0
+
Google Reviews
0
+
4.5 (2,056 Ratings)
SC-900 + SC-200 Training helps you build practical Microsoft security skills, from security and identity fundamentals to real-world SOC operations. Learn Microsoft Entra ID, Defender, Sentinel, KQL, threat detection, incident response, threat hunting, and security automation through hands-on training. Ideal for cybersecurity beginners, SOC analysts, IT professionals, cloud professionals, and security teams looking to strengthen their Microsoft security skills.
Duration of Training : 50 Hours
Batch type : Weekdays/Weekends
Mode of Training : Classroom/Online/Corporate Training
Detailed Syllabus • Hands-on Labs • Assignments • Support-Focused • Implementation
Curriculum Designed by Experts
This SC-900 + SC-200 combined program takes learners from security fundamentals to advanced security operations and SOC analyst capabilities.
The program covers:
• Microsoft Security, Compliance, and Identity fundamentals
• Microsoft Entra ID
• Microsoft Defender XDR
• Microsoft Defender for Endpoint
• Microsoft Defender for Office 365
• Microsoft Defender for Cloud
• Microsoft Sentinel SIEM
• KQL (Kusto Query Language)
• Threat detection and investigation
• Incident response
• Threat hunting
• Security analytics
• Automation and SOAR
• Microsoft Purview and compliance fundamentals
• Identity and access security
• Security monitoring
• Real-world SOC workflows
• GenAI/AI-assisted security operations
The training emphasizes hands-on SOC operations rather than only exam preparation.
Recommended
• Basic understanding of Windows and operating systems
• Basic networking concepts
• Basic understanding of cloud computing
• Familiarity with Microsoft 365 is helpful but not mandatory
• Basic cybersecurity awareness
• Logical thinking and troubleshooting skills
Programming
No advanced programming required.
Basic scripting concepts and KQL will be introduced during the course.
Cybersecurity Fundamentals
• CIA Triad
• Authentication vs Authorization
• Identity and Access Management
• Least Privilege
• Zero Trust Security
• Defense in Depth
• Threat, Vulnerability, Risk and Exposure
• Security Controls
• Security Policies
• Security Operations Center
• SOC roles and responsibilities
• Security monitoring fundamentals
• Incident response lifecycle
Cloud Security Fundamentals
• Cloud computing concepts
• Shared Responsibility Model
• SaaS, PaaS and IaaS
• Cloud identity
• Cloud security controls
• Cloud security monitoring
• Microsoft cloud security architecture
Module 1 — Microsoft Security Fundamentals
• Microsoft security ecosystem
• Security, compliance and identity concepts
• Microsoft Security solutions
• Microsoft security architecture
• Microsoft Secure Future Initiative
• Zero Trust principles
• Defense-in-depth approach
Module 2 — Microsoft Entra
• Microsoft Entra ID fundamentals
• Users and groups
• Domains
• Tenants
• Authentication
• Authorization
• Identity lifecycle
• Self-Service Password Reset
• Multi-Factor Authentication
• Conditional Access fundamentals
• Identity Protection
• Privileged Identity Management
• Application identities
• Managed identities
• Microsoft Entra Connect concepts
• Hybrid identity
• Identity Governance fundamentals
Module 3 — Microsoft Security Solutions
Microsoft Defender
• Microsoft Defender overview
• Defender XDR
• Defender for Endpoint
• Defender for Office 365
• Defender for Identity
• Defender for Cloud Apps
• Microsoft Defender for Cloud
Microsoft Sentinel
• SIEM fundamentals
• Microsoft Sentinel overview
• Security analytics
• Data collection
• Detection
• Investigation
• Automation
Microsoft Purview
• Microsoft Purview overview
• Compliance Manager
• Data classification
• Sensitivity labels
• Retention labels
• Data Loss Prevention
• Insider Risk Management
• eDiscovery
• Audit
• Information Protection
• Records Management
