Cybersecurity 路 Free
Microsoft Sentinel and Defender: SC-200 Exam Prep
Preparation for Microsoft's SC-200 Security Operations Analyst exam, mapped to the skills measured as of 21 October 2026: KQL from first query to hunting, Microsoft Defender XDR incidents and attack disruption, Defender for Endpoint, Office 365, Identity and Cloud Apps, Purview investigations, Microsoft Sentinel setup, data connectors, analytics rules, automation, Security Copilot and threat hunting.
Inside the course



From the lessons

The SC-200 exam, the Defender portal and a safe lab
Microsoft Learn

KQL for investigations: let, join, union, parse and JSON
Microsoft Security

Microsoft Defender for Endpoint: configure, investigate and respond
Microsoft Learn

Microsoft Purview investigations and Defender for Cloud alerts
Microsoft Learn

Getting data into Microsoft Sentinel
Microsoft Learn

Automation: automation rules, playbooks and case management
Microsoft Security
Lesson frames belong to the creators named in the Credits below and are shown from YouTube.
What you will learn
Plan your SC-200 study against Microsoft's published outline; write KQL that filters, aggregates, joins and parses security data; work an incident in the Microsoft Defender portal and explain attack disruption; configure and respond with Defender for Endpoint; investigate email, identity and SaaS threats; search Purview Audit and eDiscovery; set up a Microsoft Sentinel workspace with the right roles, retention and data connectors; build analytics and custom detection rules mapped to MITRE ATT&CK; automate response with automation rules and playbooks; check Security Copilot output against evidence; and hunt with Advanced hunting, the data lake and notebooks.
- Plan SC-200 study against the three skill areas and weights Microsoft publishes
- Write KQL that filters by time, aggregates, joins tables and unpacks JSON for investigations
- Work incidents in the Microsoft Defender portal and explain automatic attack disruption
- Configure Defender for Endpoint device groups, ASR rules and response actions
- Investigate phishing, compromised identities and risky OAuth apps across Office 365, Entra and Cloud Apps
- Set up a Microsoft Sentinel workspace with least-privilege roles, sensible retention and filtered data connectors
- Build analytics and custom detection rules mapped to MITRE ATT&CK, and automate response with approval gates
- Hunt with Advanced hunting, the Sentinel data lake, KQL jobs and notebooks, and check Security Copilot output
For you
Taking Microsoft Sentinel and Defender: SC-200 Exam Prep from the United States
- Free in the United States, as everywhere, and self-paced: lessons, notes and the final assessment are open at any hour, so your time zone and shift pattern do not matter.
- The optional certificate for learners in the United States is a one-off US$28.99. What you get for it
- Plants across the Americas most often run Allen-Bradley, Siemens and Inductive Automation; each has its own free course to take next.
- See automation and engineering jobs in the United States, and what the industry looks like in Houston, Detroit and Chicago.
- EDWartens also has a regional site for the United States, for classroom training and local support: edwartens.com/us.
The course project 路 about 14 hours
A starter detection and response pack: Sentinel connectors, three rules, a gated playbook and one hunt in a lab
Stand up a small Microsoft Sentinel workspace in your own lab, collect Windows Security events with a filtered data collection rule, write three analytics rules mapped to MITRE ATT&CK, design an automation rule and a playbook with an approval step, run one hypothesis-led hunt, trigger harmless test activity, and write the incident report and runbook a real SOC would keep.
Sample document pack, 5 documents, filled in for the scenario
- RegisterDetection register: starter rules
- Test reportDetection test record: lab test activity
- ProcedureTriage runbook: incidents in the Defender portal
- ReportIncident report: brute force on labuser1
- Risk registerRisk register: starter SOC pack
Read inside the course and download as a workbook. The project is optional practice, marked when you submit it; the certificate needs only the modules and the final assessment.
Course content
14 modules 路 64 lessons 路 17h 49m
In order, at whatever pace suits you. Each module ends with a practice task that builds on the last.
- 01The SC-200 exam, the Defender portal and a safe lab4 lessons20m
- 02KQL fundamentals for security analysts3 lessons1h 14m
- 03KQL for investigations: let, join, union, parse and JSON4 lessons34m
- 04Microsoft Defender XDR: incidents, alerts and attack disruption5 lessons1h 13m
- 05Microsoft Defender for Endpoint: configure, investigate and respond5 lessons1h 12m
- 06Email, identity and SaaS threats: Office 365, Identity, Entra and Cloud Apps7 lessons55m
- 07Microsoft Purview investigations and Defender for Cloud alerts3 lessons1h 16m
- 08Microsoft Sentinel: workspace, roles, retention and workbooks5 lessons1h 13m
Requirements
- Who it is for
- Intermediate. For SOC analysts, IT administrators and security graduates who know the basics of networks, Windows logs and incident response. SOC Analyst Level 1 with Splunk or Cybersecurity Fundamentals covers those basics if you need them.
- Software
- A browser and an Azure subscription you control: an Azure free account works for the Sentinel workspace, and a new workspace has a time-limited Microsoft Sentinel free trial (check the current terms on Microsoft Learn). Microsoft 365 E5 or Defender trial licences for the Defender XDR modules where available. KQL practice runs free on the Azure Data Explorer help cluster. What to download, and how
- Hardware
- A computer with a browser. A Windows virtual machine, local or in Azure, for the endpoint and log collection exercises.
Software you need
