Skip to main content

Explore core concepts of Entra ID and M365, the threats targeting them, and how to monitor their logs and activity as a SOC analyst.

This module covers the core concepts and security relevance of Microsoft Entra ID and Microsoft 365 in enterprise environments. You'll build a foundational understanding of how these platforms work, then explore the biggest threats and attack techniques that target them. From there, the module moves into monitoring, walking through the key logs, events, and signals from Entra ID, Exchange, SharePoint, and Intune that matter most from a SOC perspective. Throughout, you'll work hands-on with a Splunk instance loaded with real platform logs, putting theory into practice as you investigate suspicious activity across these environments.

What are modules?

A learning pathway is made up of modules, and a module is made of bite-sized rooms (think of a room like a mini security lab).

Hierarchical diagram showing how learning pathways contain modules, which contain individual rooms.