DefenderTraining path

Training path: SC-200 Security Operations Analyst study plan (Defender XDR and Sentinel)

A stage-by-stage study plan for exam SC-200 (Security Operations Analyst Associate): the current skills-measured domains, the Microsoft Learn paths to follow, hands-on labs and exam-day tips.

SC-200 is the exam for people who live in the Microsoft Defender portal: triaging incidents, hunting with KQL, and building detections and automation in Microsoft Sentinel. It rewards hands-on time far more than memorisation. In this post I'll lay out a realistic study plan: what the exam measures today, which Microsoft Learn paths map to each domain, what to practise in a test tenant, and what to do once you've passed.

Study roadmap: Who it's for → The exam at a glance → Stage 1 → Stage 2 → Stage 3 → Stage 4 → Stage 5 → Stage 6 → Hands-on practice → Exam day → After the examRoadmap of the training path in order: Who it's for; The exam at a glance; Stage 1 (weeks 1–2): KQL foundations; Stage 2 (weeks 3–4): Defender XDR and Defender for Endpoint; Stage 3 (weeks 5–6): The rest of the Defender family; Stage 4 (weeks 7–8): Microsoft Sentinel platform and ingestion; Stage 5 (weeks 9–10): Detections, automation and hunting; Stage 6 (week 11): Review; Hands-on practice; Exam day; After the exam.1Who it's for2The exam at a glanceStage 1weeks 1–2KQL foundationsStage 2weeks 3–4Defender XDRand Defender fo…Stage 3weeks 5–6The rest of theDefender familyStage 4weeks 7–8MicrosoftSentinel platfor…Stage 5weeks 9–10Detections,automation and…Stage 6week 11Review3Hands-on practice4Exam day5After the examStudy roadmap: Who it's for → The exam at a glance → Stage 1 → Stage 2 → Stage 3 → Stage 4 → Stage 5 → Stage 6 → Hands-on practice → Exam day → After the examRoadmap of the training path in order: Who it's for; The exam at a glance; Stage 1 (weeks 1–2): KQL foundations; Stage 2 (weeks 3–4): Defender XDR and Defender for Endpoint; Stage 3 (weeks 5–6): The rest of the Defender family; Stage 4 (weeks 7–8): Microsoft Sentinel platform and ingestion; Stage 5 (weeks 9–10): Detections, automation and hunting; Stage 6 (week 11): Review; Hands-on practice; Exam day; After the exam.1Who it's for2The exam at a glanceStage 1 · weeks 1–2KQL foundationsStage 2 · weeks 3–4Defender XDR and Defender for EndpointStage 3 · weeks 5–6The rest of the Defender familyStage 4 · weeks 7–8Microsoft Sentinel platform and ingestionStage 5 · weeks 9–10Detections, automation and huntingStage 6 · week 11Review3Hands-on practice4Exam day5After the exam
At a glance: how this study path is organised · 6 stages over 11 weeks

Who this path is for (and prerequisites)#

This plan suits endpoint and Microsoft 365 administrators who already touch Defender for Endpoint through Intune and want to move into security operations, as well as SOC analysts on other tooling who are moving to the Microsoft stack. Microsoft's audience profile expects familiarity with Microsoft security, compliance and identity solutions, Microsoft 365, Azure services, AI agents and Copilots, and Windows, Linux and mobile operating systems. You don't need to be a KQL expert before you start, but you should be comfortable reading logs and following an attack across devices, identities and mailboxes.

Practical prerequisites: a tenant you're allowed to break (a trial or lab tenant), an Azure subscription for a Sentinel workspace, and a couple of test Windows devices onboarded to Defender for Endpoint.

The exam at a glance#

ItemDetail
ExamSC-200: Microsoft Security Operations Analyst
Certification earnedMicrosoft Certified: Security Operations Analyst Associate
Time allowed100 minutes, proctored, may include interactive components
Passing score700 or greater
Price165 USD, varies by the country or region where the exam is proctored
RenewalEvery 12 months, free online assessment on Microsoft Learn

The skills measured, as published in Microsoft's study guide (skills measured as of October 21, 2026):

DomainWeight
Manage a security operations environment40–45%
Respond to security incidents35–40%
Perform threat hunting20–25%

Microsoft updates study guides regularly, so re-check the official guide before you book. Two details from the current guide shape how you should study: most questions cover generally available features, though commonly used preview features can appear; and the "manage" domain is the largest, covering Defender XDR settings, Sentinel data ingestion, retention tiers, automation and detection configuration, not just incident response.

Stage-by-stage plan#

Microsoft's official course is SC-200T00-A: Defend against cyberthreats with Microsoft's security operations platform (four days, intermediate). The learning paths below are the self-paced content from that course, so you can follow it without an instructor.

