SC-200 Lab 6 – Microsoft Sentinel: Deployment & Data Connectors

Microsoft Security Operations Analyst — Lab 6

Lab 6 – Microsoft Sentinel: Deployment & Data Connectors

SC-200: Microsoft Security Operations Analyst

Overview


Deployed Microsoft Sentinel into Microsoft Defender and established data ingestion from multiple sources — Defender for Cloud, Azure Activity, Windows devices via AMA, Linux hosts via CEF and Syslog, and Defender XDR. Supplemented with Microsoft Learn exercises covering SIEM configuration and the Sentinel-to-Defender XDR integration.

Connect data to Microsoft Sentinel: Sentinel Content Hub connecting Defender for Cloud and Azure Activity connectors
Lab architecture diagram — Source: MicrosoftLearning/SC-200T00A-Microsoft-Security-Operations-Analyst, MIT License

Tasks Completed


Connect Windows devices to Microsoft Sentinel: Azure VM with AMA connector and non-Azure Windows machine via Azure Arc
Lab architecture diagram — Source: MicrosoftLearning/SC-200T00A-Microsoft-Security-Operations-Analyst, MIT License
Connect Linux hosts to Microsoft Sentinel: LIN1 via CEF connector and LIN2 via Syslog connector to Log Analytics workspace
Lab architecture diagram — Source: MicrosoftLearning/SC-200T00A-Microsoft-Security-Operations-Analyst, MIT License

Environment: Employer-provided Azure subscription (resources deleted after lab).

Source Material


Completed using Lab 6 – Exercise 1: Deploy Sentinel, Exercise 1: Connect Services, Exercise 2: Connect Windows, Exercise 3: Connect Linux, and Exercise 4: Connect Defender XDR from the SC-200T00A MicrosoftLearning GitHub repository; and Microsoft Learn exercises SIEM Configuration Exercise 1, Exercise 2, Exercise 3, and Deploy Sentinel to Defender XDR. Completed in an employer-provided Azure subscription.