What to download, where from, what it costs and how to install it. Every link goes to the maker's own site, never a mirror.
Microsoft Sentinel and the Defender portal run in the browser; a new workspace has a time-limited Sentinel free trial, so check Microsoft's current terms and delete the lab resource group when you finish. Defender XDR modules need Microsoft 365 E5 or Defender trial licences where available. A Windows evaluation VM, in Azure or VirtualBox, is used for the endpoint and log collection exercises. KQL practice runs free at dataexplorer.azure.com on the help cluster.
Required
- 01Free trial: 30 days of credit, some services free for 12 months
Azure free account
Microsoft, in the browser
- Runs on
- Any modern web browser
- Account
- A Microsoft account, a phone number and a credit or debit card for identity checks
New customers get credit to use within 30 days, free monthly amounts of 20+ popular services for 12 months, and 65+ always-free services. The card is only for identity checks: Microsoft does not charge it, though a temporary one-dollar (or equivalent) hold may appear. You are not charged unless you upgrade.
Steps
- 1.Open the Azure free account page and click Try Azure for free.
- 2.Sign in with a Microsoft account or create one.
- 3.Verify your phone number and enter a card for identity verification.
- 4.Accept the agreement and open the Azure portal.
- 5.Set a budget alert in Cost Management before starting labs.
- Students at eligible universities can use Azure for Students instead, which needs no card.
Open Azure free accountazure.microsoft.comAlternatives
- Azure for Students: Credit for 12 months with no credit card, for full-time university students using a school email. Renews each year while you are a student.
Optional
Useful, not needed to finish the course.
- 02Free trial: 90 days
Windows 11 Enterprise (evaluation)
Microsoft
- Runs on
- Installs as a virtual machine or on a PC; ISO for x64 and Arm64
- Account
- A short registration form on the Microsoft Evaluation Center
A full-featured 90-day evaluation for testing, with no product key needed. When it expires the desktop turns black, a notice stays on screen and the PC shuts down every hour.
Steps
- 1.Open the Windows 11 Enterprise page on the Microsoft Evaluation Center.
- 2.Fill in the registration form and choose the ISO for your language and architecture (x64 for most PCs).
- 3.Create a new virtual machine in VirtualBox or Hyper-V and attach the ISO.
- 4.Install Windows 11 Enterprise and finish setup.
- 5.Take a snapshot of the fresh install so you can return to it after each lab.
- Windows 11 checks for TPM 2.0 and Secure Boot, so enable these in your virtual machine settings.
- Plan labs to finish within 90 days, or rebuild the VM from the ISO.
Official download pagemicrosoft.com - 03Free
Oracle VirtualBox
Oracle
- Runs on
- Windows, macOS (Intel and Apple Silicon), Linux and Solaris hosts
- Account
- None needed
The VirtualBox platform packages are free and open source under GPL version 3. The separate Extension Pack is free only for personal and educational use (PUEL licence); business use of the Extension Pack needs a commercial licence from Oracle.
Steps
- 1.Open virtualbox.org/wiki/Downloads.
- 2.Click the package for your host system (for example, Windows hosts).
- 3.Run the installer and accept the network driver prompts.
- 4.Open VirtualBox, click New, choose your ISO file (for example Ubuntu or Windows) and follow the wizard.
- Turn on hardware virtualisation (Intel VT-x or AMD-V) in your PC's BIOS or UEFI if VirtualBox says it is not available.
- You do not need the Extension Pack for normal lab work. Install it only if you need its extra features and your use is personal or educational.
Official download pagevirtualbox.org
Checked against each maker's own page on 27 September 2026. Trial lengths and editions change; the maker's page is the final word.
Microsoft Sentinel and Defender: SC-200 Exam Prep at a glance
Microsoft Sentinel and Defender: SC-200 Exam Prep is a free, self-paced online course from EDWartens for SOC analysts, IT administrators and security graduates preparing for Microsoft's SC-200 exam and working with Microsoft Sentinel and Defender XDR. It has 14 modules and 17h 49m of video lessons by Microsoft Learn, Microsoft Security, Microsoft Mechanics and others, with written notes and worked problems, a practical project with a document pack and a 15-question final assessment (pass mark 60%). Learning is free with an account; an optional certificate with a public verification code is issued when you pass. Last updated 27 September 2026.
All course factsHide course facts
- Price
- Free, for good. No trial, no card. The only paid item is the optional certificate, a small one-off fee.
- Who it is for
- SOC analysts, IT administrators and security graduates preparing for Microsoft's SC-200 exam and working with Microsoft Sentinel and Defender XDR
- Format
- 14 self-paced modules, 17h 49m of video, written notes, a practice task per module and one final assessment.
- Level
- Intermediate. Intermediate. For SOC analysts, IT administrators and security graduates who know the basics of networks, Windows logs and incident response. SOC Analyst Level 1 with Splunk or Cybersecurity Fundamentals covers those basics if you need them.
- Brand
- Microsoft
- Software
- A browser and an Azure subscription you control: an Azure free account works for the Sentinel workspace, and a new workspace has a time-limited Microsoft Sentinel free trial (check the current terms on Microsoft Learn). Microsoft 365 E5 or Defender trial licences for the Defender XDR modules where available. KQL practice runs free on the Azure Data Explorer help cluster.
- Hardware
- A computer with a browser. A Windows virtual machine, local or in Azure, for the endpoint and log collection exercises.
- Certificate
- Optional EDWartens Certificate of Completion, verifiable by code. Not a vendor credential.
