M365 Security Administration: Complete Course

📚 Course 7 of 8 · Advanced

Microsoft 365 Defender

M365 Security Administration
Complete Administration Course

Master Microsoft 365 security end to end — protecting email with Defender for Office 365; hardening identity with Entra ID Protection; hunting threats with Threat Explorer; running attack simulations; and monitoring your tenant with Secure Score, audit logs, and Microsoft Sentinel integration.

🔴 Advanced📦 6 Modules⏱ ~7 Hours🖥️ Portal + PowerShell + KQL🎯 SC-200 Aligned
SC-200

🎯 Aligned to SC-200: Microsoft Security Operations Analyst

Every module maps to an SC-200 exam skill area, with an exam alignment section and 5-question mock test in every module.

Mitigate Threats using Microsoft 365 Defender
Defender for Office 365
Identity & Access Threat Detection
Threat Hunting & Investigation
Cloud Security Posture Management

What You’ll Learn

By the end of this course you will be able to protect a Microsoft 365 tenant end to end and investigate security incidents like an analyst

Navigate the Microsoft 365 Defender portal (security.microsoft.com) and understand all workloads
Interpret and act on Microsoft Secure Score recommendations to improve posture
Configure Exchange Online Protection anti-spam, anti-malware, and anti-phishing policies
Apply preset security policies (Standard and Strict protection) across the tenant
Deploy Safe Links and Safe Attachments to protect users from malicious URLs and files
Manage quarantine — review, release, block, and report quarantined messages
Configure Entra ID Protection user risk and sign-in risk policies
Build risk-based Conditional Access policies that trigger on risky sign-ins
Investigate risky users, dismiss risk, and confirm compromise in the Identity Protection dashboard
Use Threat Explorer to trace email threats, analyse campaigns, and take remediation actions
Manage the Microsoft 365 Defender Incident queue — triage, investigate, and close incidents
Run Attack Simulation Training campaigns and assign remedial training automatically
Search the Unified Audit Log and export audit events for compliance and forensics
Write basic KQL queries for Advanced Hunting and integrate with Microsoft Sentinel

📋 Prerequisites

  • Complete the Intune & Endpoint Management course — this course builds on device compliance, Conditional Access, and Defender for Endpoint integration covered there
  • Solid understanding of Exchange Online mail flow, transport rules, and connector concepts
  • Familiarity with Entra ID Conditional Access policy structure (covered in the Entra ID course)
  • Optional: An SC-200 trial sandbox or Microsoft 365 E5 trial tenant to follow along hands-on

Course Modules

Six modules covering every area of Microsoft 365 security administration — SC-200 aligned with a mock test in every module. All modules freely accessible.

01
SC-200 Aligned · 5 Topics

Microsoft 365 Defender Portal & Secure Score

The Defender portal (security.microsoft.com), workload integration, Microsoft Secure Score interpretation, improvement actions, score history, and tenant comparison.


02
SC-200 Aligned · 6 Topics

Defender for Office 365 — EOP, Anti-Spam & Anti-Phishing

Exchange Online Protection as the baseline layer, anti-spam policies, anti-malware policies, anti-phishing (spoof intelligence, DMARC, DKIM), and preset security policies.


03
SC-200 Aligned · 5 Topics

Safe Links, Safe Attachments & Quarantine Management

Safe Links time-of-click URL protection, Safe Attachments detonation modes, per-workload policies (SharePoint, OneDrive, Teams), quarantine review and release workflows.


04
SC-200 Aligned · 5 Topics

Identity Protection & Risk-Based Conditional Access

Entra ID Protection sign-in risk and user risk policies, risk detections (impossible travel, anonymous IP, leaked credentials), risk-based Conditional Access, risky user investigation and remediation.


05
SC-200 Aligned · 6 Topics

Threat Explorer, Alerts & Incident Investigation

Threat Explorer vs Real-time Detections, email entity page investigation, alert policies, the Microsoft 365 Defender incident queue, campaign views, and end-to-end email investigation workflow.


06
SC-200 Aligned · 5 Topics

Attack Simulation Training, Audit Logs & Sentinel Integration

Attack Simulation Training campaign types, payload creation, training assignment, Unified Audit Log search and export, Advanced Hunting with KQL, and Microsoft Sentinel M365 connector basics.

Ready to Start?

Begin with Module 1 — the Microsoft 365 Defender portal and Secure Score — and work through each module in order. Every module includes SC-200 exam-style questions to prepare you for the certification.

Begin Module 1: Defender Portal & Secure Score →