
Sentinel Training
Master Microsoft Sentinel from the ground up and gain the hands-on skills to protect enterprise environments using a cloud-native SIEM/SOAR platform. This training covers everything from data ingestion and KQL querying to automated response and threat hunting. Whether you are breaking into security operations or levelling up your SOC career, this course delivers the practical depth you need.
What you will learn:
You will learn how to configure data connectors, write advanced KQL queries, and build analytics rules that generate high-fidelity security incidents. The course covers incident triage, investigation workflows, and evidence collection inside the Sentinel portal. You will automate response actions using Logic Apps playbooks and integrate threat intelligence feeds for proactive detection. Advanced topics include threat hunting methodologies, Jupyter notebooks, compliance reporting, and multi-workspace governance. By the end, you will have the skills to operate and manage Microsoft Sentinel in a production SOC environment.
How you study in practice Sentinel Training
How you practise Sentinel Training
For businesses looking to train their team
With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.
Course content
8 Chapters • 38 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsIntroduction to Microsoft Sentinel
Introduction to Microsoft Sentinel
Lesson 1 • Sentinel Workspace Architecture
Covers Log Analytics workspace structure, resource groups, and tenant relationships. Connects workspace design decisions to data retention and cost outcomes.
Lesson 2 • Cloud-Native SIEM Fundamentals
Defines SIEM and SOAR concepts and explains how Sentinel differs from on-premises solutions. Establishes the conceptual baseline for all subsequent platform work.
Lesson 3 • Navigating the Sentinel Portal
Guides learners through the Azure portal interface, Sentinel menu structure, and key dashboards. Builds confidence for hands-on tasks in later chapters.
Lesson 4 • Licensing and Cost Management
Explains pricing tiers, commitment levels, and data ingestion cost drivers. Enables learners to make informed decisions about workspace configuration.
Chapter 2HideHide detailsSee detailsData Connectors and Ingestion
Data Connectors and Ingestion
Lesson 1 • Connector Troubleshooting and Validation
Provides systematic methods for diagnosing missing data, agent failures, and connector errors. Reinforces reliability practices essential for production deployments.
Lesson 2 • Connecting Microsoft Security Services
Walks through enabling connectors for Microsoft 365 Defender, Entra ID, and Azure services. Demonstrates how native integrations reduce configuration complexity.
Lesson 3 • Syslog and CEF Ingestion
Covers agent-based log forwarding using Syslog and Common Event Format protocols. Connects Linux and network device log sources to the Sentinel workspace.
Lesson 4 • Data Connector Ecosystem Overview
Surveys built-in, partner, and custom connector categories and their ingestion methods. Provides context for selecting the right connector type for each data source.
Lesson 5 • REST API and Custom Log Ingestion
Explains the Data Collection Rule framework and HTTP Data Collector API for custom sources. Enables ingestion of proprietary or unsupported log formats.
Chapter 3HideHide detailsSee detailsKQL Querying for Security Analysis
KQL Querying for Security Analysis
Lesson 1 • Query Optimisation and Best Practices
Addresses query performance, cost reduction, and readability standards for team environments. Prepares learners to write scalable queries used in scheduled analytics rules.
Lesson 2 • Functions, Parsers, and Watchlists
Teaches saved functions, ASIM parsers, and watchlist integration for reusable query logic. Reduces duplication and standardises detection across the workspace.
Lesson 3 • KQL Syntax and Core Operators
Introduces tabular expression syntax, pipe operators, and basic filtering commands. Provides the grammar foundation required for all subsequent query work.
Lesson 4 • Joins, Unions, and Correlations
Covers join kinds, union statements, and time-window correlations across multiple tables. Enables multi-source threat detection logic essential for analytics rules.
Lesson 5 • Working with Security Log Tables
Explores key Sentinel tables such as SecurityEvent, SigninLogs, and CommonSecurityLog. Teaches learners to identify relevant fields for security use cases.
Chapter 4HideHide detailsSee detailsAnalytics Rules and Threat Detection
Analytics Rules and Threat Detection
Lesson 1 • Rule Tuning and False Positive Reduction
Covers threshold adjustment, allowlisting, and watchlist-based exclusions to improve signal quality. Directly reduces analyst alert fatigue in production environments.
Lesson 2 • Analytics Rule Types and Use Cases
Compares scheduled, near-real-time, fusion, ML behavioural, and Microsoft Security rule types. Establishes selection criteria for matching rule type to detection requirements.
Lesson 3 • Creating Scheduled Analytics Rules
Walks through the full rule creation wizard including query, entity mapping, and alert grouping. Produces rules that generate actionable, well-structured incidents.
Lesson 4 • Content Hub and Rule Templates
Demonstrates deploying detection content from the Content Hub and customising rule templates. Accelerates detection coverage using community and vendor-provided logic.
Lesson 5 • MITRE ATT&CK Alignment
Explains how to tag rules with MITRE ATT&CK tactics and techniques for coverage mapping. Enables gap analysis and prioritisation of detection engineering efforts.