Microsoft Service Trust Portal
• Compliance concepts
• Microsoft compliance offerings
• Trust documentation
• Regulatory requirements
• Compliance responsibilities
Module 1 — Security Operations Fundamentals
• SOC architecture
• SOC analyst responsibilities
• Security monitoring
• Threat detection
• Alert management
• Incident management
• Investigation lifecycle
• Threat intelligence
• Security telemetry
• Indicators of Compromise
• Indicators of Attack
• MITRE ATT&CK fundamentals
Sentinel Architecture
• Microsoft Sentinel overview
• Sentinel workspace
• Log Analytics Workspace
• Data connectors
• Analytics rules
• Incidents
• Workbooks
• Hunting queries
• Automation rules
• Playbooks
Data Collection
• Microsoft 365 data
• Entra ID logs
• Windows security events
• Azure activity logs
• Defender data
• Firewall logs
• Network logs
• Syslog
• CEF
• Custom log sources
KQL Fundamentals
• KQL syntax
• Tables
• Columns
• Filtering
• Sorting
• Projection
• Aggregation
• Summarization
• Grouping
• Joins
• Parsing
• String manipulation
• Date/time operations
• Variables
• Functions
Security KQL
• SecurityEvent
• SigninLogs
• AuditLogs
• DeviceEvents
• DeviceProcessEvents
• DeviceNetworkEvents
• DeviceFileEvents
• CommonSecurityLog
• OfficeActivity
Advanced KQL
• Time-series analysis
• Dynamic data
• JSON parsing
• Watchlists
• Functions
• Query optimization
• Hunting queries
• Detection queries
Defender XDR
• Defender XDR architecture
• Incidents
• Alerts
• Advanced Hunting
• Device inventory
• Identity incidents
• Email threats
• Cloud application threats
• Cross-domain investigation
Defender for Endpoint
• Endpoint security
• Device onboarding
• Device inventory
• Endpoint alerts
• Vulnerability management
• Attack Surface Reduction
• Endpoint detection and response
• Automated investigation
• Device isolation
• Live Response
• Threat remediation
• Email security
• Phishing protection
• Malware protection
• Safe Links
• Safe Attachments
• Anti-phishing policies
• Email investigation
• Threat Explorer
• Campaign investigation
• Quarantine
• Compromised user investigation
• Identity-based attacks
• Domain Controller monitoring
• Suspicious authentication
• Credential theft
• Pass-the-Hash
• Pass-the-Ticket
• Lateral movement
• Reconnaissance
• Identity alerts
• Investigation techniques
• Cloud security posture
• Secure Score
• Recommendations
• Cloud workload protection
• Security alerts
• Vulnerability assessment
• Defender plans
• Cloud security monitoring
• Multi-cloud security concepts
• Alert triage
• Alert prioritization
• Incident correlation
• Investigation trees
• Attack timelines
• Entity investigation
• User investigation
• Device investigation
• IP investigation
• Domain investigation
• Hash investigation
• URL investigation
• Threat intelligence enrichment
• Threat hunting methodology
• Hypothesis-driven hunting
• IOC hunting
• Behavioral hunting
• MITRE ATT&CK mapping
• Advanced Hunting
• KQL hunting
• Suspicious PowerShell detection
• Credential theft detection
• Lateral movement detection
• Persistence detection
• Command-and-control detection
• Incident lifecycle
• Preparation
• Identification
• Containment
• Eradication
• Recovery
• Lessons learned
• Incident severity classification
• Evidence collection
• Investigation documentation
• Escalation procedures
• SOC handoff procedures
• Sentinel automation rules
• Logic Apps
• Playbooks
• Automated incident response
• Automated enrichment
• IOC blocking
• User account response
• Ticket creation
• Notification workflows
• Threat intelligence automation
SC-900 Labs
1. Create Microsoft Entra Users
2. Create Security Groups
3. Configure MFA
4. Explore Conditional Access
5. Configure Identity Protection
6. Explore Microsoft Defender Portal
7. Explore Microsoft Purview
8. Configure Sensitivity Labels
9. Explore Compliance Manager
10. Explore Microsoft Sentinel
