Skip to content

sc-200Associate

Microsoft Security Operations Analyst

Microsoft Certified: Security Operations Analyst Associate

SC-200 is the operator's exam: what each Defender surfaces, how incidents correlate in XDR, KQL for hunting, and Sentinel for the rest. The path front-loads the product explainers, then hunting, then the response runbooks the exam's scenarios are built on.

For: SOC analysts and security admins who triage, hunt, and respond with Defender XDR and Sentinel.

25 guides in 4sections. The sections are this site's grouping, written to follow the shape of the published skills outline; weightings and the current outline live on the exam page above and change between exam versions.

01Mitigate threats with Defender XDR

  1. 1Which Microsoft Defender is whichWhich Microsoft Defender is which: Endpoint, Office 365, Identity, Cloud Apps, Business, XDR, Cloud, Antivirus — what each does and which licence gets it.
  2. 2Defender XDR and attack-surface managementHow Microsoft Defender XDR unifies Defender for Office, Endpoint, Identity, and Cloud Apps into a single SOC workflow.
  3. 3Microsoft Defender for Endpoint explainedDefender for Endpoint is Microsoft's EDR/XDR platform for laptops, servers, and mobile. Here's what it does.
  4. 4Defender Vulnerability ManagementHow Defender for Endpoint's vulnerability management surfaces CVEs, misconfigurations, and prioritises remediation.
  5. 5Microsoft Defender Antivirus configurationHow to configure Microsoft Defender Antivirus for Windows endpoints — the settings that matter and how to manage them.
  6. 6Microsoft Defender for Office 365 explainedWhat Defender for Office 365 adds on top of EOP — Safe Links, Safe Attachments, AIR, attack simulation — plus Plan 1 vs Plan 2 and the settings worth tuning.
  7. 7Investigating a phishing message that got past defencesRunbook for a phish that landed: find every copy, purge it from mailboxes, find who clicked, submit it so filters learn, and work out why it got through.
  8. 8Defender for Office 365 quarantine workflowHow users and admins work with quarantine — release, request, report, and the policy decisions behind it.
  9. 9Microsoft Defender for Identity explainedDefender for Identity detects identity-based attacks against on-prem Active Directory and Entra ID. Here's how it works.
  10. 10Microsoft Defender for Identity sensor deploymentHow to plan and roll out Defender for Identity sensors — DCs, AD FS, Entra Connect, and tuning.
  11. 11Microsoft Defender for Cloud Apps explainedDefender for Cloud Apps is Microsoft's CASB — discovering, monitoring, and controlling SaaS app usage.
  12. 12Defender Attack DisruptionAutomatic Attack Disruption is Defender XDR's ability to contain in-progress attacks automatically — what it does and how.
  13. 13Defender Threat IntelligenceHow Microsoft Defender XDR integrates threat intelligence — built-in feeds, custom IoCs, and Defender TI as a separate product.

02Hunt with KQL

  1. 14KQL primer for Defender XDRA practical introduction to Kusto Query Language for Microsoft Defender XDR and Sentinel hunting.
  2. 15Defender XDR advanced hunting workshopHow to use Defender XDR advanced hunting effectively — tables, common queries, and threat-hunting patterns.

03Mitigate threats with Sentinel

  1. 16Microsoft Sentinel for Microsoft 365How Microsoft Sentinel ingests Microsoft 365 signals and extends Defender XDR into a full SIEM.
  2. 17Microsoft Sentinel onboardingHow to onboard Microsoft Sentinel — workspace setup, data connectors, and starting analytic rules.
  3. 18Microsoft Sentinel analytic rulesHow analytic rules work in Sentinel — types, tuning, and writing custom detections.
  4. 19Microsoft Sentinel cost optimisationHow to control Microsoft Sentinel costs — ingestion tuning, commitment tiers, retention, and data tiering.
  5. 20Microsoft Security CopilotMicrosoft's AI assistant for security analysts — what it does, where it's embedded, and how it's licensed.

04Respond

  1. 21Microsoft 365 incident response runbookA structured incident response runbook for Microsoft 365 — detection, triage, containment, eradication, recovery, lessons.
  2. 22Compromised Microsoft 365 account response runbookCompromised Microsoft 365 account runbook: what to run in the first fifteen minutes, what to check in the first hour, and when it is safe to hand it back.
  3. 23How to block a compromised account in Microsoft 365How-toHow to block a compromised Microsoft 365 account in ten minutes: disable sign-in, revoke sessions, reset password and MFA, kill inbox rules and forwarding.
  4. 24Business Email Compromise response playbookHow to respond to a confirmed BEC incident in Microsoft 365 — containment, investigation, remediation, and prevention.
  5. 25Ransomware preparedness for Microsoft 365How to harden a Microsoft 365 tenant against ransomware — prevention, detection, response, and recovery.

Independent site, not affiliated with Microsoft. Found a gap in this path? Send it through the contact form.