Microsoft Sentinel
Cloud and workloads

Skill Up Resources

In brief

The page adds a link to an open-source Microsoft Sentinel Training Lab with guided exercises and updates terminology and metadata.

What Defender admins need to know

Administrators can use the linked lab for hands-on practice; no configuration changes are required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security operations team member, I want to complete advanced training on Microsoft Sentinel so that I can enhance my skills in threat detection, incident response, and security automation.

  • Do you have a feature idea to share with us? Let us know on the Microsoft Sentinel user voice page.
  • Are you a premier customer? You might want the on-site or remote, four-day Microsoft Sentinel Fundamentals Workshop. Contact your Customer Success Account Manager for more details.
  • Do you have a specific issue? Ask (or answer others) on the Microsoft Sentinel Tech Community. Or you can email your question or issue to us at [email protected].
  • For hands-on practice, use the Microsoft Sentinel Training Lab, an open source lab with guided exercises for hunting, detection engineering, incident investigation, cost monitoring, and data lake workflows.

Module 1: Get started with Microsoft Sentinel

The value of Microsoft Sentinel security is a combination of its built-in capabilities and your ability to create custom capabilities and customize the built-in ones. Among built-in capabilities, there are User and Entity Behavior Analytics (UEBA), machine learning, or out-of-box analytics rules. Customized capabilities are often referred to as "content" and include analytic rules, hunting queries, workbooks, playbooks, and so on.

In this section, we grouped the modules that help you learn how to create such content or modify built-in-content to your needs. We start with KQL, the lingua franca of Azure Microsoft Sentinel. The following modules discuss one of the content building blocks such as rules, playbooks, and workbooks. They wrap up by discussing use cases, which encompass elements of different types that address specific security goals, such as threat detection, hunting, or governance.

Module 10: Kusto Query Language

Module 19: Monitoring Microsoft Sentinel's health

Part of operating a SIEM is making sure that it works smoothly and is an evolving area in Azure Microsoft Sentinel. Use the following to monitor Microsoft Sentinel's health: