<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.de/css/xml-course.xsl"?><course productid="32843" language="en" source="https://portal.flane.de/sap_esi/en/xml-course/masterclass-hybsec" lastchanged="2026-03-18T11:03:12+01:00" parent="https://portal.flane.de/sap_esi/en/xml-courses"><title>Master Class: Microsoft Defender and Microsoft Sentinel for Hybrid Cloud</title><productcode>HYBSEC</productcode><vendorcode>MT</vendorcode><vendorname>Master Class</vendorname><fullproductcode>MT-HYBSEC</fullproductcode><version>1.0</version><audience>&lt;p&gt;Administrators with experience of at least 5 years in administering Windows Active Directory Domain Services, Azure Active Directory and Azure resources.&lt;/p&gt;</audience><contents>&lt;h5&gt;Defender for Cloud&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Overview of Defender for Cloud&lt;/li&gt;&lt;li&gt;Prerequisites and implementation&lt;/li&gt;&lt;li&gt;Securing Azure workloads&lt;/li&gt;&lt;li&gt;Securing on-premises workloads&lt;/li&gt;&lt;li&gt;Cloud Security Posture Management overview&lt;/li&gt;&lt;li&gt;Use automation to respond to alerts&lt;/li&gt;&lt;li&gt;Mastering Azure Policy guest configuration&lt;/li&gt;&lt;/ul&gt;
&lt;h5&gt;Defender for Identity&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Overview of MS Defender for Identity&lt;/li&gt;&lt;li&gt;Planning MS Defender for Identity Deployment&lt;br/&gt;(Architecture, Prerequisites)+&lt;/li&gt;&lt;li&gt;Implement Defender for Identity&lt;/li&gt;&lt;li&gt;Investigate alerts/detections
&lt;ul&gt;
&lt;li&gt;Reconnaissance Alerts&lt;/li&gt;&lt;li&gt;Compromised Credential Alerts&lt;/li&gt;&lt;li&gt;Lateral Movement Alerts&lt;/li&gt;&lt;li&gt;and some more&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;KQL Primer&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Basic operators for querying tables and formatting output&lt;/li&gt;&lt;li&gt;Working with variables&lt;/li&gt;&lt;li&gt;Advance operators and functions
&lt;ul&gt;
&lt;li&gt;Extending tables&lt;/li&gt;&lt;li&gt;Querying and filtering property bags&lt;/li&gt;&lt;li&gt;Aggregate records and&lt;/li&gt;&lt;li&gt;Create custom functions&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;working with multiple tables and external data&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Microsoft Sentinel&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Data collectors Implementation&lt;/li&gt;&lt;li&gt;Creating Analytic rules&lt;/li&gt;&lt;li&gt;Use automation to respond to Incidents&lt;/li&gt;&lt;li&gt;Automatically enrich incident information&lt;/li&gt;&lt;li&gt;Investigate Incidents&lt;/li&gt;&lt;li&gt;Perform threat hunting&lt;/li&gt;&lt;li&gt;Create workbooks&lt;/li&gt;&lt;li&gt;Investigate with UEBA&lt;/li&gt;&lt;/ul&gt;</contents><audience_plain>Administrators with experience of at least 5 years in administering Windows Active Directory Domain Services, Azure Active Directory and Azure resources.</audience_plain><contents_plain>Defender for Cloud


- Overview of Defender for Cloud
- Prerequisites and implementation
- Securing Azure workloads
- Securing on-premises workloads
- Cloud Security Posture Management overview
- Use automation to respond to alerts
- Mastering Azure Policy guest configuration

Defender for Identity


- Overview of MS Defender for Identity
- Planning MS Defender for Identity Deployment
(Architecture, Prerequisites)+
- Implement Defender for Identity
- Investigate alerts/detections

- Reconnaissance Alerts
- Compromised Credential Alerts
- Lateral Movement Alerts
- and some more
KQL Primer


- Basic operators for querying tables and formatting output
- Working with variables
- Advance operators and functions

- Extending tables
- Querying and filtering property bags
- Aggregate records and
- Create custom functions
- working with multiple tables and external data
Microsoft Sentinel


- Data collectors Implementation
- Creating Analytic rules
- Use automation to respond to Incidents
- Automatically enrich incident information
- Investigate Incidents
- Perform threat hunting
- Create workbooks
- Investigate with UEBA</contents_plain><duration unit="d" days="5">5 days</duration><pricelist><price country="DE" currency="EUR">5990.00</price><price country="AT" currency="EUR">5990.00</price><price country="SE" currency="EUR">5990.00</price><price country="SI" currency="EUR">5990.00</price><price country="IT" currency="EUR">5990.00</price><price country="NL" currency="EUR">5990.00</price><price country="US" currency="USD">6520.00</price><price country="IN" currency="USD">999.00</price><price country="GB" currency="GBP">4980.00</price><price country="CH" currency="CHF">4780.00</price><price country="CA" currency="CAD">9000.00</price></pricelist><miles/></course>