Chapter 5HideHide detailsSee detailsIncident Management and Investigation
Incident Management and Investigation
Lesson 1 • Bookmarks and Evidence Collection
Teaches creating query bookmarks to preserve evidence and annotate findings during investigations. Supports audit trails and handoff documentation for incident response teams.
Lesson 2 • Incident Investigation Graph
Covers the investigation graph for visualising entity relationships and attack timelines. Connects alert evidence to broader attack patterns for faster root-cause analysis.
Lesson 3 • Incident Closure and Documentation
Covers classification, closure reasons, and post-incident comment standards for quality records. Ensures consistent data for metrics, trend analysis, and compliance reporting.
Lesson 4 • Incident Queue and Triage Workflow
Explains incident severity, status fields, and queue filtering for efficient triage. Establishes a repeatable intake process that scales with alert volume.
Lesson 5 • Entity Pages and Enrichment
Explores user, host, IP, and URL entity pages for contextual enrichment during investigations. Reduces manual lookups by surfacing behavioural baselines and threat intelligence.
Chapter 6HideHide detailsSee detailsAutomation with Playbooks and SOAR
Automation with Playbooks and SOAR
Lesson 1 • Logic Apps and Playbook Architecture
Explains Azure Logic Apps structure, connectors, and triggers used to build Sentinel playbooks. Provides the technical foundation for designing multi-step response workflows.
Lesson 2 • Playbook Testing and Governance
Covers run history review, error handling, and access control for production playbooks. Ensures automation reliability and prevents unauthorised or unintended actions.
Lesson 3 • SOAR Concepts and Automation Rules
Introduces SOAR principles and Sentinel automation rules for lightweight, no-code response logic. Establishes the automation layer before introducing full playbook complexity.
Lesson 4 • Building Common Response Playbooks
Guides learners through building playbooks for user disablement, IP blocking, and ticket creation. Translates theoretical SOAR concepts into deployable, tested automation.
Lesson 5 • Advanced Automation Patterns
Explores enrichment loops, watchlist updates, and cross-workspace automation for complex scenarios. Extends learner capability beyond basic response into proactive defence workflows.
Chapter 7HideHide detailsSee detailsThreat Intelligence Integration
Threat Intelligence Integration
Lesson 1 • Threat Intelligence Workbook and Management
Explores the built-in TI workbook for visualising indicator coverage, staleness, and source health. Supports ongoing TI programme governance and feed quality assessment.
Lesson 2 • Threat Intelligence Fundamentals
Defines indicator types, confidence scoring, and the intelligence lifecycle relevant to SIEM operations. Grounds learners in TI concepts before platform-specific configuration.
Lesson 3 • TI-Based Analytics Rules
Teaches building detection rules that match log data against imported indicators in real time. Directly converts threat intelligence into operational detections within the workspace.
Lesson 4 • Importing Indicators into Sentinel
Covers TAXII feed configuration, Microsoft TI connector, and API-based indicator import methods. Enables automated, continuous population of the ThreatIntelligenceIndicator table.
Chapter 8HideHide detailsSee detailsAdvanced Hunting and Threat Detection
Advanced Hunting and Threat Detection
Lesson 1 • Hunt-to-Detection Pipeline
Teaches converting validated hunt queries into scheduled analytics rules and updating playbooks. Closes the loop between proactive hunting and automated, ongoing detection.
Lesson 2 • Notebooks and Advanced Analytics
Introduces Jupyter notebooks integrated with Sentinel for ML-assisted hunting and data science workflows. Enables advanced analysts to apply statistical methods to security data.
Lesson 3 • Sentinel Hunting Queries and Bookmarks
Covers the Hunting blade, built-in query library, and bookmark workflow for capturing findings. Connects hunting activity directly to incident creation and evidence preservation.
Lesson 4 • Threat Hunting Methodology
Introduces hypothesis-driven hunting, the hunting maturity model, and hunt planning frameworks. Establishes a structured approach that distinguishes hunting from reactive investigation.
Lesson 5 • Livestream and Anomaly Detection
Explains the Livestream feature for real-time query monitoring and built-in anomaly detection rules. Extends hunting capability into continuous, low-latency threat monitoring.
Your valid completion certificate
This course is for you:
IT administrators: ready to specialise in cloud security monitoring and detection.
Junior SOC analysts: wanting structured depth behind the tools they use daily.
Network engineers: transitioning into security operations roles within Azure environments.
Cybersecurity students: building job-ready skills before entering their first analyst position.
System administrators: moving from infrastructure management towards threat detection responsibilities.
Career changers: entering cybersecurity from adjacent IT fields with foundational technical backgrounds.
What our students say
Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast and simple to use. The diversity of content and complementary videos really help with learning.

Top qualifications
FAQ
Who is Dedika?
Is the certificate valid in the United Kingdom?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















