Cybersecurity 路 Free

Microsoft Sentinel and Defender: SC-200 Exam Prep

Preparation for Microsoft's SC-200 Security Operations Analyst exam, mapped to the skills measured as of 21 October 2026: KQL from first query to hunting, Microsoft Defender XDR incidents and attack disruption, Defender for Endpoint, Office 365, Identity and Cloud Apps, Purview investigations, Microsoft Sentinel setup, data connectors, analytics rules, automation, Security Copilot and threat hunting.

14 modules 17h 49m of video English 路 self-paced

Inside the course

Microsoft Sentinel and Defender: SC-200 Exam Prep: Syllabus at a glanceMicrosoft Sentinel and Defender: SC-200 Exam Prep: What you will be able to doMicrosoft Sentinel and Defender: SC-200 Exam Prep: Tools and credits

From the lessons

  • Course Preview | SC-200 | Microsoft Security Operations Analyst

    The SC-200 exam, the Defender portal and a safe lab

    Microsoft Learn

  • KQL Inner and Outer Joins for Advanced Hunting | Microsoft Defender (Part 2)

    KQL for investigations: let, join, union, parse and JSON

    Microsoft Security

  • Mitigate threats using Microsoft Defender for Endpoint | SC-200 | Episode 4

    Microsoft Defender for Endpoint: configure, investigate and respond

    Microsoft Learn

  • Mitigate threats using Microsoft Purview | SC-200 | Episode 3

    Microsoft Purview investigations and Defender for Cloud alerts

    Microsoft Learn

  • Connect logs to Microsoft Sentinel | SC-200 | Episode 8

    Getting data into Microsoft Sentinel

    Microsoft Learn

  • Creating Microsoft Sentinel automations and workbooks in Microsoft Defender

    Automation: automation rules, playbooks and case management

    Microsoft Security

Lesson frames belong to the creators named in the Credits below and are shown from YouTube.

What you will learn

Plan your SC-200 study against Microsoft's published outline; write KQL that filters, aggregates, joins and parses security data; work an incident in the Microsoft Defender portal and explain attack disruption; configure and respond with Defender for Endpoint; investigate email, identity and SaaS threats; search Purview Audit and eDiscovery; set up a Microsoft Sentinel workspace with the right roles, retention and data connectors; build analytics and custom detection rules mapped to MITRE ATT&CK; automate response with automation rules and playbooks; check Security Copilot output against evidence; and hunt with Advanced hunting, the data lake and notebooks.

  • Plan SC-200 study against the three skill areas and weights Microsoft publishes
  • Write KQL that filters by time, aggregates, joins tables and unpacks JSON for investigations
  • Work incidents in the Microsoft Defender portal and explain automatic attack disruption
  • Configure Defender for Endpoint device groups, ASR rules and response actions
  • Investigate phishing, compromised identities and risky OAuth apps across Office 365, Entra and Cloud Apps
  • Set up a Microsoft Sentinel workspace with least-privilege roles, sensible retention and filtered data connectors
  • Build analytics and custom detection rules mapped to MITRE ATT&CK, and automate response with approval gates
  • Hunt with Advanced hunting, the Sentinel data lake, KQL jobs and notebooks, and check Security Copilot output

For you

Taking Microsoft Sentinel and Defender: SC-200 Exam Prep from the United States

The course project 路 about 14 hours

A starter detection and response pack: Sentinel connectors, three rules, a gated playbook and one hunt in a lab

Stand up a small Microsoft Sentinel workspace in your own lab, collect Windows Security events with a filtered data collection rule, write three analytics rules mapped to MITRE ATT&CK, design an automation rule and a playbook with an approval step, run one hypothesis-led hunt, trigger harmless test activity, and write the incident report and runbook a real SOC would keep.

Sample document pack, 5 documents, filled in for the scenario

  • RegisterDetection register: starter rules
  • Test reportDetection test record: lab test activity
  • ProcedureTriage runbook: incidents in the Defender portal
  • ReportIncident report: brute force on labuser1
  • Risk registerRisk register: starter SOC pack

Read inside the course and download as a workbook. The project is optional practice, marked when you submit it; the certificate needs only the modules and the final assessment.

Course content

14 modules 路 64 lessons 路 17h 49m

In order, at whatever pace suits you. Each module ends with a practice task that builds on the last.

