Call
 

Microsoft 365 Security Analyst

Duration: 3 Days

Who should attend:

As a candidate for this course, you operate as a security operations analyst focused on reducing organizational risk through triage, incident response, threat hunting, and detection engineering.

 

In this role, you monitor, identify, investigate, and respond to threats across multi‑cloud and on‑premises environments using tools such as Microsoft Defender XDR, Microsoft Entra ID, Microsoft Purview, and Microsoft Defender for Cloud and Cloud Apps workload protections. You conduct threat hunting and automate responses to emerging threats.

You partner with business and security leaders to establish the organization’s security standards. You collaborate with teams across the digital enterprise to implement these standards, strengthen the organization’s security posture, and promote greater security awareness.

Pre-requisites:

Learners should start this course already having the following skills:

  • Have a solid foundation in the administration of Microsoft 365 environments.

Price: £1995+VAT

Want to talk through your training requirements with one of our curriculum specialists? You can get in touch by EMAIL or PHONE

Learning path 1 - Mitigate threats using Microsoft Defender XDR

  • Introduction to Microsoft Defender XDR threat protection

  • Mitigate incidents using Microsoft Defender

  • Remediate risks with Microsoft Defender for Office 365

  • Manage Microsoft Entra Identity Protection

  • Safeguard your environment with Microsoft Defender for Identity

  • Secure your cloud apps and services with Microsoft Defender for Cloud Apps

Lab - Explore Microsoft Defender XDR

Learning path 2 - Mitigate threats using Microsoft Security Copilot

  • Fundamentals of Generative AI

  • Describe Microsoft Security Copilot

  • Describe the core features of Microsoft Security Copilot

  • Describe the embedded experiences of Microsoft Security Copilot

Lab - Explore use cases of Microsoft Security Copilot

Learning path 3 - Mitigate threats using Microsoft Purview

  • Respond to data loss prevention alerts using Microsoft 365

  • Manage insider risk in Microsoft Purview

  • Search and investigate with Microsoft Purview Audit

  • Investigate threats with Content search in Microsoft Purview

Lab - Explore Microsoft Purview Audit logs

Learning path 4 - Mitigate threats using Microsoft Defender for Endpoint

  • Protect against threats with Microsoft Defender for Endpoint

  • Deploy the Microsoft Defender for Endpoint environment

  • Implement Windows security enhancements with Microsoft Defender for Endpoint

  • Perform device investigations in Microsoft Defender for Endpoint

  • Perform actions on a device using Microsoft Defender for Endpoint

  • Perform evidence and entities investigations using Microsoft Defender for Endpoint

  • Configure and manage automation using Microsoft Defender for Endpoint

  • Configure for alerts and detections in Microsoft Defender for Endpoint

  • Utilize Vulnerability Management in Microsoft Defender for Endpoint

Lab - Deploy Microsoft Defender for Endpoint

Lab - Mitigate Attacks with Microsoft Defender for Endpoint

Learning path 5 - Mitigate threats using Microsoft Defender for Cloud

  • Plan for cloud workload protections using Microsoft Defender for Cloud

  • Connect Azure assets to Microsoft Defender for Cloud

  • Connect non-Azure resources to Microsoft Defender for Cloud

  • Manage your cloud security posture management

  • Explain cloud workload protections in Microsoft Defender for Cloud

  • Remediate security alerts using Microsoft Defender for Cloud

Lab - Enable Microsoft Defender for Cloud

Lab - Mitigate threats using Microsoft Defender for Cloud

Learning Path 6 – Mitigate threats using Microsoft Defender for Cloud Apps

• Plan for cloud app protections

• Understand MDCA as a CASB and its four pillars: Discover, Investigate, Control, Protect.

• Know licensing and integrations (Entra ID, Defender XDR, Purview DLP, Sentinel).

• Connect cloud apps

• Use API connectors for SaaS apps (Salesforce, Google Workspace, Box).

• Enable app governance for Microsoft 365.

• Scan OAuth apps for risky permissions.

• Apply cloud app protections.

• Analyse app risk scores and sanction/block apps.

• Discover and assess cloud app usage (Shadow IT).

• Use Cloud Discovery to identify unsanctioned apps.

• Use activity logs, user insights, and app governance tools.

There are now over 155 million Office 365 business users!