
Explore Microsoft Sentinel's architecture, setup, and governance, including Log Analytics workspace, RBAC, cost management, and MITRE ATT&CK integration, with hands-on tasks and practical how-to guidance.
Discover prerequisites for deploying Microsoft Sentinel, including an Azure tenant and subscription, a Log Analytics workspace, data sources and connectors, budgeting, and a resource group with roles and permissions.
Plan and apply Azure role-based access control roles for Microsoft Sentinel using built-in and custom roles, scoped at the resource group to cover the Sentinel workspace and Log Analytics.
Explore how to estimate and manage costs for Microsoft Sentinel using the pricing calculator, pay-as-you-go and commitment pricing, and cost management tools, including data ingestion, retention, and budgeting.
Explore the content hub in Microsoft Sentinel, discover out-of-the-box content from Microsoft and third-party vendors, and deploy workbooks, analytics rules, and playbooks to fast-track security operations.
Learn to connect your threat intelligence platform to Microsoft Sentinel using the Graph Security API, including Azure AD app registration, permissions, and the data connector workflow.
Explore how to create custom analytics rules in Microsoft Sentinel to detect threats and drive incident response. Learn to use templates, scheduled and near real-time rules, and automated responses.
Learn how to work with anomaly detection analytics rules in Microsoft Sentinel by using templates, duplicating to customize, and evaluating anomalies with logs and queries.
Enable UEBA in Microsoft Sentinel by turning it on, selecting data sources, and using the built-in workbook to visualize risky user behavior and anomalous activity.
Configure multistage attack detection fusion rules in Microsoft Sentinel to correlate anomalous behavior across sessions using a fusion engine powered by machine learning and the MITRE ATT&CK framework.
The Microsoft Sentinel Skills Course is a comprehensive training program designed to provide learners with the knowledge and skills needed to effectively use Microsoft Sentinel, a cloud-native Security Information and Event Management (SIEM) system. The course is intended for security professionals, IT administrators, and anyone responsible for monitoring and responding to security incidents in an organization.
The course begins with an introduction to Sentinel and its key features, followed by a deep dive into the Sentinel data model, query language, and analytics capabilities. Learners will also learn how to use Sentinel to detect and respond to security threats, configure data connectors, and automate incident response workflows.
Other topics covered in the course include threat hunting, incident investigation, creating custom alerts and workbooks, and managing Sentinel at scale. The course also covers best practices for configuring and managing Sentinel in a production environment.
Throughout the course, learners will have access to hands-on labs and exercises designed to reinforce the concepts covered in the lectures. Upon completion of the course, learners will be well-equipped to use Microsoft Sentinel to monitor and protect their organization's digital assets.
The Microsoft Sentinel Skills Course is intended for security professionals, IT administrators, and anyone responsible for monitoring and responding to security incidents in an organization. The course is ideal for individuals who want to gain a deep understanding of Microsoft Sentinel, a cloud-native Security Information and Event Management (SIEM) system, and learn how to use it effectively to monitor and protect their organization's digital assets.