SC-200 Labs
11. Create a Microsoft Sentinel Workspace
12. Connect Microsoft Entra ID Logs
13. Connect Microsoft Defender XDR
14. Configure Data Connectors
15. Create Analytics Rules
16. Investigate Sentinel Incidents
17. Build Sentinel Workbooks
18. Write Basic KQL Queries
19. Write Advanced KQL Queries
20. Build Threat Hunting Queries
21. Investigate Windows Security Events
22. Investigate Suspicious Sign-ins
23. Investigate Malware Alerts
24. Investigate Phishing Incidents
25. Investigate Endpoint Attacks
26. Perform Device Investigation
27. Perform User Investigation
28. Use Defender Advanced Hunting
29. Perform Device Isolation
30. Configure Sentinel Automation
31. Create a Logic Apps Playbook
32. Automate IOC Investigation
33. Investigate Identity Attacks
34. Perform Threat Intelligence Investigation
35. Conduct MITRE ATT&CK-based Hunting
1. Microsoft Security Architecture Analysis
2. Build a Zero Trust Security Model
3. Create an Entra Identity Management Plan
4. Design an MFA Strategy
5. Create Conditional Access Policies
6. Analyze Entra Sign-in Logs
7. Analyze Risky Users
8. Design a Microsoft Defender Architecture
9. Create a Sentinel Deployment Plan
10. Design a SOC Monitoring Strategy
11. Write 20 Basic KQL Queries
12. Write 20 Intermediate KQL Queries
13. Write Security Detection Queries
14. Investigate Suspicious Authentication
15. Analyze Windows Security Events
16. Investigate PowerShell Activity
17. Analyze Endpoint Alerts
18. Investigate Phishing Emails
19. Build a Threat Hunting Hypothesis
20. Map Attacks to MITRE ATT&CK
21. Design an Incident Response Workflow
22. Create an Automated Response Plan
23. Build a Sentinel Workbook
24. Design a SOC Escalation Matrix
25. Prepare an Incident Investigation Report
Mini Project 1 — SOC Monitoring Dashboard
Build a Microsoft Sentinel dashboard for monitoring:
• Authentication
• Failed logins
• Suspicious users
• Security alerts
• Endpoint activity
Mini Project 2 — Phishing Investigation
Investigate a simulated phishing attack using:
• Defender for Office 365
• Defender XDR
• Threat Explorer
• Sentinel
• KQL
Mini Project 3 — Suspicious Login Investigation
Detect and investigate:
• Impossible travel
• Multiple failed logins
• Risky sign-ins
• Unusual locations
• Suspicious IP addresses
Mini Project 4 — Endpoint Malware Investigation
Investigate a compromised endpoint and perform:
• Alert triage
• Process investigation
• Network investigation
• Device isolation
• Remediation
Mini Project 5 — Threat Hunting
Perform proactive hunting for:
• PowerShell attacks
• Credential theft
• Persistence
• Lateral movement
• Command-and-control activity
Mini Project 6 — Automated SOC Response
Create an automated Sentinel workflow for:
Alert → Incident → Enrichment → Notification → Response
Capstone Project 1 — Enterprise SOC Implementation
Design and implement a complete Microsoft-based SOC environment covering:
• Microsoft Entra ID
• Microsoft Defender XDR
• Defender for Endpoint
• Defender for Office 365
• Microsoft Sentinel
• KQL
• Threat Intelligence
• Incident Response
• Automation
Deliverables:
• SOC architecture
• Monitoring strategy
• Detection rules
• KQL queries
• Dashboard
• Incident response playbook
• Threat hunting report
Capstone Project 2 — Ransomware Attack Investigation
Simulate an enterprise ransomware incident.
Learners investigate:
Initial Access → Execution → Persistence → Privilege Escalation → Lateral Movement → Data Impact
Using:
• Sentinel
• Defender XDR
• Defender for Endpoint
• KQL
• MITRE ATT&CK
Then perform containment and remediation.
Capstone Project 3 — Enterprise Phishing & Account Compromise
Investigate a complete identity compromise involving:
• Phishing email
• Credential theft
• Suspicious authentication
• Account takeover
• Endpoint compromise
• Lateral movement
Learners prepare a complete SOC Incident Investigation Report.
