Choose your language
Microsoft Security Training
More than 2 million students worldwide

Microsoft Security Training

Master the full Microsoft security stack — from identity and endpoints to cloud workloads and compliance. This training covers Defender, Sentinel, Purview, and Entra ID in depth, giving you the hands-on skills to protect modern enterprise environments. Build the expertise that security teams and hiring managers are actively looking for.

Dedika for businesses

What you will learn:

You will learn how to deploy and operate Microsoft's core security products across identity, endpoint, cloud, and data protection domains. The course covers Zero Trust architecture, Microsoft Entra ID, Defender for Endpoint, Defender for Cloud, Microsoft Sentinel, and Microsoft Purview. You will write KQL queries for threat hunting, build automated playbooks, and configure compliance frameworks. Advanced modules address AI-assisted investigations with Microsoft Security Copilot and proactive threat hunting methodology. By the end, you will be equipped to lead security operations and respond to complex attacks in Microsoft environments.

How you study in practice Microsoft Security Training

How you practice Microsoft Security Training

For companies looking to train their teams

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course Content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Microsoft Security Ecosystem Foundations

  • Lesson 1 • Licensing and Deployment Models

    Explains Microsoft security licensing tiers and deployment options. Enables informed decisions about feature availability and rollout strategy.

  • Lesson 2 • Microsoft Security Portfolio Overview

    Introduces the full range of Microsoft security products and how they interrelate. Provides the mental model needed for all subsequent chapters.

  • Lesson 3 • Microsoft Security Architecture Pillars

    Covers identity, endpoints, data, apps, infrastructure, and network as security pillars. Connects each pillar to specific Microsoft tooling.

  • Lesson 4 • Threat Landscape and Attack Vectors

    Surveys modern adversary tactics, techniques, and procedures relevant to Microsoft environments. Grounds product selection in real threat scenarios.

  • Lesson 5 • Zero Trust Security Model

    Defines Zero Trust principles and Microsoft's implementation approach. Anchors all product decisions to a unified security philosophy.

Chapter 2See details

Identity and Access Management with Entra ID

  • Lesson 1 • Identity Protection and Risk Policies

    Configures user risk and sign-in risk policies using machine-learning signals. Automates remediation for compromised identities.

  • Lesson 2 • Entra ID Core Concepts

    Covers tenants, directories, users, groups, and service principals. Establishes the identity objects that all access policies depend on.

  • Lesson 3 • Conditional Access Configuration

    Explains policy conditions, grant controls, and session controls for adaptive access. Implements context-aware enforcement across all sign-ins.

  • Lesson 4 • Privileged Identity Management

    Covers just-in-time privileged access, approval workflows, and access reviews. Minimizes standing privilege exposure in the tenant.

  • Lesson 5 • Authentication Methods and Policies

    Teaches password policies, passwordless options, and multi-factor authentication configuration. Directly reduces credential-based attack risk.

Chapter 3See details

Endpoint Security with Microsoft Defender

  • Lesson 1 • Vulnerability Management

    Uses Defender Vulnerability Management to prioritize and remediate software weaknesses. Connects exposure data to remediation workflows.

  • Lesson 2 • Defender for Endpoint Architecture

    Explains sensor deployment, data flow, and portal components. Provides the operational foundation for all endpoint security tasks.

  • Lesson 3 • Defender for Business and SMB Scenarios

    Addresses simplified Defender configurations for smaller organizations. Ensures security coverage scales across enterprise and SMB environments.

  • Lesson 4 • Attack Surface Reduction Rules

    Configures ASR rules to block common malware behaviors before execution. Directly limits the techniques attackers use against endpoints.

  • Lesson 5 • Endpoint Detection and Response

    Covers alert triage, device timeline analysis, and live response capabilities. Enables rapid investigation and containment of endpoint incidents.

Chapter 4See details

Cloud Security with Microsoft Defender for Cloud

  • Lesson 1 • Security Alerts and Threat Detection

    Analyzes Defender for Cloud alerts, suppression rules, and alert correlation. Enables accurate triage of cloud-native attack signals.

  • Lesson 2 • Defender for Cloud Fundamentals

    Introduces Secure Score, recommendations, and workload protection plans. Establishes the posture management baseline for cloud environments.

  • Lesson 3 • Cloud Security Posture Management

    Covers regulatory compliance dashboards, governance rules, and attack path analysis. Translates posture findings into prioritized remediation actions.

  • Lesson 4 • DevSecOps and Supply Chain Security

    Integrates Defender for Cloud into CI/CD pipelines and scans infrastructure-as-code. Shifts security left into the development lifecycle.

