---
title: SC-200 Labs
description: "Lab exercises for SC-200: Microsoft Security Operations Analyst. Includes Applied Skills, Microsoft Learn, and Microsoft GitHub labs."
---

**Applied Skills:**

:::note
Applied Skills on Microsoft Learn are practical, hands-on exercises designed to help users build and demonstrate proficiency in specific technologies or tasks. These small labs focus on solving real-world scenarios, reinforcing learning through direct application of skills, and preparing users for industry roles or certifications.
:::

### Defend against cyberthreats with Microsoft Defender XDR

### Implement information protection and data loss prevention by using Microsoft Purview

**Microsoft Learn:**

:::note
Microsoft Learn Sandboxes require you to bring in your own subscription.
:::

### Set up the Sentinel hunting environment

### Hunt for threats using Microsoft Sentinel

### Detect threats with Microsoft Sentinel analytics

### Create a playbook in Microsoft Sentinel

### Set up the Sentinel incident management environment

### Investigate an incident in Microsoft Sentinel

### Install Microsoft Sentinel Content Hub solutions and data connectors

### Perform a simulated attack to validate analytic and automation rules

### Connect Microsoft Sentinel to Microsoft Defender XDR

### Investigate and respond with Security Copilot

### Query and visualize data in Microsoft Sentinel

### Deploy Microsoft Sentinel to the Microsoft Defender portal

### Harden and monitor endpoints with security policies

### Explore Microsoft Defender for Cloud (interactive guide)

### Investigate a Microsoft Purview Data Loss Prevention alert

### Conduct a Microsoft Purview eDiscovery search

### Investigate insider risk alerts in Microsoft Purview

### Connect to resources with Kusto Query Language

### Return rows with the Kusto Query Language take operator

### Enable a sign-in risk policy in Microsoft Entra ID Protection

### Configure a multifactor authentication registration policy

**Microsoft GitHub:**

:::note
Microsoft GitHub labs are series of labs designed to be used in Microsoft Instructor Lead Trainings delivered by Microsoft Certified Trainers where participants also have access to the environment to perform them. This means that for everyone else, it is necessary to bring your own environment to go through them.
:::

### Explore Microsoft Defender XDR

### Explore Microsoft Security Copilot

### Explore Microsoft Purview Audit logs

### Deploy Microsoft Defender for Endpoint

### Mitigate Attacks with Microsoft Defender for Endpoint

### Create queries for Microsoft Sentinel using Kusto Query Language (KQL)

### Configure your Microsoft Sentinel environment

### Connect data to Microsoft Sentinel using data connectors

### Connect Windows devices to Microsoft Sentinel using data connectors

### Connect Linux hosts to Microsoft Sentinel using data connectors

### Connect Defender XDR to Microsoft Sentinel using data connectors

### Create a Playbook in Microsoft Sentinel

### Create a Scheduled Query from a template

### Explore Entity Behavior Analytics

### Prepare to perform simulated attacks

### Conduct attacks

### Create Detections

### Investigate Incidents

### Deploy ASIM parsers

### Create workbooks

### Use Repositories in Microsoft Sentinel

### Perform Threat Hunting with Microsoft Sentinel in the Microsoft Defender portal

### Threat Hunting using Data lake Notebooks in Microsoft Sentinel