Students will practice scenarios such as:
1. Employee account has multiple failed logins.
2. User signs in from two geographically impossible locations.
3. Employee clicks a malicious phishing URL.
4. Defender detects malware on an endpoint.
5. PowerShell executes suspicious commands.
6. Unknown executable starts on a workstation.
7. User account suddenly becomes high risk.
8. Suspicious administrator login occurs.
9. Endpoint communicates with a malicious IP.
10. Large data transfer is detected.
11. Possible credential theft is detected.
12. Suspicious process creates a persistence mechanism.
13. Multiple machines show similar alerts.
14. Possible ransomware activity is detected.
15. SOC receives a high-severity Sentinel incident.
16. Security alert needs threat-intelligence enrichment.
17. Compromised device needs immediate isolation.
18. Multiple alerts must be correlated into one incident.
19. Security team needs an automated response.
20. SOC needs to create a new detection rule.
• Sentinel data connector not receiving logs
• KQL query returning no results
• Incorrect KQL syntax
• Analytics rule not generating incidents
• Duplicate alerts
• False-positive security alerts
• Defender device not appearing
• Endpoint onboarding failure
• Defender alert investigation
• Microsoft Entra sign-in failures
• Conditional Access blocking legitimate users
• MFA issues
• Suspicious authentication investigation
• Sentinel workbook not displaying data
• Logic Apps playbook failure
• Automation rule not triggering
• Incorrect incident severity
• Threat hunting query performance problems
• Missing Windows security events
• CEF/Syslog ingestion issues
Microsoft Security
• Microsoft Entra ID
• Microsoft Entra ID Protection
• Microsoft Entra PIM
• Microsoft Defender XDR
• Microsoft Defender for Endpoint
• Microsoft Defender for Office 365
• Microsoft Defender for Identity
• Microsoft Defender for Cloud
• Microsoft Defender for Cloud Apps
• Microsoft Sentinel
• Microsoft Purview
• Microsoft Intune
SOC / Security Tools
• KQL
• Log Analytics
• Logic Apps
• MITRE ATT&CK
• Threat Intelligence
• Syslog
• CEF
• Windows Event Viewer
• PowerShell
• Follow Zero Trust principles
• Apply least privilege
• Implement strong identity security
• Use MFA
• Apply Conditional Access appropriately
• Reduce security alert noise
• Prioritize high-risk incidents
• Build effective detection rules
• Use KQL efficiently
• Document investigations
• Follow incident-response procedures
• Automate repetitive SOC tasks
• Maintain detection-rule quality
• Regularly review false positives
• Use MITRE ATT&CK for threat coverage
• Continuously improve SOC processes
Microsoft SC-900
Microsoft Certified: Security, Compliance, and Identity Fundamentals
Microsoft SC-200
Microsoft Certified: Security Operations Analyst Associate
The training can be structured around the knowledge and skills measured by the corresponding Microsoft certification exams.
Conduct SOC Analyst and Microsoft Security-focused mock interviews covering:
• SC-900 fundamentals
• SC-200 technical questions
• KQL
• Microsoft Sentinel
• Defender XDR
• Incident response
• Threat hunting
• Entra ID
• Real-time troubleshooting
• Scenario-based SOC questions
Focus: Technical knowledge + practical problem solving + communication.
Build a job-oriented Microsoft Security/SOC Analyst resume highlighting:
• Microsoft Sentinel
• Microsoft Defender
• Entra ID
• KQL
• Threat Hunting
• Incident Response
• Security Monitoring
• SOC Projects
• Capstone Projects
• Hands-on Labs
• Microsoft Certifications
Projects will be converted into strong resume project descriptions rather than simply listing course topics.
Placement preparation can include:
• SOC Analyst job-role mapping
• Resume optimization
• LinkedIn profile guidance
• Technical interview preparation
• Mock interviews
• KQL interview preparation
• Scenario-based interview preparation
• HR interview preparation
• Job application guidance
• Interview feedback
• Real-time SOC troubleshooting practice
Target Job Roles
• SOC Analyst — L1
• SOC Analyst — L2
• Security Operations Analyst
• Microsoft Security Analyst
• Cybersecurity Analyst
• SIEM Analyst
• Microsoft Sentinel Analyst
• Threat Detection Analyst
• Incident Response Analyst
• Security Monitoring Analyst
• Junior Threat Hunter
• Cloud Security Analyst
Radical Technologies is the leading IT certification institute in Kochi, offering a wide range of globally recognized certifications across various domains. With expert trainers and comprehensive course materials, it ensures that students gain in-depth knowledge and hands-on experience to excel in their careers. The institute’s certification programs are tailored to meet industry standards, helping professionals enhance their skillsets and boost their career prospects. From cloud technologies to data science, Radical Technologies covers it all, empowering individuals to stay ahead in the ever-evolving tech landscape. Achieve your professional goals with certifications that matter.
