Choose your language
Sentinel Training
Over 400,000 professionals on the platform
Exclusive for businesses

Sentinel Training

Master Microsoft Sentinel from the ground up and gain the hands-on skills to protect enterprise environments using a cloud-native SIEM/SOAR platform. This training covers everything from data ingestion and KQL querying to automated response and threat hunting. Whether you are breaking into security operations or levelling up your SOC career, this course delivers the practical depth you need.

Dedika for students

What your team will master:

You will learn how to configure data connectors, write advanced KQL queries, and build analytics rules that generate high-fidelity security incidents. The course covers incident triage, investigation workflows, and evidence collection inside the Sentinel portal. You will automate response actions using Logic Apps playbooks and integrate threat intelligence feeds for proactive detection. Advanced topics include threat hunting methodologies, Jupyter notebooks, compliance reporting, and multi-workspace governance. By the end, you will have the skills to operate and manage Microsoft Sentinel in a production SOC environment.

How your team learns in practice Sentinel Training

How your team practises Sentinel Training

Professionals from these companies study at Dedika

ActemiumFR
Nunner LogisticsNL
GT Constructora GeotécnicaCR
Sydel StarBR
Metrô de São PauloBR
Aguas AndinasCL
DSMIN
MeridianbetRS
CDHCN

Course content

8 Chapters • 38 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Introduction to Microsoft Sentinel

  • Lesson 1 • Sentinel Workspace Architecture

    Covers Log Analytics workspace structure, resource groups, and tenant relationships. Connects workspace design decisions to data retention and cost outcomes.

  • Lesson 2 • Cloud-Native SIEM Fundamentals

    Defines SIEM and SOAR concepts and explains how Sentinel differs from on-premises solutions. Establishes the conceptual baseline for all subsequent platform work.

  • Lesson 3 • Navigating the Sentinel Portal

    Guides learners through the Azure portal interface, Sentinel menu structure, and key dashboards. Builds confidence for hands-on tasks in later chapters.

  • Lesson 4 • Licensing and Cost Management

    Explains pricing tiers, commitment levels, and data ingestion cost drivers. Enables learners to make informed decisions about workspace configuration.

Chapter 2See details

Data Connectors and Ingestion

  • Lesson 1 • Connector Troubleshooting and Validation

    Provides systematic methods for diagnosing missing data, agent failures, and connector errors. Reinforces reliability practices essential for production deployments.

  • Lesson 2 • Connecting Microsoft Security Services

    Walks through enabling connectors for Microsoft 365 Defender, Entra ID, and Azure services. Demonstrates how native integrations reduce configuration complexity.

  • Lesson 3 • Syslog and CEF Ingestion

    Covers agent-based log forwarding using Syslog and Common Event Format protocols. Connects Linux and network device log sources to the Sentinel workspace.

  • Lesson 4 • Data Connector Ecosystem Overview

    Surveys built-in, partner, and custom connector categories and their ingestion methods. Provides context for selecting the right connector type for each data source.

  • Lesson 5 • REST API and Custom Log Ingestion

    Explains the Data Collection Rule framework and HTTP Data Collector API for custom sources. Enables ingestion of proprietary or unsupported log formats.

Chapter 3See details

KQL Querying for Security Analysis

  • Lesson 1 • Query Optimisation and Best Practices

    Addresses query performance, cost reduction, and readability standards for team environments. Prepares learners to write scalable queries used in scheduled analytics rules.

  • Lesson 2 • Functions, Parsers, and Watchlists

    Teaches saved functions, ASIM parsers, and watchlist integration for reusable query logic. Reduces duplication and standardises detection across the workspace.

  • Lesson 3 • KQL Syntax and Core Operators

    Introduces tabular expression syntax, pipe operators, and basic filtering commands. Provides the grammar foundation required for all subsequent query work.

  • Lesson 4 • Joins, Unions, and Correlations

    Covers join kinds, union statements, and time-window correlations across multiple tables. Enables multi-source threat detection logic essential for analytics rules.

  • Lesson 5 • Working with Security Log Tables

    Explores key Sentinel tables such as SecurityEvent, SigninLogs, and CommonSecurityLog. Teaches learners to identify relevant fields for security use cases.

Chapter 4See details

Analytics Rules and Threat Detection

  • Lesson 1 • Rule Tuning and False Positive Reduction

    Covers threshold adjustment, allowlisting, and watchlist-based exclusions to improve signal quality. Directly reduces analyst alert fatigue in production environments.

  • Lesson 2 • Analytics Rule Types and Use Cases

    Compares scheduled, near-real-time, fusion, ML behavioural, and Microsoft Security rule types. Establishes selection criteria for matching rule type to detection requirements.

  • Lesson 3 • Creating Scheduled Analytics Rules

    Walks through the full rule creation wizard including query, entity mapping, and alert grouping. Produces rules that generate actionable, well-structured incidents.

  • Lesson 4 • Content Hub and Rule Templates

    Demonstrates deploying detection content from the Content Hub and customising rule templates. Accelerates detection coverage using community and vendor-provided logic.

