Opleiding: Planning and implementing Microsoft Sentinel (SIEM & SOAR) [M55610A]

OVERVIEW

This 3 day hands on course helps you get ramped up with Microsoft Sentinel and provide hands-on practical experience for product features, capabilities, and scenarios.

During the course you will deploy a Microsoft Sentinel workspace and ingest pre-recorded data to simulate scenarios that showcase various Microsoft Sentinel features.

 

Updated July 2026

 

OBJECTIVES

This course covers the following topics:

  • Overview of Microsoft Sentinel
  • KQL
  • Data Connectors
  • Analytics Rules
  • Incident Management
  • Hunting
  • Watchlists
  • Threat Intelligence

AUDIENCE

This course is aimed at IT professionals and Azure administrators that have some experience administering and configuring Azure, but want to gain an insight into implementing Microsoft’s SIEM/SOAR solution, Microsoft Sentinel.

CERTIFICATION

None

NEXT STEP

None

CONTENT

Module 1: Overview of Microsoft Sentinel

  • Overview of Microsoft Sentinel
  • Data ingestion methods
  • Microsoft Sentinel for MSSPs
  • User and Entity Behaviour Analytics
  • Fusion
  • Notebooks
  • Management & Automation Tools
  • Logs & Costs

Module 2: KQL

  • Importance of KQL across Azure
  • The User Interface (demo)
  • The standard KQL Structure
  • Common KQL Commands

Module 3: Data Connectors

  • Manage content in Microsoft Sentinel
  • Connect data to Microsoft Sentinel using data connectors
  • Connect Microsoft services to Microsoft Sentinel
  • Connect Microsoft 365 Defender to Microsoft Sentinel
  • Connect Windows hosts to Microsoft Sentinel
  • Connect Common Event Format logs to Microsoft Sentinel
  • Connect syslog data sources to Microsoft Sentinel
  • Connect threat indicators to Microsoft Sentinel

Module 4 – Analytics Rules

  • Threat detection with Microsoft Sentinel analytics
  • Automation in Microsoft Sentinel
  • Threat response with Microsoft Sentinel playbooks

Module 5 – Incident Management

  • Incident management Overview
  • User and Entity Behaviour Analytics
  • Data normalization in Microsoft Sentinel
  • Query, visualize, and monitor data

Module 6 – Hunting

  • Threat hunting concepts
  • Threat hunting with Microsoft Sentinel
  • Use Search jobs in Microsoft Sentinel
  • Hunt for threats using notebooks

Module 7 – Watchlists

  • Prioritize incidents
  • Import business data
  • Reduce Alert Fatigue
  • Enrich Event Data

Module 8 – Threat Intelligence

  • Threat Intelligence Overview
  • Threat Intelligence in Microsoft Sentinel
Meer...
€1.995
ex. BTW
Aangeboden door
Global Knowledge Network Netherlands B.V.
Onderwerp
SIEM
Niveau
Looptijd
3 dagen
Taal
nl
Type product
cursus
Lesvorm
Klassikaal
Aantal deelnemers
Max: 16
Tijdstip
Overdag
Tijden en locaties
Nieuwegein (Iepenhoeve 5)
ma 7 dec. 2026
VIRTUAL TRAINING CENTRE
ma 7 dec. 2026
VIRTUAL TRAINING CENTER
ma 10 mei 2027
VIRTUAL TRAINING CENTRE
ma 28 jun. 2027
Zoetermeer (Kinderen v Versteegplein 18)
ma 28 jun. 2027
VIRTUAL TRAINING CENTER
ma 15 nov. 2027
Nieuwegein (Iepenhoeve 5)
ma 20 dec. 2027
VIRTUAL TRAINING CENTRE
ma 20 dec. 2027
Keurmerken aanbieder
Cedeo
CRKBO en BTW-vrijstelling
VOI
EXIN
ISO register
Microsoft Learning Partner
VMWare Partner
Oracle Education Partner
AgilePM - Agile Project Management (APMG)
ASL