
Sentinel Training Course
Master Microsoft Sentinel from the ground up and gain the hands-on skills to protect enterprise environments using a cloud-native SIEM/SOAR platform. This training covers everything from data ingestion and KQL querying to automated emergency response and threat hunting. Whether you are breaking into security operations or advancing your SOC career, this course delivers the practical depth you need.
What your team will master:
You will learn how to configure data connectors, write advanced KQL queries, and build analytics rules that generate high-fidelity security incidents. The course covers incident triage, preliminary inquiry workflows, and evidence collection inside the Sentinel portal. You will automate response actions using Logic Apps playbooks and integrate threat intelligence feeds for proactive detection. Advanced topics include threat hunting methodologies, Jupyter notebooks, compliance reporting, and multi-workspace governance. By the end, you will have the skills to operate and manage Microsoft Sentinel in a production SOC environment.
How your team learns practically Sentinel Training Course
How your team practises Sentinel Training Course
Professionals from these companies study at Dedika









Course content
8 Chapters • 38 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsIntroduction to Microsoft Sentinel
Introduction to Microsoft Sentinel
Lesson 1 • Sentinel Workspace Architecture
Covers Log Analytics workspace structure, resource groups, and tenant relationships. Connects workspace design decisions to data retention and cost outcomes.
Lesson 2 • Cloud-Native SIEM Fundamentals
Defines SIEM and SOAR concepts and explains how Sentinel differs from on-premises solutions. Establishes the conceptual baseline for all subsequent platform work.
Lesson 3 • Navigating the Sentinel Portal
Guides learners through the Azure portal interface, Sentinel menu structure, and key dashboards. Builds confidence for hands-on tasks in later chapters.
Lesson 4 • Licensing and Cost Management
Explains pricing tiers, commitment levels, and data ingestion cost drivers. Enables learners to make informed decisions about workspace configuration.
Chapter 2HideHide detailsSee detailsData Connectors and Ingestion
Data Connectors and Ingestion
Lesson 1 • Connector Troubleshooting and Validation
Provides systematic methods for diagnosing missing data, agent failures, and connector errors. Reinforces reliability practices essential for production deployments.
Lesson 2 • Connecting Microsoft Security Services
Walks through enabling connectors for Microsoft 365 Defender, Entra ID, and Azure services. Demonstrates how native integrations reduce configuration complexity.
Lesson 3 • Syslog and CEF Ingestion
Covers agent-based log forwarding using Syslog and Common Event Format protocols. Connects Linux and network device log sources to the Sentinel workspace.
Lesson 4 • Data Connector Ecosystem Overview
Surveys built-in, partner, and custom connector categories and their ingestion methods. Provides context for selecting the right connector type for each data source.
Lesson 5 • REST API and Custom Log Ingestion
Explains the Data Collection Rule framework and HTTP Data Collector API for custom sources. Enables ingestion of proprietary or unsupported log formats.
Chapter 3HideHide detailsSee detailsKQL Querying for Security Analysis
KQL Querying for Security Analysis
Lesson 1 • Query Optimization and Best Practices
Addresses query performance, cost reduction, and readability standards for team environments. Prepares learners to write scalable queries used in scheduled analytics rules.
Lesson 2 • Functions, Parsers, and Watchlists
Teaches saved functions, ASIM parsers, and watchlist integration for reusable query logic. Reduces duplication and standardizes detection across the workspace.
Lesson 3 • KQL Syntax and Core Operators
Introduces tabular expression syntax, pipe operators, and basic filtering commands. Provides the grammar foundation required for all subsequent query work.
Lesson 4 • Joins, Unions, and Correlations
Covers join kinds, union statements, and time-window correlations across multiple tables. Enables multi-source threat detection logic essential for analytics rules.
Lesson 5 • Working with Security Log Tables
Explores key Sentinel tables such as SecurityEvent, SigninLogs, and CommonSecurityLog. Teaches learners to identify relevant fields for security use cases.
Chapter 4HideHide detailsSee detailsAnalytics Rules and Threat Detection
Analytics Rules and Threat Detection
Lesson 1 • Rule Tuning and False Positive Reduction
Covers threshold adjustment, allowlisting, and watchlist-based exclusions to improve signal quality. Directly reduces analyst alert fatigue in production environments.
Lesson 2 • Analytics Rule Types and Use Cases
Compares scheduled, near-real-time, fusion, ML behavioural, and Microsoft Security rule types. Establishes selection criteria for matching rule type to detection requirements.
Lesson 3 • Creating Scheduled Analytics Rules
Walks through the full rule creation wizard including query, entity mapping, and alert grouping. Produces rules that generate actionable, well-structured incidents.
Lesson 4 • Content Hub and Rule Templates
Demonstrates deploying detection content from the Content Hub and customizing rule templates. Accelerates detection coverage using community and vendor-provided logic.
Lesson 5 • MITRE ATT&CK Alignment
Explains how to tag rules with MITRE ATT&CK tactics and techniques for coverage mapping. Enables gap analysis and prioritization of detection engineering efforts.