At Radical Technologies, we are committed to your success beyond the classroom. Our 100% Job Assistance program ensures that you are not only equipped with industry-relevant skills but also guided through the job placement process. With personalized resume building, interview preparation, and access to our extensive network of hiring partners, we help you take the next step confidently into your IT career. Join us and let your journey to a successful future begin with the right support.
At Radical Technologies, we ensure you’re ready to shine in any interview. Our comprehensive Interview Preparation program includes mock interviews, expert feedback, and tailored coaching sessions to build your confidence. Learn how to effectively communicate your skills, handle technical questions, and make a lasting impression on potential employers. With our guidance, you’ll walk into your interviews prepared and poised for success.
At Radical Technologies, we believe that a strong professional profile is key to standing out in the competitive IT industry. Our Profile Building services are designed to highlight your unique skills and experiences, crafting a resume and LinkedIn profile that resonate with employers. From tailored advice on showcasing your strengths to tips on optimizing your online presence, we provide the tools you need to make a lasting impression. Let us help you build a profile that opens doors to your dream career.
Kochi | Fort Kochi | Mattancherry | Ernakulam | Marine Drive | Kakkanad | Palarivattom | Kadavanthra | Chullikkal | Elamakkara | Kochi Port | Vyttila | Aluva | Thrippunithura | Panampilly Nagar | Edappally | Kothad | Njarackal
At Radical Technologies, we are committed to providing world-class Azure Data Engineer Training in Bangalore, helping aspiring data professionals master the skills needed to excel in the rapidly growing field of cloud data engineering. As the leading institute for Azure Data Engineer Course In Bangalore, we offer comprehensive, hands-on training designed to meet the demands of today’s data-driven organizations.
Our Azure Data Engineer Training Bangalore program covers every aspect of the Azure Data Engineer Syllabus, ensuring that students receive in-depth knowledge of data architecture, data processing, and data storage on Microsoft Azure. Whether you prefer attending classes in-person or via Azure Data Engineer Online Training, Radical Technologies provides flexible learning options to suit your needs.
Our Azure Data Engineering Training is renowned for its practical, real-world approach. Students have access to an industry-leading Azure Data Engineer Bootcamp, which combines theory and hands-on labs to ensure they are fully prepared for their certification exams. The Microsoft Azure Data Engineer Training is tailored to cover all key topics, from data integration to security, and is led by experienced professionals who are experts in their field.
For professionals and organizations seeking Azure Data Engineering Corporate Training, we offer tailored courses that address specific business needs. Our Azure Data Engineering Corporate Training Course ensures that teams gain practical experience in building scalable, secure, and efficient data solutions on Azure.
At Radical Technologies, our Azure Data Engineer Courses are structured to ensure that both beginners and experienced professionals alike can enhance their knowledge. The Azure Data Engineer Certification Training offered here equips students with the skills and credentials needed to stand out in a competitive job market.
Our institute also offers the Azure Data Engineer Full Course, which provides a comprehensive pathway for mastering Azure Data Engineering concepts and techniques. We take pride in being one of the top Azure Data Engineer Institutes in Bangalore, with a proven track record of helping students achieve their Azure Data Engineering Certification.
Whether you are looking for Azure Data Engineer Training Online or prefer our in-person classes in Bangalore, Radical Technologies is your trusted partner for career advancement in data engineering. Join us today to enroll in the Best Azure Data Engineer Course and kick-start your journey towards becoming a certified data engineer.
(Our Team will call you to discuss the Fees)
(Our Team will call you to discuss the Fees)