SC-200 Lab 4 – Microsoft Defender for Endpoint

Microsoft Security Operations Analyst — Lab 4

Lab 4 – Microsoft Defender for Endpoint

SC-200: Microsoft Security Operations Analyst

Overview


Deployed and configured Microsoft Defender for Endpoint, onboarded a Windows device, configured roles and device groups, then ran a simulated backdoor attack and investigated the resulting multi-stage incident. Supplemented with Microsoft Learn exercises covering endpoint hardening, Defender for Cloud, and Entra ID Protection policies.

Deploy Microsoft Defender for Endpoint: initialize, onboard device, configure role and device groups
Lab architecture diagram — Source: MicrosoftLearning/SC-200T00A-Microsoft-Security-Operations-Analyst, MIT License

Tasks Completed


Mitigate Attacks with Microsoft Defender for Endpoint: simulated attack flow and multi-stage incident review
Lab architecture diagram — Source: MicrosoftLearning/SC-200T00A-Microsoft-Security-Operations-Analyst, MIT License

Environment: Employer-provided Azure subscription (resources deleted after lab) and Microsoft 365 E5 test tenant.

Source Material


Completed using Exercise 1: Deploy Microsoft Defender for Endpoint and Exercise 2: Mitigate Attacks from the SC-200T00A MicrosoftLearning GitHub repository; and Microsoft Learn exercises Harden and Monitor Endpoints, Defender for Cloud Interactive Guide, Enable Sign-In Risk Policy, and Configure MFA Registration Policy. Completed in an employer-provided Azure subscription and a personal Microsoft 365 E5 test tenant.