Overview

The Microsoft Sentinel Training at Zoom Technologies is a complete, hands-on program that takes you from cloud computing fundamentals to confident operation of Microsoft Sentinel — Azure's cloud-native SIEM and SOAR platform. Starting with Azure essentials, networking, and Sentinel's data-flow architecture, you'll configure every major capability live in your own Azure tenant: Log Analytics workspaces, RBAC, data connectors, AMA and Data Collection Rules, on-premises onboarding through Azure Arc, Kusto Query Language, analytic rules across all five rule types, incident investigation, Logic Apps playbooks, workbooks, watchlists, and ingestion cost control. By the end, you'll be able to deploy, monitor, detect, automate, and optimise a production Microsoft Sentinel deployment in a real enterprise environment — with a curriculum closely mapped to the SC-200 certification exam objectives. 

Curriculum

Microsoft Sentinel Training — Azure Cloud SIEM & SOAR

2 Week

Module 1: Cloud Computing Fundamentals

  • What is cloud computing
  • Cloud service models: IaaS, PaaS, SaaS 
  • Public, private, hybrid and community cloud 
  • Why cloud security matters 
  • Security challenges in cloud environments 

Module 2: Azure Fundamentals

  • What is Azure 
  • Shared responsibility model 
  • Azure subscription types 
  • Creating your Azure subscription 
  • Azure resource hierarchy 
  • Resources, resource groups and Role-Based Access Control (RBAC) 
  • Creating and managing Azure resource groups 

Module 3: Azure Networking

  • Overview of Azure networking and its components
  • Implementing and managing Azure Virtual Networks (VNet) 
  • Configuring VNets, managing IP and subnets 
  • Creating and managing Azure Virtual Machines 

Module 4: Microsoft Sentinel Architecture

  • What is Microsoft Sentinel 
  • Sentinel as SaaS SIEM vs SOAR — understanding the differences 
  • Sentinel architecture and components 
  • How data flows in Microsoft Sentinel 

Module 5: Deploying & Managing Sentinel

  • Deployment prerequisites for Sentinel 
  • Creating a Log Analytics Workspace 
  • Creating a Sentinel workspace 
  • Azure RBAC and Sentinel RBAC 
  • Configuring Azure RBAC for Sentinel 

Module 6: Data Connectors

  • Overview of data connectors 
  • Typical data sources for a SIEM 
  • Working with the Content Hub 
  • Ingesting threat intelligence and verifying ingestion 
  • Ingesting Entra ID logs and verifying ingestion 
  • AMA and Data Collection Rules (DCR) 
  • Ingesting Windows Security Event logs with AMA and DCR 
  • Ingesting Linux Syslog logs with AMA and DCR 

Module 7: On-Boarding On-Premises Machines

  • What is Azure Arc 
  • Azure Arc roles 
  • Prerequisites for Azure Arc 
  • On-boarding on-premises Windows machines 
  • On-boarding on-premises Linux machines 
  • On-boarding on-premises virtual machines 

Module 8: Ingesting On-Premises Logs

  • Ingesting Windows Security Event logs with AMA 
  • Verifying Windows Security Event log ingestion 
  • Ingesting Linux Syslog logs with AMA 
  • Verifying Linux Syslog log ingestion 

Module 9: Kusto Query Language (KQL)

  • Introduction to KQL and Log Analytics 
  • Writing basic KQL queries 
  • Advanced KQL: joins, aggregations and time series analysis 
  • Creating custom dashboards with KQL in Sentinel Logs 
  • Hands-on practice: KQL for threat investigation 

Module 10: Threat Hunting & Investigation

  • How Sentinel detects and correlates security incidents 
  • Investigating alerts and incidents in Sentinel 
  • Managing false positives and incident prioritisation 
  • Hands-on incident investigation walkthrough 

Module 11: Analytic Rules & Threat Management

  • Analytic rules — concepts and rule types 
  • Configuring analytic rules 
  • Scheduled analytic rules 
  • Scheduled analytic rules — Entra ID 
  • Scheduled analytic rules — Windows Security Events 
  • Near-Real-Time (NRT) rules 
  • NRT rules — Windows Security Events 
  • Fusion — multi-stage attack detection 
  • ML Behavior Analytics 
  • Threat Intelligence rules 
  • Microsoft Security rules 