  1. 01The SC-200 exam, the Defender portal and a safe lab20m
  2. 02KQL fundamentals for security analysts1h 14m
  3. 03KQL for investigations: let, join, union, parse and JSON34m
  4. 04Microsoft Defender XDR: incidents, alerts and attack disruption1h 13m
  5. 05Microsoft Defender for Endpoint: configure, investigate and respond1h 12m
  6. 06Email, identity and SaaS threats: Office 365, Identity, Entra and Cloud Apps55m
  7. 07Microsoft Purview investigations and Defender for Cloud alerts1h 16m
  8. 08Microsoft Sentinel: workspace, roles, retention and workbooks1h 13m

Requirements

Who it is for
Intermediate. For SOC analysts, IT administrators and security graduates who know the basics of networks, Windows logs and incident response. SOC Analyst Level 1 with Splunk or Cybersecurity Fundamentals covers those basics if you need them.
Software
A browser and an Azure subscription you control: an Azure free account works for the Sentinel workspace, and a new workspace has a time-limited Microsoft Sentinel free trial (check the current terms on Microsoft Learn). Microsoft 365 E5 or Defender trial licences for the Defender XDR modules where available. KQL practice runs free on the Azure Data Explorer help cluster. What to download, and how
Hardware
A computer with a browser. A Windows virtual machine, local or in Azure, for the endpoint and log collection exercises.

Software you need

What to download, where from, what it costs and how to install it. Every link goes to the maker's own site, never a mirror.

Microsoft Sentinel and the Defender portal run in the browser; a new workspace has a time-limited Sentinel free trial, so check Microsoft's current terms and delete the lab resource group when you finish. Defender XDR modules need Microsoft 365 E5 or Defender trial licences where available. A Windows evaluation VM, in Azure or VirtualBox, is used for the endpoint and log collection exercises. KQL practice runs free at dataexplorer.azure.com on the help cluster.

Required

  1. 01

    Azure free account

    Microsoft, in the browser

    Free trial: 30 days of credit, some services free for 12 months
    Runs on
    Any modern web browser
    Account
    A Microsoft account, a phone number and a credit or debit card for identity checks

    New customers get credit to use within 30 days, free monthly amounts of 20+ popular services for 12 months, and 65+ always-free services. The card is only for identity checks: Microsoft does not charge it, though a temporary one-dollar (or equivalent) hold may appear. You are not charged unless you upgrade.

    Open Azure free accountazure.microsoft.com

    Alternatives

    • Azure for Students: Credit for 12 months with no credit card, for full-time university students using a school email. Renews each year while you are a student.

Optional

Useful, not needed to finish the course.

  1. 02

    Windows 11 Enterprise (evaluation)

    Microsoft

    Free trial: 90 days
    Runs on
    Installs as a virtual machine or on a PC; ISO for x64 and Arm64
    Account
    A short registration form on the Microsoft Evaluation Center

    A full-featured 90-day evaluation for testing, with no product key needed. When it expires the desktop turns black, a notice stays on screen and the PC shuts down every hour.

  2. 03

    Oracle VirtualBox

    Oracle

    Free
    Runs on
    Windows, macOS (Intel and Apple Silicon), Linux and Solaris hosts
    Account
    None needed

    The VirtualBox platform packages are free and open source under GPL version 3. The separate Extension Pack is free only for personal and educational use (PUEL licence); business use of the Extension Pack needs a commercial licence from Oracle.

Checked against each maker's own page on 27 September 2026. Trial lengths and editions change; the maker's page is the final word.

Microsoft Sentinel and Defender: SC-200 Exam Prep at a glance

Microsoft Sentinel and Defender: SC-200 Exam Prep is a free, self-paced online course from EDWartens for SOC analysts, IT administrators and security graduates preparing for Microsoft's SC-200 exam and working with Microsoft Sentinel and Defender XDR. It has 14 modules and 17h 49m of video lessons by Microsoft Learn, Microsoft Security, Microsoft Mechanics and others, with written notes and worked problems, a practical project with a document pack and a 15-question final assessment (pass mark 60%). Learning is free with an account; an optional certificate with a public verification code is issued when you pass. Last updated 27 September 2026.

