Configure SIEM security operations using Microsoft Sentinel (SC-5001)
Learn to configure Microsoft Sentinel SIEM operations: set up workspaces, connect Microsoft services and Windows events, create analytics rules, and automate re
Register or Request Training
- Private class for your team
- Live expert instructor
- Online or on‑location
- Customizable agenda
- Proposal responses same day as request
Course Overview
Get started with Microsoft Sentinel security operations by configuring a Microsoft Sentinel workspace, connecting Microsoft services and Windows security events, building analytics rules, and responding to threats with automated actions.
Course Benefits
- Create and configure a Microsoft Sentinel workspace
- Deploy a Microsoft Sentinel content hub solution
- Connect Windows hosts and collect security events in Microsoft Sentinel
- Configure and manage analytics rules for threat detection
- Configure automation to support threat response
Delivery Methods
Live expert-led online training from anywhere. Guaranteed to run .
Delivered for your team at your site or online.
Microsoft Certified Partner
Webucator is a Microsoft Certified Partner. This class uses official Microsoft courseware and will be delivered by a Microsoft Certified Trainer (MCT).

Course Outline
- Create and manage Microsoft Sentinel workspaces
- Plan for the Microsoft Sentinel workspace
- Create a Microsoft Sentinel workspace
- Manage workspaces across tenants using Azure Lighthouse
- Understand Microsoft Sentinel permissions and roles
- Manage Microsoft Sentinel settings
- Configure logs
- Module assessment
- Connect Microsoft services to Microsoft Sentinel
- Plan for Microsoft services connectors
- Connect the Microsoft 365 connector
- Connect the Microsoft Entra connector
- Connect the Microsoft Entra ID Protection connector
- Connect the Azure Activity connector
- Module assessment
- Connect Windows hosts to Microsoft Sentinel
- Plan for Windows hosts security events connector
- Connect using the Windows Security Events via AMA Connector
- Connect using the Security Events via Legacy Agent Connector
- Collect Sysmon event logs
- Module assessment
- Threat detection with Microsoft Sentinel analytics
- What is Microsoft Sentinel Analytics?
- Types of analytics rules
- Create an analytics rule from templates
- Create an analytics rule from wizard
- Manage analytics rules
- Automation in Microsoft Sentinel
- Understand automation options
- Create automation rules
- Module assessment
- Configure SIEM security operations using Microsoft Sentinel
Class Materials
Each student receives a comprehensive set of materials, including course notes and all class examples.
Class Prerequisites
Experience in the following is required for this Microsoft Security class:
- Fundamental understanding of Microsoft Azure
- Basic understanding of Microsoft Sentinel
- Experience using Kusto Query Language (KQL) in Microsoft Sentinel
Prerequisite Courses
Courses that can help you meet these prerequisites:
Have questions about this course?
We can help with curriculum details, delivery options, pricing, or anything else. Reach out and we’ll point you in the right direction.