- Video lessons by
- Microsoft Learn, Microsoft Security, Microsoft Mechanics, Microsoft Security Community, Cloud360 Training, Peter Rising, CyberPlatter, Christopher Nett (independent creators, credited below)
- Language
- English
- Last updated
- 27 September 2026
A shareable EDWartens certificate
Finish every module and pass the final assessment, and the optional EDWartens certificate is yours. It carries a unique verification code on a public page anyone can check, so it stands up when a recruiter looks it up. See it below.
The course itself stays free whether or not you ever buy one.
Stuck? Ask a practising engineer
A free course usually means a comment section and hope. This one does not. Every module has an Ask-your-trainer panel that reaches the same engineers who teach our paid programme: people who commission panels for a living, not moderators.
Pairs well with
FreeAI for professionals 路 FreeMicrosoft 365 Copilot and Copilot Studio AgentsUse Microsoft 365 Copilot well and build your first agent: what Copilot, Copilot Chat and Copilot Studio each are, how grounding works, Copilot in Word, Excel, Outlook and PowerPoint, prompting and saved prompts, the Researcher and Analyst agents, building and grounding an agent in Copilot Studio, and responsible use.
FreeCybersecurity 路 FreeOT Security Assessment: Testing a Plant Without Stopping ItThe assessment half of OT security, for engineers who have to do it on a plant that is running. Rules of engagement first, then passive capture, careful enumeration, what an attacker does with a protocol that has no authentication, the Windows machines nobody mentions, the logging that would have caught it, and a report written in the language of consequence.
FreeCybersecurity 路 FreeICS Security Foundations: Control Systems, Defence in Depth and the 62443 RequirementsThe ground floor of industrial cyber security, taught through the systems themselves: what a DCS, PLC, SCADA, BACS and safety system actually do, the Purdue model, why OT is not IT, how industrial attacks unfold, defence in depth and a layered architecture, then the seven ISA/IEC 62443 foundational requirements one at a time, asset registers, segmentation, discovery, IDS and IPS, secure remote access, SIEM and endpoint protection.
FreeCybersecurity 路 FreeOT and ICS Cybersecurity with ISA/IEC 62443Free OT security course for automation and IT staff: Purdue zones, ISA/IEC 62443 security levels, risk assessment. The certificate is optional and paid.More free courses: Free cyber security courses
Learner reviews
No reviews yet
Reviews here are written only by learners who have finished every module of Microsoft Sentinel and Defender: SC-200 Exam Prep, and they are published exactly as written. Finish the course and yours will be the first.
Common questions
What is the SC-200 exam?
SC-200 is Microsoft's exam for the Microsoft Certified: Security Operations Analyst Associate certification. It tests managing a security operations environment (40-45%), responding to security incidents (35-40%) and threat hunting (20-25%) with Microsoft Defender XDR, Microsoft Sentinel and KQL, under the skills measured as of 21 October 2026. You book it with Microsoft through Pearson VUE, the fee is paid to Microsoft, and 700 is the pass mark.
Who is this SC-200 preparation course for?
It is for SOC analysts, IT administrators, cloud engineers and security graduates who work with, or want to work with, Microsoft's security stack. It suits anyone moving from a level 1 SOC role into Microsoft Sentinel and Defender XDR, and anyone preparing for the SC-200 exam.
Is the course free to learn?
Yes. Every module, the notes, the worked problems, the practice tasks, the optional project and the final assessment are free to learn. The labs use an Azure free account, the Microsoft Sentinel free trial on a new workspace and the free KQL help cluster; check Microsoft's current trial terms before you start and delete lab resources when you finish.
What do I need to know before I start?
You should know the basics of networks, Windows event logs and the incident response process. If those are new, take Cybersecurity Fundamentals or SOC Analyst Level 1 with Splunk first. No KQL experience is needed; two modules teach it from the first query.
How long does the SC-200 course take?
About 19 hours of video, notes and practice at your own pace, of which about 13.6 hours is video in the study modules. An optional 4-hour study cram sits in the final module for revision, and the optional project takes about 14 hours more.
Does this course include Microsoft Security Copilot and the Sentinel data lake?
Yes. One module covers embedded Security Copilot and agents in the Defender portal, with the habit of checking every AI output against evidence, and the hunting module covers the Sentinel data lake, KQL jobs, summary rules, notebooks and the Sentinel MCP server, all of which appear in the current SC-200 outline.
What certificate do I get, and is it the Microsoft certification?
You get an EDWartens verifiable certificate of completion, issued when you finish the modules and pass the 15-question final at 60 percent. It has a unique certificate number, a QR code and a public verification page showing the course, the modules covered and your score. It is not the Microsoft certification, which only Microsoft awards after its own SC-200 exam; EDWartens is not a Microsoft training partner.
What jobs does SC-200 preparation lead to?
The skills match security operations analyst, SOC analyst level 2, detection engineer and incident responder roles in organisations and managed security service providers that run Microsoft Defender XDR and Microsoft Sentinel.
What you walk away with
Your certificate for Microsoft Sentinel and Defender: SC-200 Exam Prep
Finish the course, pass the final, and this is the document with your name on it.