All course facts
Price
Free, for good. No trial, no card. The only paid item is the optional certificate, a small one-off fee.
Who it is for
SOC analysts, IT administrators and security graduates preparing for Microsoft's SC-200 exam and working with Microsoft Sentinel and Defender XDR
Format
14 self-paced modules, 17h 49m of video, written notes, a practice task per module and one final assessment.
Level
Intermediate. Intermediate. For SOC analysts, IT administrators and security graduates who know the basics of networks, Windows logs and incident response. SOC Analyst Level 1 with Splunk or Cybersecurity Fundamentals covers those basics if you need them.
Brand
Microsoft
Software
A browser and an Azure subscription you control: an Azure free account works for the Sentinel workspace, and a new workspace has a time-limited Microsoft Sentinel free trial (check the current terms on Microsoft Learn). Microsoft 365 E5 or Defender trial licences for the Defender XDR modules where available. KQL practice runs free on the Azure Data Explorer help cluster.
Hardware
A computer with a browser. A Windows virtual machine, local or in Azure, for the endpoint and log collection exercises.
Certificate
Optional EDWartens Certificate of Completion, verifiable by code. Not a vendor credential.
Video lessons by
Microsoft Learn, Microsoft Security, Microsoft Mechanics, Microsoft Security Community, Cloud360 Training, Peter Rising, CyberPlatter, Christopher Nett (independent creators, credited below)
Language
English
Last updated
27 September 2026

A shareable EDWartens certificate

Finish every module and pass the final assessment, and the optional EDWartens certificate is yours. It carries a unique verification code on a public page anyone can check, so it stands up when a recruiter looks it up. See it below.

The course itself stays free whether or not you ever buy one.

Stuck? Ask a practising engineer

A free course usually means a comment section and hope. This one does not. Every module has an Ask-your-trainer panel that reaches the same engineers who teach our paid programme: people who commission panels for a living, not moderators.

Pairs well with

Microsoft 365 Copilot and Copilot Studio Agents free course coverFreeAI for professionals 路 FreeMicrosoft 365 Copilot and Copilot Studio AgentsUse Microsoft 365 Copilot well and build your first agent: what Copilot, Copilot Chat and Copilot Studio each are, how grounding works, Copilot in Word, Excel, Outlook and PowerPoint, prompting and saved prompts, the Researcher and Analyst agents, building and grounding an agent in Copilot Studio, and responsible use.OT Security Assessment: Testing a Plant Without Stopping It free course coverFreeCybersecurity 路 FreeOT Security Assessment: Testing a Plant Without Stopping ItThe assessment half of OT security, for engineers who have to do it on a plant that is running. Rules of engagement first, then passive capture, careful enumeration, what an attacker does with a protocol that has no authentication, the Windows machines nobody mentions, the logging that would have caught it, and a report written in the language of consequence.ICS Security Foundations: Control Systems, Defence in Depth and the 62443 Requirements free course coverFreeCybersecurity 路 FreeICS Security Foundations: Control Systems, Defence in Depth and the 62443 RequirementsThe ground floor of industrial cyber security, taught through the systems themselves: what a DCS, PLC, SCADA, BACS and safety system actually do, the Purdue model, why OT is not IT, how industrial attacks unfold, defence in depth and a layered architecture, then the seven ISA/IEC 62443 foundational requirements one at a time, asset registers, segmentation, discovery, IDS and IPS, secure remote access, SIEM and endpoint protection.OT and ICS Cybersecurity with ISA/IEC 62443 free course coverFreeCybersecurity 路 FreeOT and ICS Cybersecurity with ISA/IEC 62443Free OT security course for automation and IT staff: Purdue zones, ISA/IEC 62443 security levels, risk assessment. The certificate is optional and paid.

More free courses: Free cyber security courses

Learner reviews

No reviews yet

Reviews here are written only by learners who have finished every module of Microsoft Sentinel and Defender: SC-200 Exam Prep, and they are published exactly as written. Finish the course and yours will be the first.

Common questions

What is the SC-200 exam?

SC-200 is Microsoft's exam for the Microsoft Certified: Security Operations Analyst Associate certification. It tests managing a security operations environment (40-45%), responding to security incidents (35-40%) and threat hunting (20-25%) with Microsoft Defender XDR, Microsoft Sentinel and KQL, under the skills measured as of 21 October 2026. You book it with Microsoft through Pearson VUE, the fee is paid to Microsoft, and 700 is the pass mark.

Who is this SC-200 preparation course for?

It is for SOC analysts, IT administrators, cloud engineers and security graduates who work with, or want to work with, Microsoft's security stack. It suits anyone moving from a level 1 SOC role into Microsoft Sentinel and Defender XDR, and anyone preparing for the SC-200 exam.

