOAR automation
UEBA behaviors layer for readable behaviour summaries
Sentinel data lake for low-cost long-term security telemetry
Unified SIEM and XDR incident management in one portal
10 hands-on labs
Nine labs run on the Azure free account and the 31-day Microsoft Sentinel trial. The Security Copilot lab needs Copilot access, which comes with Microsoft 365 E5 or with paid security compute units; you can also follow it by watching.
Lab 1: Deploy Microsoft Sentinel in the Defender portal
Lab 2: Connect data sources and validate ingestion
Lab 3: Create detection rules and investigate incidents
Lab 4: Advanced KQL threat hunting with bookmarks
Lab 5: Build and test automation playbooks
Lab 6: Configure UEBA and investigate behavioural anomalies
Lab 7: Design workbooks and compliance dashboards
Lab 8: Security Copilot investigation and AI automation
Lab 9: Threat intelligence integration and MITRE ATT&CK coverage
Lab 10: Build a Sentinel GitOps repository with CI/CD
SC-200 exam alignment
The course maps to the SC-200 skills outline effective October 21, 2026: manage a security operations environment (40-45%), respond to security incidents (35-40%) and perform threat hunting (20-25%). A final section reviews the exam, and two full practice exams help you check your readiness.
Skills you build
Architecture and deployment: deploy Sentinel in the Defender portal, plan Log Analytics workspaces, set up RBAC and plan retention across the analytics and data lake tiers.
Data ingestion: configure the Azure Monitor Agent and data collection rules, and connect Entra ID, Defender XDR, Microsoft 365 and third-party sources.
KQL: write Kusto Query Language queries for detection, hunting, cross-table joins and performance.
Threat detection: build scheduled, near-real-time and anomaly analytics rules mapped to MITRE ATT&CK.
Incident investigation: work the unified incident queue with entity pages, the investigation graph, UEBA insights and Security Copilot summaries.
SOAR automation: create automation rules and Logic App playbooks, including AI-generated playbooks, for notification and response.
Enterprise operations: manage many workspaces and tenants with Azure Lighthouse, deploy Sentinel as code with ARM, Bicep and Terraform, and support a Zero Trust programme.
Who should enrol
IT administrators moving into cybersecurity
SOC analysts (Tier 1-3) who want Sentinel skills and the SC-200 certification
Security engineers building detection and automation
MSSP analysts managing several customer environments
Anyone preparing for SC-200
Do I need Azure experience? Basic Azure knowledge helps but is not required; the course covers the foundations you need.
About the instructor
Your instructor works in cloud platform engineering with a focus on governance, security, risk and FinOps, with more than 18 years on enterprise Azure and multi-cloud platforms. The course is updated as Microsoft changes the platform.