Course Overview
Microsoft Sentinel Specialist equips professionals with the skills to deploy and operate a cloud-native SIEM and SOAR platform using Microsoft Sentinel. The course focuses on real-world SOC use cases including log ingestion, detection engineering, and automated response.
Through mentor-led sessions and hands-on labs, learners will write KQL queries, configure analytics rules, build workbooks, and integrate threat intelligence feeds. The programme also explores automation playbooks to streamline incident response and reduce manual effort.
By the end of the course, participants will be able to manage security operations using Sentinel, detect and investigate threats, and automate response workflows. This course is ideal for professionals working in modern cloud-based SOC environments.
Hands-On Learning
Deploy Sentinel, write KQL queries, create analytics rules, and automate responses in lab-based SOC scenarios.
Mentor-Led Sessions
Mentors guide SIEM configuration, KQL optimisation, and incident investigation techniques
Career-Ready Skills
Develop cloud SIEM, detection engineering, and SOAR automation capabilities.
Learning Outcomes
Deploy and configure Microsoft Sentinel
Write and optimise KQL queries
Implement analytics rules and alerts
Automate response with playbooks
Integrate threat intelligence feeds
Investigate and respond to incidents
Prerequisites
Basic understanding of cybersecurity concepts
Familiarity with cloud platforms (Azure preferred)
Basic knowledge of logs and monitoring
Detailed Syllabus
Step-by-step learning journey from basics to professional practice
Topics Covered
- Course orientation and Sentinel overview
- Lab environment setup
- Introduction to cloud SIEM concepts
Skills You'll Gain
Master these in-demand skills through hands-on practice
Career Progression
A clear view of the roles this programme supports, what typically comes next, and where learners progress over time
Ways to Learn
Choose the learning format that works best for you and your team
Live Online
Instructor-Led Training
Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.
- Live instructor interaction (real-time)
- Trainer-led walkthroughs and real examples
- Guided resources and session notes provided
- Structured Q&A and practical discussion
Price per person
Group enrolments and early planning options available.
All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.
Prefer a Faster, Personalised Route into IT?
Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.
"Many learners choose 1-to-1 when they want understanding, not memorisation."
Exam & Certification Information
Everything you need to know about the certification exams
Important Information
You will receive an Xcademia certificate of completion based on participation and successful completion of labs and scenario simulations.
Credential
Certificate of Completion
On successful completion of Microsoft Sentinel Specialist, learners receive an Xcademia Certificate of Completion. This standalone certificate is issued directly by Xcademia and is aligned with globally recognised frameworks and best practices.
Frequently Asked Questions
Everything you need to know about this course
It is a cloud-native SIEM and SOAR platform for security operations.
Ready to Start Your Learning Journey?
Take the next step in your professional development