Is the course free to learn?

Yes. Every module, the notes, the worked problems, the practice tasks, the optional project and the final assessment are free to learn. The labs use an Azure free account, the Microsoft Sentinel free trial on a new workspace and the free KQL help cluster; check Microsoft's current trial terms before you start and delete lab resources when you finish.

What do I need to know before I start?

You should know the basics of networks, Windows event logs and the incident response process. If those are new, take Cybersecurity Fundamentals or SOC Analyst Level 1 with Splunk first. No KQL experience is needed; two modules teach it from the first query.

How long does the SC-200 course take?

About 19 hours of video, notes and practice at your own pace, of which about 13.6 hours is video in the study modules. An optional 4-hour study cram sits in the final module for revision, and the optional project takes about 14 hours more.

Does this course include Microsoft Security Copilot and the Sentinel data lake?

Yes. One module covers embedded Security Copilot and agents in the Defender portal, with the habit of checking every AI output against evidence, and the hunting module covers the Sentinel data lake, KQL jobs, summary rules, notebooks and the Sentinel MCP server, all of which appear in the current SC-200 outline.

What certificate do I get, and is it the Microsoft certification?

You get an EDWartens verifiable certificate of completion, issued when you finish the modules and pass the 15-question final at 60 percent. It has a unique certificate number, a QR code and a public verification page showing the course, the modules covered and your score. It is not the Microsoft certification, which only Microsoft awards after its own SC-200 exam; EDWartens is not a Microsoft training partner.

What jobs does SC-200 preparation lead to?

The skills match security operations analyst, SOC analyst level 2, detection engineer and incident responder roles in organisations and managed security service providers that run Microsoft Defender XDR and Microsoft Sentinel.

What you walk away with

Your certificate for Microsoft Sentinel and Defender: SC-200 Exam Prep

Finish the course, pass the final, and this is the document with your name on it.

Sample EDWartens Certificate of Completion for Microsoft Sentinel and Defender: SC-200 Exam Prep
Sample. The issued certificate carries your name, admission number, a unique certificate number and its own QR code.
  • Verifiable by anyone

  • Adds to LinkedIn in one click

  • QR code on the certificate

  • Names what you can do

  • A permanent link

  • Earned, not attended

Learning is free. The certificate is optional.

Add it now and pay only when you have finished the course, or come back for it later. One-off, US$28.99, with a receipt.

Issued by EDWartens, the training division of Wartens, as a Certificate of Completion for this self-paced course. Sold by Wartens Ltd (England and Wales). It is not a vendor certification, a university award or a CPD-accredited activity, and it does not certify competence on live equipment. Delivered electronically; see the refund policy.

Credits

Who made the video lessons

The video lessons in this course were created by the people below, not by EDWartens. Every lesson streams from its creator's own YouTube channel; EDWartens neither hosts nor sells that footage, and the creators are not affiliated with EDWartens and do not endorse this course. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.

  • Microsoft Learnthe official SC-200 video series: course preview, Defender XDR, Security Copilot, Purview, Defender for Endpoint, Defender for Cloud, KQL, Sentinel configuration, connecting logs, detections and threat hunting
  • Microsoft Securityshort product demos on Defender XDR incidents, alert correlation, attack disruption, Defender for Endpoint onboarding and settings, Office 365 investigation, Sentinel in the Defender portal, unified RBAC, SOC optimization, connectors, threat intelligence, case management, Security Copilot agents, Advanced hunting, the hunting graph, the Sentinel data lake, KQL jobs, notebooks, Sentinel graph and the MCP server
  • Microsoft Mechanicsthe overview of the Microsoft Sentinel platform in the first module
  • Microsoft Security Communitythe demo of near-real-time detection rules in Microsoft Sentinel
  • Cloud360 TrainingKQL basic operators and joins, Defender for Office 365, Defender for Identity, Entra ID Protection, Defender for Cloud Apps and a step-by-step Sentinel playbook
  • Peter RisingSC-200 lessons on alert and vulnerability notification rules, Defender XDR detection rules and Defender XDR automation
  • CyberPlattercollecting Windows Security events into Sentinel with the Azure Monitor Agent
  • Christopher Nettthe full SC-200 study cram offered as optional revision in the final module

If you are one of these creators and would like a lesson removed or credited differently, write to info@wartens.com.