  • Lesson 5 • MITRE ATT&CK Alignment

    Explains how to tag rules with MITRE ATT&CK tactics and techniques for coverage mapping. Enables gap analysis and prioritisation of detection engineering efforts.

Chapter 5See details

Incident Management and Investigation

  • Lesson 1 • Bookmarks and Evidence Collection

    Teaches creating query bookmarks to preserve evidence and annotate findings during investigations. Supports audit trails and handoff documentation for incident response teams.

  • Lesson 2 • Incident Investigation Graph

    Covers the investigation graph for visualising entity relationships and attack timelines. Connects alert evidence to broader attack patterns for faster root-cause analysis.

  • Lesson 3 • Incident Closure and Documentation

    Covers classification, closure reasons, and post-incident comment standards for quality records. Ensures consistent data for metrics, trend analysis, and compliance reporting.

  • Lesson 4 • Incident Queue and Triage Workflow

    Explains incident severity, status fields, and queue filtering for efficient triage. Establishes a repeatable intake process that scales with alert volume.

  • Lesson 5 • Entity Pages and Enrichment

    Explores user, host, IP, and URL entity pages for contextual enrichment during investigations. Reduces manual lookups by surfacing behavioural baselines and threat intelligence.

Chapter 6See details

Automation with Playbooks and SOAR

  • Lesson 1 • Logic Apps and Playbook Architecture

    Explains Azure Logic Apps structure, connectors, and triggers used to build Sentinel playbooks. Provides the technical foundation for designing multi-step response workflows.

  • Lesson 2 • Playbook Testing and Governance

    Covers run history review, error handling, and access control for production playbooks. Ensures automation reliability and prevents unauthorised or unintended actions.

  • Lesson 3 • SOAR Concepts and Automation Rules

    Introduces SOAR principles and Sentinel automation rules for lightweight, no-code response logic. Establishes the automation layer before introducing full playbook complexity.

  • Lesson 4 • Building Common Response Playbooks

    Guides learners through building playbooks for user disablement, IP blocking, and ticket creation. Translates theoretical SOAR concepts into deployable, tested automation.

  • Lesson 5 • Advanced Automation Patterns

    Explores enrichment loops, watchlist updates, and cross-workspace automation for complex scenarios. Extends learner capability beyond basic response into proactive defence workflows.

Chapter 7See details

Threat Intelligence Integration

  • Lesson 1 • Threat Intelligence Workbook and Management

    Explores the built-in TI workbook for visualising indicator coverage, staleness, and source health. Supports ongoing TI programme governance and feed quality assessment.

  • Lesson 2 • Threat Intelligence Fundamentals

    Defines indicator types, confidence scoring, and the intelligence lifecycle relevant to SIEM operations. Grounds learners in TI concepts before platform-specific configuration.

  • Lesson 3 • TI-Based Analytics Rules

    Teaches building detection rules that match log data against imported indicators in real time. Directly converts threat intelligence into operational detections within the workspace.

  • Lesson 4 • Importing Indicators into Sentinel

    Covers TAXII feed configuration, Microsoft TI connector, and API-based indicator import methods. Enables automated, continuous population of the ThreatIntelligenceIndicator table.

Chapter 8See details

Advanced Hunting and Threat Detection

  • Lesson 1 • Hunt-to-Detection Pipeline

    Teaches converting validated hunt queries into scheduled analytics rules and updating playbooks. Closes the loop between proactive hunting and automated, ongoing detection.

  • Lesson 2 • Notebooks and Advanced Analytics

    Introduces Jupyter notebooks integrated with Sentinel for ML-assisted hunting and data science workflows. Enables advanced analysts to apply statistical methods to security data.

  • Lesson 3 • Sentinel Hunting Queries and Bookmarks

    Covers the Hunting blade, built-in query library, and bookmark workflow for capturing findings. Connects hunting activity directly to incident creation and evidence preservation.

  • Lesson 4 • Threat Hunting Methodology

    Introduces hypothesis-driven hunting, the hunting maturity model, and hunt planning frameworks. Establishes a structured approach that distinguishes hunting from reactive investigation.

  • Lesson 5 • Livestream and Anomaly Detection

    Explains the Livestream feature for real-time query monitoring and built-in anomaly detection rules. Extends hunting capability into continuous, low-latency threat monitoring.

Certification

Your valid completion certificate

This course is for you:

  • IT administrators: ready to specialise in cloud security monitoring and detection.

  • Junior SOC analysts: wanting structured depth behind the tools they use daily.

  • Network engineers: transitioning into security operations roles within Azure environments.

  • Cybersecurity students: building job-ready skills before entering their first analyst position.

  • System administrators: moving from infrastructure management towards threat detection responsibilities.

  • Career changers: entering cybersecurity from adjacent IT fields with foundational technical backgrounds.

Related Courses

FAQ

Who is Dedika?

Is the certificate valid in Australia?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course