Verifiable by anyone
Adds to LinkedIn in one click
QR code on the certificate
Names what you can do
A permanent link
Earned, not attended
Learning is free. The certificate is optional.
Add it now and pay only when you have finished the course, or come back for it later. One-off, US$28.99, with a receipt.
Issued by EDWartens, the training division of Wartens, as a Certificate of Completion for this self-paced course. Sold by Wartens Ltd (England and Wales). It is not a vendor certification, a university award or a CPD-accredited activity, and it does not certify competence on live equipment. Delivered electronically; see the refund policy.
Credits
Who made the video lessons
The video lessons in this course were created by the people below, not by EDWartens. Every lesson streams from its creator's own YouTube channel; EDWartens neither hosts nor sells that footage, and the creators are not affiliated with EDWartens and do not endorse this course. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.
- Microsoft Learnthe official SC-200 video series: course preview, Defender XDR, Security Copilot, Purview, Defender for Endpoint, Defender for Cloud, KQL, Sentinel configuration, connecting logs, detections and threat hunting
- Microsoft Securityshort product demos on Defender XDR incidents, alert correlation, attack disruption, Defender for Endpoint onboarding and settings, Office 365 investigation, Sentinel in the Defender portal, unified RBAC, SOC optimization, connectors, threat intelligence, case management, Security Copilot agents, Advanced hunting, the hunting graph, the Sentinel data lake, KQL jobs, notebooks, Sentinel graph and the MCP server
- Microsoft Mechanicsthe overview of the Microsoft Sentinel platform in the first module
- Microsoft Security Communitythe demo of near-real-time detection rules in Microsoft Sentinel
- Cloud360 TrainingKQL basic operators and joins, Defender for Office 365, Defender for Identity, Entra ID Protection, Defender for Cloud Apps and a step-by-step Sentinel playbook
- Peter RisingSC-200 lessons on alert and vulnerability notification rules, Defender XDR detection rules and Defender XDR automation
- CyberPlattercollecting Windows Security events into Sentinel with the Azure Monitor Agent
- Christopher Nettthe full SC-200 study cram offered as optional revision in the final module
If you are one of these creators and would like a lesson removed or credited differently, write to info@wartens.com.
