Sentinel for Beginners
by Microsoft
Two remote days on Microsoft Sentinel, from environment setup and data source ingestion to analytics rules and response automation. Substantial time goes to KQL for querying logs and reading incidents, with attention to governance and cost control. It requires Microsoft security basics and some familiarity with the Azure portal. The programme is designed by Microsoft and delivered through EDU.Labs, Computer Gross competence centre.
Target audience
What you will learn
- SIEM and SOAR architecture, workspaces and least-privilege roles
- Data connectors, ingestion modes, costs and retention
- Kusto Query Language for log analysis
- Analytics rules, hunting and response automation
How we support you
- Free guidance to identify the ideal training path
- Full management: from enrollment to logistics, we take care of everything
- Post-course support to integrate new skills into daily work
- Custom paths for business teams, on-site or remote