Stage 1: KQL foundations (weeks 1–2)#

Study the learning path Create queries for Microsoft Sentinel using Kusto Query Language (KQL). Then practise daily in Hunting › Advanced hunting in the Defender portal: filter with where, aggregate with summarize, join DeviceProcessEvents to DeviceNetworkEvents, and use the in-portal schema reference to look up columns and action types. The exam asks you to pick the right table for a question, so learn what lives in DeviceInfo, DeviceEvents, EmailEvents, IdentityLogonEvents and CloudAppEvents.

Stage 2: Defender XDR and Defender for Endpoint (weeks 3–4)#

Study Mitigate threats using Microsoft Defender XDR and Mitigate threats using Microsoft Defender for Endpoint. Focus areas from the study guide: incident and alert tuning, suppression and correlation, automated investigation and response levels, automatic attack disruption, device groups and permissions, advanced features, ASR rules, device timelines, live response and investigation packages, and custom detection rules built from hunting queries.

Stage 3: The rest of the Defender family (weeks 5–6)#

Study Mitigate threats using Microsoft Purview, Mitigate threats using Microsoft Defender for Cloud and Mitigate threats using Microsoft Security Copilot. The "respond" domain expects you to investigate threats surfaced by Defender for Office 365, Defender for Cloud Apps, Defender for Identity, Microsoft Entra ID and Defender for Cloud workload protections, plus Purview Audit and Content search in eDiscovery.

Stage 4: Microsoft Sentinel platform and ingestion (weeks 7–8)#

Study Configure your Microsoft Sentinel environment and the course paths on connecting logs to Sentinel. Practise the connectors the guide names: Windows Security Events via AMA with data collection rules, Syslog and CEF via AMA, Azure activity logs through Azure Policy and diagnostic settings, and threat indicators. Understand roles, workbooks, and retention across the Analytics, Data lake and XDR tiers.

Stage 5: Detections, automation and hunting (weeks 9–10)#

Finish with the course paths on detecting and remediating threats and on threat hunting in Sentinel. Build scheduled, near-real-time (NRT), threat intelligence and anomaly rules, automation rules and playbooks, hunting queries, and look at the MITRE ATT&CK coverage view and SOC optimization recommendations. Newer items on the guide include summary rules, KQL jobs in the data lake, hunting graphs and notebooks.

Stage 6: Review (week 11)#

Take Microsoft's free practice assessment, work through the exam sandbox so the interface holds no surprises, and spend the remaining days on whichever domain scored lowest.

Hands-on practice#

  • Incident triage. Run Microsoft's detection test on an onboarded device, then follow the resulting alert into an incident: read the attack story, classify it, assign it, and note which entities were correlated.
  • Hunting to detection. Write a query that finds the test activity, then use Create detection rule. Make sure the query returns Timestamp, ReportId and DeviceId, and try both an hourly and a Continuous (NRT) frequency.
  • Device actions. On a test device, isolate it, run an antivirus scan, collect an investigation package, and open a live response session. Watch each action in the Action center.
  • Defender for Office 365. If your tenant lacks Plan 2, Microsoft offers a 90-day trial through the Defender portal trials hub. Submit a test message as a false positive or false negative and follow the result, then review preset security policies and the configuration analyzer.
  • Sentinel workspace. Microsoft waives charges for the first 10 GB per day ingested into a new workspace for 31 days, which is plenty for a lab. Connect the Defender XDR connector and Azure Activity, create one scheduled and one NRT analytics rule, build a workbook, and wire an automation rule to a playbook.

Tip: keep a lab journal. For every lab, write down the portal path, the roles you needed and what the result looked like. Those notes become your fastest revision material in week 11.

Exam-day tips#

  • Register with a personal Microsoft account. Microsoft warns that exam records tied to a work or school account are lost if you leave that organisation.
  • Budget the 100 minutes. Interactive items take longer than multiple choice, so don't linger on a question you can flag and revisit.
  • If the exam isn't offered in your preferred language, you can request an additional 30 minutes.
  • Read for the product first. Many questions hinge on whether the scenario is Defender XDR or Sentinel, and whether the data is native Defender data or ingested into a workspace.
  • If you don't pass, you can retake after 24 hours; later retakes have longer waiting periods.

After the exam#

Associate certifications expire after one year. Renewal is free: from six months before the expiry date, a Renew button appears on your Learn profile, and you pass a short, open-book, unproctored online assessment that focuses on what changed in the product. You can retake it as often as needed before expiry (with a 24-hour wait after the second attempt), and passing extends the certification one year from the original expiry date.

For next steps, SC-200 pairs naturally with SC-300 (identity and access) if your incidents keep leading back to Microsoft Entra ID, with AZ-500 if you want depth on Azure workload security, and with SC-100 if you move toward security architecture. Check each certification page for its current prerequisites before planning.

References#

Training path

Everything for SC-200 on this site

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)