Chapter 5HideHide detailsSee detailsIncident Management and Preliminary Inquiry
Incident Management and Preliminary Inquiry
Lesson 1 • Bookmarks and Evidence Collection
Teaches creating query bookmarks to preserve evidence and annotate findings during preliminary inquiries. Supports audit trails and handoff documentation for incident response teams.
Lesson 2 • Incident Preliminary Inquiry Graph
Covers the preliminary inquiry graph for visualizing entity relationships and attack timelines. Connects alert evidence to broader attack patterns for faster root-cause analysis.
Lesson 3 • Incident Closure and Documentation
Covers classification, closure reasons, and post-incident comment standards for quality records. Ensures consistent data for metrics, trend analysis, and compliance reporting.
Lesson 4 • Incident Queue and Triage Workflow
Explains incident severity, status fields, and queue filtering for efficient triage. Establishes a repeatable intake process that scales with alert volume.
Lesson 5 • Entity Pages and Enrichment
Explores user, host, IP, and URL entity pages for contextual enrichment during preliminary inquiries. Reduces manual lookups by surfacing behavioural baselines and threat intelligence.
Chapter 6HideHide detailsSee detailsAutomation with Playbooks and SOAR
Automation with Playbooks and SOAR
Lesson 1 • Logic Apps and Playbook Architecture
Explains Azure Logic Apps structure, connectors, and triggers used to build Sentinel playbooks. Provides the technical foundation for designing multi-step response workflows.
Lesson 2 • Playbook Testing and Governance
Covers run history review, error handling, and access control for production playbooks. Ensures automation reliability and prevents unauthorized or unintended actions.
Lesson 3 • SOAR Concepts and Automation Rules
Introduces SOAR principles and Sentinel automation rules for lightweight, no-code response logic. Establishes the automation layer before introducing full playbook complexity.
Lesson 4 • Building Common Response Playbooks
Guides learners through building playbooks for user disablement, IP blocking, and ticket creation. Translates theoretical SOAR concepts into deployable, tested automation.
Lesson 5 • Advanced Automation Patterns
Explores enrichment loops, watchlist updates, and cross-workspace automation for complex scenarios. Extends learner capability beyond basic response into proactive defense workflows.
Chapter 7HideHide detailsSee detailsThreat Intelligence Integration
Threat Intelligence Integration
Lesson 1 • Threat Intelligence Workbook and Management
Explores the built-in TI workbook for visualizing indicator coverage, staleness, and source health. Supports ongoing TI programme governance and feed quality assessment.
Lesson 2 • Threat Intelligence Fundamentals
Defines indicator types, confidence scoring, and the intelligence lifecycle relevant to SIEM operations. Grounds learners in TI concepts before platform-specific configuration.
Lesson 3 • TI-Based Analytics Rules
Teaches building detection rules that match log data against imported indicators in real time. Directly converts threat intelligence into operational detections within the workspace.
Lesson 4 • Importing Indicators into Sentinel
Covers TAXII feed configuration, Microsoft TI connector, and API-based indicator import methods. Enables automated, continuous population of the ThreatIntelligenceIndicator table.
Chapter 8HideHide detailsSee detailsAdvanced Hunting and Threat Detection
Advanced Hunting and Threat Detection
Lesson 1 • Hunt-to-Detection Pipeline
Teaches converting validated hunt queries into scheduled analytics rules and updating playbooks. Closes the loop between proactive hunting and automated, ongoing detection.
Lesson 2 • Notebooks and Advanced Analytics
Introduces Jupyter notebooks integrated with Sentinel for ML-assisted hunting and data science workflows. Enables advanced analysts to apply statistical methods to security data.
Lesson 3 • Sentinel Hunting Queries and Bookmarks
Covers the Hunting blade, built-in query library, and bookmark workflow for capturing findings. Connects hunting activity directly to incident creation and evidence preservation.
Lesson 4 • Threat Hunting Methodology
Introduces hypothesis-driven hunting, the hunting maturity model, and hunt planning frameworks. Establishes a structured approach that distinguishes hunting from reactive preliminary inquiry.
Lesson 5 • Livestream and Anomaly Detection
Explains the Livestream feature for real-time query monitoring and built-in anomaly detection rules. Extends hunting capability into continuous, low-latency threat monitoring.
Your valid completion certificate
This course is for you:
IT administrators: ready to specialise in cloud security monitoring and detection.
Junior SOC analysts: wanting structured depth behind the tools they use daily.
Network engineers: transitioning into security operations roles within Azure environments.
Cybersecurity students: building job-ready skills before entering their first analyst position.
System administrators: moving from infrastructure management toward threat detection responsibilities.
Career changers: entering cybersecurity from adjacent IT fields with foundational technical backgrounds.
Related Courses
FAQs
Who is Dedika?
Is the certificate valid in Pakistan?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course



















