logo
Live instructor-led learningLearn with an experienced trainer and ask questions in real time.
Flexible delivery optionsChoose scheduled virtual or classroom dates that work for your team.
Onsite for three or moreAsk about a private delivery tailored to your organisation.
Course information

Microsoft Security course content

View course overview
Upcoming classes

Choose a country and city to view dates

Course content

What you will learn

Overview

Get started with Microsoft Sentinel security operations by configuring the Microsoft Sentinel workspace, connecting Microsoft services and Windows security events to Microsoft Sentinel, configuring Microsoft Sentinel analytics rules, and responding to threats with automated responses.

. Explore more Microsoft training here

Audience

IT professionals, system administrators, developers, analysts, architects and technical specialists responsible for implementing or supporting the technology covered in this course.

Skills Gained

By completing the Configure SIEM Security Operations Using Microsoft Sentinel - Applied Skills Workshop MSC5001 course participants will gain practical knowledge, configuration skills, implementation techniques and best practice understanding relevant to real enterprise environments.

Prerequisites

  • Fundamental understanding of Microsoft security, compliance, and identity products
  • Intermediate understanding of Microsoft Windows
  • Familiarity with Azure services, specifically Azure Virtual Machines
  • Familiarity with Azure virtual machines and virtual networking
  • Basic understanding of scripting concepts

Outline

Module 1: Create and manage Microsoft Sentinel workspaces

Learn about the architecture of Microsoft Sentinel workspaces to ensure you configure your system to meet your organization's security operations requirements.

  • Introduction
  • Plan for the Microsoft Sentinel workspace
  • Create a Microsoft Sentinel workspace
  • Manage workspaces across tenants using Azure Lighthouse
  • Understand Microsoft Sentinel permissions and roles
  • Manage Microsoft Sentinel settings
  • Configure logs
  • Knowledge check
  • Summary and resources

Module 2: Connect Microsoft services to Microsoft Sentinel

Learn how to connect Microsoft 365 and Azure service logs to Microsoft Sentinel.

  • Introduction
  • Plan for Microsoft services connectors
  • Connect the Microsoft Office 365 connector
  • Connect the Microsoft Entra connector
  • Connect the Microsoft Entra ID Protection connector
  • Connect the Azure Activity connector
  • Knowledge check
  • Summary and resources

Module 3: Connect Windows hosts to Microsoft Sentinel

One of the most common logs to collect is Windows security events. Learn how Microsoft Sentinel makes this easy with the Security Events connector.

  • Introduction
  • Plan for Windows hosts security events connector
  • Connect using the Windows Security Events via AMA Connector
  • Connect using the Security Events via Legacy Agent Connector
  • Collect Sysmon event logs
  • Knowledge check
  • Summary and resources

Module 4: Threat detection with Microsoft Sentinel analytics

In this module, you learned how Microsoft Sentinel Analytics can help the SecOps team identify and stop cyber attacks.

  • Introduction
  • Exercise - Detect threats with Microsoft Sentinel analytics
  • What is Microsoft Sentinel Analytics?
  • Types of analytics rules
  • Create an analytics rule from templates
  • Create an analytics rule from wizard
  • Manage analytics rules
  • Exercise - Detect threats with Microsoft Sentinel analytics
  • Summary

Module 5: Automation in Microsoft Sentinel

By the end of this module, you'll be able to use automation rules in Microsoft Sentinel to automated incident management.

  • Introduction
  • Understand automation options
  • Create automation rules
  • Knowledge check
  • Summary and resources

Module 6: Configure SIEM security operations using Microsoft Sentinel

In this module, you learned how to configure SIEM security operations using Microsoft Sentinel.

  • Introduction
  • Exercise - Configure SIEM operations using Microsoft Sentinel
  • Exercise - Install Microsoft Sentinel Content Hub solutions and data connectors
  • Exercise - Configure a data connector Data Collection Rule
  • Exercise - Perform a simulated attack to validate the Analytic and Automation rules
  • Summary
. Explore more Microsoft training here

Certification

Please note: Your applied skills assessment practical lab can be sat at any time of your choosing directly via the MSLearn website here.

Is Configure SIEM Security Operations Using Microsoft Sentinel - Applied Skills Workshop MSC5001 right for me?

This course is for learners who want structured, expert-led training in cybersecurity with practical workplace outcomes.

What will I learn on Configure SIEM Security Operations Using Microsoft Sentinel - Applied Skills Workshop MSC5001?

You will build practical cybersecurity skills, understand key concepts and apply the course outcomes in real workplace scenarios.

Does Configure SIEM Security Operations Using Microsoft Sentinel - Applied Skills Workshop MSC5001 include exam preparation?

Exam availability depends on the selected delivery option; check the course details before booking.

What should I do after Configure SIEM Security Operations Using Microsoft Sentinel - Applied Skills Workshop MSC5001?

Compare related CourseMonster courses and follow-on pathways to choose the best next step for your role or team.

Talk to an expert

Thinking about Onsite?

If you need training for 3 or more people, you should ask us about onsite training. Putting aside the obvious location benefit, content can be customised to better meet your business objectives and more can be covered than in a public classroom. Its a cost effective option. One on one training can be delivered too, at reasonable rates.

Submit an enquiry from any page on this site and let us know you are interested in the requirements box, or simply mention it when we contact you.

All $ prices are in USD unless it’s a NZ or AU date

SPVC = Self Paced Virtual Class

LVC = Live Virtual Class

Please Note: All courses are availaible as Live Virtual Classes

Trusted by over 1/2 million students in 15 countries

Our clients have included prestigious national organisations such as Oxford University Press, multi-national private corporations such as JP Morgan and HSBC, as well as public sector institutions such as the Department of Defence and the Department of Health.