Modernize and optimize your SOC deployment with Microsoft Sentinel

Last Updated 17 Feb 2026

Course Overview

Learn how to deploy, configure, and optimize Microsoft Sentinel using the new unified experience within the Microsoft Defender portal. This course equips technical teams to plan architecture, connect data sources, apply SIEM best practices, and operationalize an AI-ready SOC with improved visibility, integrated Defender workflows, and interactive simulated labs.

Duration - 6 Hours

Level - Intermediate

Style - Self paced

Course Type - Project Ready with Labs

Certification - No

Hands on Labs - Yes

Solution Areas - Security, Modern SecOps with Unified Platform

ESI Course Code - DW-350

Course Modules

Modernizing your SOC with Microsoft Sentinel

This module explores the evolving threat landscape and the challenges faced by modern Security Operations Centers (SOC), emphasizing the need to modernize defenses. It provides an overview of Microsoft Sentinel SIEM, its platform architecture, key capabilities, and how to detect, investigate, and respond to threats through a unified security operations experience with the Defender Portal.

Planning for Sentinel Deployment

This module covers planning for Microsoft Sentinel SIEM deployment, including workspace architecture, sample designs, and prioritizing data connectors. It also addresses data retention, tiering models with Analytics and Data Lake, and planning costs while understanding billing considerations.

Deploy and configure Microsoft Sentinel

This module guides managing roles and permissions, deploying Microsoft Sentinel SIEM, enabling initial content, and connecting to the Microsoft Defender portal and content hub solutions. It also covers connecting data sources, deploying log forwarders, using AWS S3 connectors, Microsoft Security Store, Sentinel MCP tools, platform deployment, Graph (Preview) overview, and onboarding Sentinel to Data Lake and Graph.

SOC Optimizing and best practices

This module focuses on identifying areas of optimization and implementing SIEM best practices within Microsoft Sentinel. It also highlights practical use cases to maximize the effectiveness of Sentinel in real-world security operations.

Post-training Skills Assessment

Take this assessment to validate your skills gathered from the self-paced online learning completed in this course to mark your completion.

Course Completion Survey

Share your feedback with us regarding your experience!

Other courses in this Category

Intermediate

Implement Microsoft Defender for Endpoint

Duration - 12 Hours
Course
Intermediate

Protect cloud, AI Platform and Apps by implementing Defender for Cloud

Duration - 12 Hours
Course
Intermediate

Implement Threat Protection with Microsoft Defender XDR solutions

Duration - 12 Hours
Course
Advanced

Implement Identity and access management with Microsoft Entra

Duration - 16 Hours
Course