Module 12: Automation & SOAR

  • Automation capabilities in Sentinel 
  • Automation rules and how to build them 
  • Playbooks 
  • Automation rules vs playbooks 
  • Azure Logic Apps 
  • Building playbooks with Azure Logic Apps 

Module 13: Workbooks

  • Workbooks in Sentinel 
  • Creating workbooks 
  • Creating a customised dashboard in Azure 

Module 14: Watchlists

  • Watchlists in Sentinel 
  • Creating watchlists 
  • Integrating watchlists with analytic rules 

Module 15: Cost Optimisation

  • Pricing models 
  • Commitment tiers 
  • Log types 
  • Archive and restore logs

Module 16: AI Based SOC Operation

Course Schedule

Course Schedule

Microsoft Sentinel Training — Azure Cloud SIEM & SOAR

30 Sep 2026

04:00 PM to 06:00 PM

(IST - GMT +05:30)

2 Weeks

2 Hrs/Day

Sunday off

Online

For Online Training Students

  • Instructions will be Provided to do Lab Practicals with your PC at Home
  • You will receive a link to your email in an hour after the class from Webex to Download the Recorded Videos..
  • All our study materials are available for free access on our online portal for registered students


Imp. Note

  • Fees once paid will not be refunded or adjusted against other courses / batches / students under any circumstances whatsoever.
  • Organization reserves the right to expel any student during the training period.
  • In case, a student fails to attend the given batch the amount given will be forfeited against his / her name.


FAQ'S

Is Microsoft Sentinel the same as Azure Sentinel?

Yes. Azure Sentinel was renamed Microsoft Sentinel. The product is the same; you will still see the older name in many job listings and documentation.

What is Microsoft Sentinel?

Microsoft Sentinel is Azure's cloud-native SIEM and SOAR platform. It collects security data across cloud and on-premises sources, detects threats using analytic rules, and automates response through playbooks — all delivered as a service with no infrastructure to maintain.

Is this a certification course?

This is a hands-on skills course focused on operating Microsoft Sentinel in real environments, not an exam-prep program. You receive a Zoom Technologies course certificate on completion. Candidates who later choose to pursue a Microsoft certification will find the practical experience useful preparation, but the course is not structured around any exam syllabus.

Do I need Azure knowledge before joining this course?

No. The course begins with cloud computing and Azure fundamentals — subscriptions, resource groups, RBAC, virtual networks and virtual machines — before moving into Sentinel.

Do I need my own Azure subscription for the labs?

Yes, and creating one is covered in Module 2. An Azure free trial or pay-as-you-go subscription is sufficient. Azure consumption charges are billed by Microsoft and are not included in the course fee.

Will I learn KQL from scratch?

Yes. Module 9 starts with KQL basics and progresses to joins, aggregations, time-series analysis and custom dashboards, with hands-on threat-investigation practice.

Does the course cover on-premises servers, or only cloud?

Both. Modules 7 and 8 cover Azure Arc onboarding for on-premises Windows, Linux and virtual machines, then ingesting Windows Security Events and Linux Syslog through the Azure Monitor Agent.

What is the difference between automation rules and playbooks?

Automation rules handle incident-level orchestration inside Sentinel — assignment, tagging, closing and triggering. Playbooks are Logic Apps workflows that perform the actual response actions. Module 12 covers both and when to use each.

Does the course cover Sentinel costs?

Yes. Module 15 covers pricing models, commitment tiers, log types and archive/restore — the ingestion cost controls that determine whether a Sentinel deployment stays affordable in production.

How long is the Microsoft Sentinel course?

Two weeks, 2 hours per day, Sunday off, delivered online with classroom options available.

What are the Microsoft Sentinel training fees in India?

The course is offered at an introductory price of INR 9,900 (reduced from INR 15,000), plus 18% GST.

Are classes recorded?

Yes. A recording download link is emailed within an hour of each session, and study materials are free on the student portal for registered students.

Will I get a certificate and placement assistance?

Yes. A Zoom Technologies course certificate is issued on completion, and placement assistance is included.
Microsoft 365 Preview this course
Duration : 2 Weeks
Mode Of Training : Online / Classroom
Placement Assistance : Yes
Certificate : Yes

Introductory Limited Period Offer

INR 15,000

Price: 9,900

All prices are subject to an 18% Goods and Service Tax (GST) Charge. Rate quoted in U.S. dollars subject to change according to Foreign Exchange rates.

Once you make the payment, kindly contact our course counsellor at priya@zoomgroup.com to schedule the course as per your convenience from the available slots.