Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

MS Sentinel: Investigate

Premium room

Investigate and manage incidents in Microsoft Sentinel.

medium

90 min

451

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Our Microsoft Sentinel journey continues. Let's take a quick snapshot of where we are in this journey and review the milestones we've passed in the previous rooms:

  • Onboarding - Microsoft Sentinel concepts, planning and initial deployment
  • Configuration - Installing Content hub solutions
  • Configuration - Connecting Data connectors
  • Threat detection - Analytics rules enabled

Learning Objectives

In this room, we will look into incident investigation and management concepts to see how we can easily manage security incidents in Microsoft Sentinel.

  • Firstly, we'll introduce incident tools and features in Microsoft Sentinel
  • Then, investigate sample incidents
  • Finally, we'll see how we can manage incidents, hand them over, or escalate them a higher level security team

Prerequisites

A good understanding of previous Sentinel rooms is recommended to fully leverage the benefits of this room:

Answer the questions below
Let's go!