  • Lesson 5 • Workload Protection for Azure Services

    Configures protection plans for VMs, containers, databases, and storage. Extends threat detection to each Azure workload type.

Chapter 5See details

Information Protection and Data Security

  • Lesson 1 • Sensitivity Labels and Encryption

    Creates and publishes sensitivity labels with encryption, marking, and access controls. Labels enforce protection wherever labeled content travels.

  • Lesson 2 • Microsoft Purview Data Governance

    Covers data catalog, data map, and data estate insights for governance. Connects data discovery to protection and compliance workflows.

  • Lesson 3 • Sensitive Information Types and Classifiers

    Builds custom and built-in sensitive information types and trainable classifiers. Accurate classification underpins all downstream protection policies.

  • Lesson 4 • Insider Risk Management

    Configures insider risk policies to detect data theft, leakage, and sabotage signals. Balances user privacy with organizational data protection.

  • Lesson 5 • Data Loss Prevention Policies

    Configures DLP policies across Microsoft 365 workloads and endpoints. Prevents unauthorized sharing of sensitive data in real time.

Chapter 6See details

Security Operations with Microsoft Sentinel

  • Lesson 1 • SOAR Automation with Playbooks

    Builds Logic Apps-based playbooks for automated incident response actions. Reduces mean time to respond by automating repetitive SOC tasks.

  • Lesson 2 • Sentinel Architecture and Data Ingestion

    Covers workspace design, data connectors, and log ingestion cost management. Proper architecture ensures complete visibility without excessive cost.

  • Lesson 3 • Analytics Rules and Threat Detection

    Creates scheduled, near-real-time, and ML-based analytics rules. Translates threat intelligence into automated alert generation.

  • Lesson 4 • Incident Investigation and Hunting

    Uses the investigation graph, bookmarks, and hunting queries to analyze incidents. Builds structured investigation habits for SOC analysts.

  • Lesson 5 • KQL for Security Analysis

    Teaches Kusto Query Language for threat hunting and detection rule authoring. KQL proficiency is the core analytical skill in Sentinel.

Chapter 7See details

Compliance and Risk Management with Purview

  • Lesson 1 • Compliance Manager and Assessments

    Configures Compliance Manager assessments and tracks improvement actions. Provides a quantified compliance posture score for stakeholder reporting.

  • Lesson 2 • Audit Logging and Investigations

    Configures unified audit log search and advanced audit capabilities. Provides forensic evidence for compliance investigations and breach response.

  • Lesson 3 • eDiscovery and Legal Hold

    Manages Content Search, eDiscovery Standard, and Premium cases for legal requests. Preserves and exports data in a defensible, auditable manner.

  • Lesson 4 • Retention Policies and Labels

    Creates retention policies and labels to meet records management obligations. Ensures data is kept or deleted according to defined schedules.

  • Lesson 5 • Communication Compliance

    Sets up communication compliance policies to detect policy violations in messages. Addresses regulatory obligations for supervised communications.

Chapter 8See details

Advanced Threat Hunting and Incident Response

  • Lesson 1 • Incident Response Frameworks and Playbooks

    Applies structured IR frameworks to Microsoft environment incidents. Standardizes response actions to reduce decision fatigue under pressure.

  • Lesson 2 • Proactive Threat Hunting Methodology

    Establishes hypothesis-driven hunting using threat intelligence and behavioral analytics. Moves security posture from reactive to proactive detection.

  • Lesson 3 • Advanced Hunting in Microsoft 365 Defender

    Uses the unified advanced hunting schema across identity, endpoint, email, and cloud. Enables cross-domain correlation of attacker activity.

  • Lesson 4 • Responding to Identity and Cloud Attacks

    Covers response procedures for compromised accounts, token theft, and cloud resource abuse. Addresses the most prevalent attack patterns in Microsoft environments.

  • Lesson 5 • Post-Incident Recovery and Hardening

    Guides recovery from security incidents and translates findings into hardening actions. Closes the loop between incident response and security improvement.

Certification

Your valid completion certificate

This course is for you:

  • IT administrators: ready to specialize in Microsoft security tools and practices.

  • SOC analysts: looking to deepen their skills across the full Microsoft stack.

  • Cloud engineers: responsible for securing Azure workloads and hybrid environments.

  • Compliance officers: needing technical fluency to manage Microsoft 365 obligations.

  • Career changers: transitioning from general IT into a dedicated cybersecurity role.

  • Security consultants: expanding their Microsoft-specific expertise for enterprise clients.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the presentation style and video transcription, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQ

Who is Dedika?

Is the certificate valid in United States?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course