SC-5001 : Configure SIEM Security Operations using Microsoft Sentinel
Overview
Get started with Microsoft Sentinel security operations by configuring the Microsoft Sentinel workspace, connecting Microsoft services and Windows security events to Microsoft Sentinel, configuring Microsoft Sentinel analytics rules, and responding to threats with automated responses.
Who should attend
- Security Engineers
- Security Operations Analysts
Prerequisites
- Fundamental understanding of Microsoft Azure
- Basic understanding of Microsoft Sentinel
- Experience using Kusto Query Language (KQL) in Microsoft Sentinel
What you'll learn
After completing this course, students will be able to:
- Describe Microsoft Sentinel workspace architecture
- Install Microsoft Sentinel workspace
- Create and configure a Microsoft Sentinel workspace
- Connect Microsoft service connectors
- Explain how connectors auto-create incidents in Microsoft Sentinel
- Connect Azure Windows Virtual Machines to Microsoft Sentinel
- Connect non-Azure Windows hosts to Microsoft Sentinel
- Configure Log Analytics agent to collect Sysmon events
- Explain the importance of Microsoft Sentinel Analytics
- Create rules from templates
- Create new analytics rules and queries using the analytics rule wizard
- Manage rules with modifications
- Explain automation options in Microsoft Sentinel
- Create automation rules in Microsoft Sentinel
- Deploy Microsoft Sentinel Content Hub solutions and data connectors
- Configure Microsoft Sentinel Data Collection rules, NRT Analytic rule and Automation
- Perform a simulated attack to validate Analytic and Automation rules
Course content
- Create and manage Microsoft Sentinel workspaces
- Connect Microsoft services to Microsoft Sentinel
- Connect Windows hosts to Microsoft Sentinel
- Threat detection with Microsoft Sentinel analytics
- Automation in Microsoft Sentinel
- Configure SIEM security operations using Microsoft Sentinel
Common questions
When does SC-5001 : Configure SIEM Security Operations using Microsoft Sentinel next run?
The next date is Wed, 23 Sept 2026, and there are 2 further dates scheduled. Delivered live online, ACE Training Wellington, ACE Training Auckland. Every date and its format is listed on this page.
How much does SC-5001 : Configure SIEM Security Operations using Microsoft Sentinel cost?
From $895 + GST per person. Pricing can differ by date and location, so check the option you want before booking.
Do I need any prior experience?
Fundamental understanding of Microsoft Azure Basic understanding of Microsoft Sentinel Experience using Kusto Query Language (KQL) in Microsoft Sentinel
Can I attend online, or does it have to be in a classroom?
Both. Some dates run live online and others in-class — each date on this page shows its format, so pick whichever suits.
Can you run this course for my team?
Yes. Any ACE course can be delivered in-house at your workplace and tailored to your team's tools and goals — quote course code SC5001 when you enquire.
