Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Udemy

Microsoft Security Copilot Hands On Course with Simulations

via Udemy

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
Learn how to expertly administer Microsoft Security Copilot with hands on experience!

What you'll learn:
  • Learn the concepts and perform hands on activities needed to master Microsoft Security Copilot
  • Gain a tremendous amount of knowledge involving Microsoft Security Copilot
  • Learn using hands on simulations on how Microsoft Security Copilot
  • Learn how to set up your own test lab for practicing the concepts!

We really hope you'll agree, this training is way more than the average course on Udemy!

Have access to the following:

  • Training from an instructor of over 20 years who has trained thousands of people and also a Microsoft Certified Trainer

  • Lecture that explains the concepts in an easy to learn method for someone that is just starting out with this material

  • Instructor led hands on and simulations to practice that can be followed even if you have little to no experience

TOPICS COVERED INCLUDING HANDS ON LECTURE AND PRACTICE TUTORIALS:

Introduction

  • Welcome to the course!

  • Understanding the Microsoft 365 and Azure Environment

  • A Solid Foundation of Active Directory Domains

  • A Solid Foundation of RAS, DMZ, and Virtualization

  • A Solid Foundation of the Microsoft Cloud Services

  • DON'T SKIP: Using Assignments in the course

  • Questions for John Christopher

  • Certificate of Completion

Setting up for hands on

  • DONT SKIP: Before beginning your account setup

  • Creating a trial Microsoft 365/Azure Account

Understanding Microsoft Security Copilot and basic security concepts

  • What Microsoft Security Copilot (MSC) is and how it works

  • Core components and architecture

  • How Copilot uses security signals and context

  • Common use cases: incident response, threat hunting, posture management

  • What is Defense in Depth?

  • Understanding the Zero-Trust model

Concepts involving Microsoft Defender, Microsoft Purview, and Microsoft Sentinel

  • Understanding Microsoft Security Copilots connections with various services

  • Introduction to the Microsoft 365 Defender services

  • Understanding the concepts of extended detection and response (XDR)

  • Understanding the basics of Microsoft Defender for Cloud

  • Common Vulnerabilities and Exposures (CVEs)

  • Basic purposes of using Microsoft Sentinel

  • Setup a log analytics workspace for using Microsoft Sentinel

  • Working with Sentinel log types, log retention and data storage

  • Understanding data sources with Microsoft Sentinel

  • Using the MITRE ATT&CK matrix for analyzing attack vectors

  • Connecting to data sources with Microsoft Sentinel

Prerequisites and Basics for using Microsoft Security Copilot

  • What are Security compute units (SCUs)

  • Looking at the latest pricing for Security compute units (SCUs)

  • Warning before allocating Security compute units (SCUs)

  • Allocating Security compute units (SCUs) in Azure

Exploring the User Interface

  • Owner Settings and Role Assignments

  • Concepts of Prompts, Promptbooks, Roles and Plugins

  • Controlling Plugin access

  • Writing effective prompts in Microsoft Security Copilot

  • Monitoring Security Computer Unit (SCU) usage

Incident Response with Security Copilot

  • Setting up sample alerts for querying

  • Using a Prompt to investigate an incident involving a VM

  • Using a Prompt to investigate an incident involving Azure Storage

  • Incident investigation of a VM using a Promptbook

  • Incident investigation of Azure Storage using a Promptbook

Analysis and Intelligence Gathering with Security Copilot

  • Getting a script for Microsoft Security Copilot (MSC) to analyze

  • Using MSC to analyze a malicious script

  • Creating data in Microsoft Entra ID to analyze

  • Analyzing data from Entra ID using Microsoft Security Copilot (MSC)

  • Perform a Microsoft User Analysis on an Entra user

  • Uploading and analyzing files in Microsoft Security Copilot (MSC)

Using Data Loss Prevention and Security Copilot to prevent data leakage

  • What is data loss prevention (DLP) in Microsoft 365 Defender

  • Working with roles and permissions in regard to data loss prevention (DLP)

  • Using Microsoft Security Copilot to create step by step instructions for DLP

  • Implementing data loss prevention policies

  • How Adaptive Protection works in data loss prevention

  • Policy and rule precedence in Data Loss Prevention

  • Leveraging the Microsoft Purview plugin to look up DLP alerts

Non-Microsoft and Custom Plugins

  • Intro to Non-Microsoft Plugins

  • Shodan InternetDB Plugin

  • CIRCL Hash Lookup

  • Adding a custom plugin


Taught by

John Christopher | 500,000+ enrollments

Reviews

4.7 rating at Udemy based on 37 ratings

Start your review of Microsoft Security Copilot Hands On Course with Simulations

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.