Become a Microsoft 365 Defender Ninja

Published Oct 19 2020 08:53 AM 55.3K Views
Microsoft

Microsoft 365 Defender, part of Microsoft’s XDR solution, leverages the Microsoft 365 security portfolio to automatically analyze threat data across domains, building a complete picture of each attack in a single dashboard. This Ninja blog covers the features and functions of Microsoft 365 Defender – everything that goes across the workloads, but not the individual workloads themselves. The content is structured into three different knowledge levels, with multiple modules: Fundamentals, Intermediate, and Expert.

 

In addition, after each level, we offer you a knowledge check based on the training material you have just finished! Since there’s a lot of content, the goal of the knowledge checks is to help ensure understanding of the key concepts that were covered. Lastly, there’ll be a fun certificate issued at the end of the training: Disclaimer: This is not an official Microsoft certification and only acts as a way of recognizing your participation in this training content.

 

I want to give kudos to my colleagues: @Sarahzin for letting me copy from her MCAS Ninja training, @DanEdwards for helping me automate the certificate distribution and @Tali Ash for helping me pull the questions together! Thank you!

 

We will keep updating this training on a regular basis and highlight new resources.

 

If you already did the training, you can focus on the latest updates (January update)

 

Table of Contents

Security Operations Fundamentals

Module 1. Technical overview

Module 2. Getting started

Module 3. Investigation – Incident

Module 4. Advanced hunting

Module 5. Self-healing

Module 6. Community (blogs, webinars, GitHub)

 

Security Operations Intermediate

Module 1. Architecture

Module 2. Investigation

Module 3. Advanced hunting

Module 4. Automated investigation and remediation

Module 6. Self-healing

Module 5. Build your own lab

Module 7. Reporting

 

Security Operations Expert

Module 1. Incidents

Module 2. Advanced hunting

Module 3. APIs, custom reports, SIEM & other integrations

 

Legend:

vid.png Product videos

webcast.png Webcast recordings

TechCommunity.png Tech Community

docs.png Docs on Microsoft

blogs.png Blogs on Microsoft

GitHub.png GitHub

⤴ External

InteractiveGuides.png Interactive guides

 

 

Security Operations Fundamentals

Module 1. Technical overview

Module 2. Getting started

Module 3. Investigation – Incident

Module 4. Advanced hunting

Module 5. Self-healing

Module 6. Community (blogs, webinars, GitHub)

 

> Ready for the Fundamentals Knowledge Check

 

Security Operations Intermediate

Module 1.  Architecture

Module 2. Investigation

Module 3. Advanced hunting

Module 4. Automated investigation and remediation

Module 6. Self-healing

Module 5. Build your own lab

Module 7. Reporting

 

> Ready for the Intermediate Knowledge Check

 

Security Operations Expert

Module 1. Incidents

Module 2. Advanced hunting

Module 3. APIs, custom reports, SIEM & other integrations

 

> Ready for the Expert Knowledge Check

 

Once you’ve finished the training and the knowledge checks, please click here to request your certificate (you'll see it in your inbox within 3-5 business days.

24 Comments
Valued Contributor

Thank you for sharing, for the top part when there are Modules, when click on the link it will open new tab. If possible please make it like navigate inside this page (instead of opening new tab), while for other links opening new tab is fine because it is new website.

Microsoft

@Reza_Ameri-Archived  weird, it should open in the same page. Thanks for the info, I will check again

Trusted Contributor

Thanks! And @Reza_Ameri-Archived it open in the same page for me.

Microsoft

@Kam & @Reza_Ameri-Archived  I just fixed it quickly :) Thanks again!! 

Valued Contributor

@Heike Ritter 

Please consider add these contents in Microsoft Learn platform too.

Microsoft

Great work @Heike Ritter !

Occasional Contributor

I cannot wait to go through the security modules. Awesome job!

Microsoft

Hi Heike,
great Learning Stuff for my customers and an excellent detailed overview!!
thanks

Contributor

Awesome post. put it on my ToDo learn list.

Thans for this great post @Heike Ritter !

Frequent Visitor

Great resource!  Thanks for sharing.

New Contributor

Thanks @Heike Ritter for sharing your knowledge with us. Great stuff and well-detailed.:smile:

Honored Contributor

Great blog post, lots of useful information, bookmarking this page for future reference :)

Occasional Visitor

Great resource!  Thanks for sharing too.:clapping_hands:

New Contributor

awesome resources @Heike Ritter 

Microsoft

I am a new starter and this is great! 

Senior Member

Very interesting and useful.
Thank you @Heike Ritter

Regular Visitor

Thanks for the training, I have successfully passed the evaluation, I share my certificate: DM365 Defender.PNG

Microsoft

Very good . Thank you

Completed, I'm a Ninja in Microsoft 365 Defender.

Occasional Visitor

Hi,

Do we have an estimation of the time requested to complete this training ?

Thanks in advance

Regular Visitor

I found this wonderful learning content on MSLearn SC-200 Microsoft Defender for Endpoints. I understood the features of Microsoft Defender. I'll recommend this Ninja contents to my colleagues. Thanks,

Occasional Contributor

Thanks for providing this great ninja training resource @Heike Ritter 

 

The last section "Security Operations Expert" provides links to the same documentation for "Prioritze incidents", "Manage incidents" and "Report false positives/negatives" that is already coverd in the "Security Operations Intermediate" section (see screenshot below).

I am not sure if this was intentional but I guess it doesn't hurt to read about it twice :D

 

ms-defender-ninja.jpg

Occasional Visitor

There are some overlapping materials along the learning journey.

Co-Authors
Version history
Last update:
‎Mar 08 2021 09:44 AM
Updated by: