Agent Foskett Academy • Microsoft Sentinel

Microsoft Sentinel Academy.

The KQL Academy taught analysts how to ask better questions of security data.

Now Agent Foskett moves into the platform that turns those questions into operational security monitoring.

Microsoft Sentinel brings together SIEM, SOAR, analytics rules, incidents, automation, workbooks and threat hunting into one cloud-native security operations platform.

This Academy teaches security analysts how to build Sentinel the practical way: one connector, one rule, one incident and one investigation at a time.

Agent Foskett Microsoft Sentinel Academy learning path
Academy overview

Learn Microsoft Sentinel from the ground up, with practical lessons covering workspace design, data ingestion, analytics rules, incidents, automation and investigation workflows.

Understand Microsoft Sentinel architecture
Connect Microsoft security data sources
Create analytics rules and incidents
Build workbooks, playbooks and hunting workflows

Microsoft Sentinel Academy Learning Path

Follow a practical learning path from Sentinel foundations into operational security monitoring and investigation.
The Academy builds from core Sentinel concepts into data ingestion, dashboards, automation, playbooks, threat hunting and investigation enrichment.
 
Module 1 — Microsoft Sentinel Foundations Six lessons covering Sentinel fundamentals, Defender XDR integration, Log Analytics, incidents and analytics rules.
Lesson 1 — What is Microsoft Sentinel? Learn what Microsoft Sentinel is, how SIEM and SOAR work, and how Sentinel fits alongside Microsoft Defender XDR in a modern Security Operations Centre. Lesson 2 — Microsoft Sentinel vs Microsoft Defender XDR Understand where the platforms overlap, where they differ, and why mature SOCs often deploy both. Lesson 3 — Log Analytics Workspace Basics Learn how Sentinel stores security data in Log Analytics, including tables, retention, ingestion and workspace design. Lesson 4 — Connecting Microsoft Defender XDR Learn how Defender XDR incidents, alerts, entities and telemetry become part of broader Sentinel investigations. Lesson 5 — Understanding Microsoft Sentinel Incidents Understand incident severity, status, ownership, entities, alerts and repeatable analyst investigation workflows. Lesson 6 — Your First Analytics Rule Turn KQL into scheduled detections using frequency, lookup periods, thresholds, entity mapping and incident creation.
Module 2 — Sentinel Operations Operational lessons covering data ingestion, workbooks, automation rules, Logic Apps playbooks, Watchlists, Threat Intelligence, Entity Mapping, proactive Threat Hunting, investigation Bookmarks, the Investigation Graph, UEBA, Fusion, Content Hub, Notebooks and Data Collection Rules.
Lesson 7 — Microsoft Sentinel Data Connectors Learn how Microsoft, Azure and third-party data sources send telemetry into Log Analytics and Sentinel. Lesson 8 — Microsoft Sentinel Workbooks and Dashboards Use KQL, charts, parameters and visualisations to monitor incidents, connectors and SOC performance. Lesson 9 — Microsoft Sentinel Automation Rules Automate owner assignment, tags, severity changes, status updates, comments and playbook execution. Lesson 10 — Microsoft Sentinel Playbooks and Logic Apps Use Azure Logic Apps to automate notifications, enrichment, ticketing and repeatable incident response workflows. Lesson 11 — Microsoft Sentinel Watchlists Learn how Watchlists add business context to Sentinel investigations using VIP users, critical assets, trusted IP addresses, service accounts and other organisation-specific reference data. Lesson 12 — Microsoft Sentinel Threat Intelligence Learn how Microsoft Sentinel uses Threat Intelligence feeds and Indicators of Compromise (IOCs) to detect known malicious IP addresses, domains, URLs, file hashes and other attacker infrastructure. Lesson 13 — Microsoft Sentinel Entity Mapping Learn how analytics rules map accounts, hosts, IP addresses, URLs, files and other entities so Microsoft Sentinel can connect related evidence and improve incident investigations. Lesson 14 — Microsoft Sentinel Hunting Learn how Microsoft Sentinel Hunting uses KQL and hypothesis-driven investigations to proactively identify suspicious activity, pivot across security data and uncover threats before alerts are generated. Lesson 15 — Microsoft Sentinel Bookmarks Learn how Microsoft Sentinel Bookmarks help analysts preserve investigation evidence, add notes, apply tags, map entities and build a structured timeline during threat hunting and incident investigations. Lesson 16 — Microsoft Sentinel Investigation Graph Learn how the Microsoft Sentinel Investigation Graph visualises relationships between incidents, alerts, accounts, devices, IP addresses and other entities, helping analysts pivot through evidence and understand complex security investigations. Lesson 17 — Microsoft Sentinel UEBA (User and Entity Behavior Analytics) Learn how Microsoft Sentinel User and Entity Behavior Analytics (UEBA) builds behavioural baselines, identifies anomalous user and device activity, enriches investigations and helps analysts prioritise potential threats. Lesson 18 — Microsoft Sentinel Fusion Learn how Microsoft Sentinel Fusion uses machine learning to correlate alerts, entities and behavioural signals into high-confidence multi-stage incidents, helping analysts investigate complex attacks across the Microsoft security ecosystem. Lesson 19 — Microsoft Sentinel Content Hub Learn how the Microsoft Sentinel Content Hub provides packaged solutions containing data connectors, analytics rules, workbooks, hunting queries, playbooks and automation, helping SOC teams deploy, configure and maintain security content more efficiently. Lesson 20 — Microsoft Sentinel Notebooks Learn how Microsoft Sentinel Notebooks use Jupyter, Python and MSTICPy to extend investigations with advanced threat hunting, enrichment, visualisations and repeatable security analysis workflows. Lesson 21 — Microsoft Sentinel Data Collection Rules Learn how Data Collection Rules control supported Azure Monitor Agent data collection, routing, filtering and ingestion-time transformations for Microsoft Sentinel and Log Analytics.
Module 3 — Analytics Rules Build, tune and validate Microsoft Sentinel analytics rules that turn security telemetry and KQL detections into actionable alerts and incidents.
Lesson 22 — Building Scheduled Analytics Rules in Microsoft Sentinel Learn how scheduled analytics rules use KQL, query frequency, lookback periods, thresholds, entity mapping and grouping to turn security telemetry into actionable alerts. Lesson 23 — Understanding Rule Frequency and Lookup Periods Learn how query frequency, lookup periods, overlapping detection windows and ingestion delay affect scheduled analytics rules and help prevent missed or duplicated detections. Lesson 24 — Setting Alert Thresholds in Microsoft Sentinel Learn how alert thresholds control when scheduled analytics rule results generate alerts, including query result counts, KQL aggregation, event grouping, simulation and evidence-based tuning. Lesson 25 — Entity Mapping in Analytics Rules Learn how entity mapping connects analytics rule query fields to accounts, IP addresses, hosts and other Microsoft Sentinel entities used for correlation, investigation and response. Lesson 26 — Custom Details and Alert Enrichment Learn how custom details surface useful query values directly in Microsoft Sentinel alerts so analysts can see important investigation context without reopening the original query. Lesson 27 — Grouping Alerts into Incidents Learn how Microsoft Sentinel groups related analytics rule alerts into incidents using time windows, entities, alert details and custom details so analysts can investigate connected activity together. Lesson 28 — Near-Real-Time (NRT) Analytics Rules Learn how Microsoft Sentinel NRT analytics rules run every minute to provide faster detection of newly ingested security activity, and when NRT is a better choice than a scheduled rule. Lesson 29 — Microsoft Security Analytics Rules Learn how alerts generated by connected Microsoft security products become Microsoft Sentinel incidents, how to identify the original alert provider, and how Defender XDR integration changes incident creation. Lesson 30 — Mapping Analytics Rules to MITRE ATT&CK Learn how to map Microsoft Sentinel analytics rules to MITRE ATT&CK tactics and techniques so detections clearly describe the adversary behaviour they are designed to identify. Lesson 31 — Tuning Analytics Rules and Reducing False Positives Learn how to tune Microsoft Sentinel analytics rules, investigate false positives, manage exceptions with KQL and watchlists, and reduce SOC noise without filtering away real threats. Lesson 32 — Testing a Detection Before Enabling It Learn how to validate Microsoft Sentinel detection logic using historical data, true and false positive testing, threshold boundaries, rule simulation and alert context before enabling an analytics rule. Lesson 33 — From Hunting Query to Analytics Rule Learn how to turn useful Microsoft Sentinel hunting logic into a production analytics rule with scheduling, thresholds, entity mapping, alert enrichment, incident configuration and testing. Lesson 34 — Troubleshooting an Analytics Rule That Didn't Fire Learn how to troubleshoot a Microsoft Sentinel analytics rule that failed to alert by checking source data, KQL logic, execution windows, ingestion delay, thresholds, rule health and incident behaviour. Lesson 35 — Building a Complete Sentinel Detection Build a complete Microsoft Sentinel detection from hypothesis and KQL through scheduling, thresholds, entity mapping, alert enrichment, MITRE ATT&CK, incident behaviour, testing, tuning and production validation. Lesson 36 — Understanding Microsoft Sentinel Incidents Learn how Microsoft Sentinel incidents bring alerts, entities, timelines, evidence and investigation context together so analysts can understand what happened before deciding how to respond. Lesson 37 — Reading an Incident Before You Touch Anything Learn how to perform a disciplined first-pass review of a Microsoft Sentinel incident by establishing scope, reading alerts chronologically, identifying affected assets, reviewing evidence and deciding the right investigation pivot before taking action. Lesson 38 — Prioritising Incidents: Severity Is Not the Whole Story Learn how to prioritise Microsoft Sentinel incidents using severity, asset criticality, privilege, scope, evidence confidence, behavioural context, threat intelligence and business impact. Lesson 39 — Investigating the Alerts Inside an Incident Learn how to investigate the alerts inside a Microsoft Sentinel incident by examining detection sources, activity times, entities and evidence, validating important findings against telemetry and connecting alerts into an evidence-based attack story. Lesson 40 — Investigating Entities in Microsoft Sentinel Learn how to investigate users, devices, IP addresses and other entities in Microsoft Sentinel, using entity context, timelines, insights and targeted KQL pivots to discover related activity and determine the true scope of an incident. Lesson 41 — Building an Incident Timeline Learn how to build a clear incident timeline in Microsoft Sentinel using alerts, bookmarks, entity activity and targeted KQL queries to reconstruct what happened and identify the true sequence of attacker activity. Lesson 42 — Using Bookmarks During an Investigation Learn how to use bookmarks during a Microsoft Sentinel investigation to preserve important findings, add useful notes and tags, map related entities and strengthen the incident timeline with evidence discovered during hunting and analysis.
🔎 Take your Sentinel skills into the SOC.
Continue into the new SOC Analyst Academy and apply Sentinel, KQL, Defender XDR, Entra and Security Copilot to realistic alert triage, incident investigation, containment and escalation scenarios.
Open SOC Analyst Academy →

Microsoft Sentinel Academy roadmap

The Academy combines Sentinel foundations with operational learning across data connectors, workbooks, automation, playbooks, detection engineering, incident investigation and threat hunting.
Module 1 — Sentinel FoundationsWhat Sentinel is, how it differs from Defender XDR, how Log Analytics fits in and how cloud-native SIEM changes security operations.
Module 2 — Sentinel OperationsData connectors, workbooks, automation rules, Logic Apps playbooks and repeatable SOC workflows.
Module 3 — Analytics RulesBuilding scheduled rules, near-real-time detections, entity mapping, alert grouping, incident creation and MITRE ATT&CK alignment.
Module 4 — Incidents and InvestigationWorking alerts, entities, bookmarks, timelines, comments, owner assignment and repeatable investigation processes inside Sentinel.
Module 5 — Workbooks and DashboardsTurning security data into operational views for SOC teams, managers, threat hunters and incident responders.
Module 6 — Automation and SOARUsing automation rules, Logic Apps and playbooks to enrich incidents, notify responders, isolate risk and standardise response actions.

How Sentinel connects to the KQL Academy

The existing KQL Academy becomes the foundation. Sentinel then applies those skills to operational monitoring, detections and investigations.
KQL FoundationsSentinel analytics rules and hunting queries rely on KQL, making the original Academy the natural prerequisite.
Enterprise Hunting QueriesAdvanced KQL patterns can be reused inside Sentinel hunting, analytics rules and workbook queries.
Defender XDR WorkflowSentinel expands the investigation view by bringing Microsoft and non-Microsoft signals into one SOC workflow.

Sentinel skills this Academy builds

The goal is not just to explain the portal. The goal is to teach operational Sentinel thinking.
SIEM architectureUnderstand workspaces, data connectors, retention, tables, ingestion cost and deployment design.
Detection engineeringCreate analytics rules that map entities, reduce false positives, generate useful incidents and align with MITRE ATT&CK.
SOC operationsManage incidents, triage alerts, assign owners, investigate entities and document response decisions.
Threat huntingUse KQL, bookmarks, hunting queries and investigation pivots to proactively find suspicious activity.
AutomationUse automation rules and playbooks to notify responders, enrich incidents, create tickets and standardise response actions.
ReportingBuild workbooks that show security posture, incident trends, detection coverage and operational SOC performance.

Final thought

KQL helps analysts find evidence. Sentinel helps security teams operationalise that evidence.
Agent Foskett mindsetA query becomes more powerful when it becomes part of a repeatable SOC workflow. Sentinel is where hunting logic becomes detection, investigation and response.
SOC Analyst AcademyPut Sentinel into practice through realistic SOC scenarios covering alert triage, investigation decisions, containment, escalation and evidence-driven response.
Develop IT. Protect IT.GEMXIT PTY LTD | GEMXIT UK LTD

Microsoft Sentinel Academy by Agent Foskett

The Agent Foskett Microsoft Sentinel Academy teaches security analysts how to use Microsoft Sentinel for SIEM, SOAR, threat hunting, analytics rules, incidents, data connectors, workbooks, watchlists and automation. The learning path connects Sentinel fundamentals, Defender XDR integration, Log Analytics, incidents, analytics rules, data connectors, workbooks, automation rules and Logic Apps playbooks with practical security operations.

Learn Microsoft Sentinel for security operations

This Sentinel learning path explains Log Analytics workspaces, Microsoft Defender XDR connectors, analytics rules, incident investigation, automation rules, Logic Apps playbooks, threat intelligence, hunting queries and operational SOC workflows.

Microsoft Sentinel training for Defender XDR and KQL analysts

The Microsoft Sentinel Academy builds on the Agent Foskett KQL Academy by showing defenders how to turn KQL queries into detections, workbooks, incident response processes and enterprise-scale security monitoring. The SOC Analyst Academy then applies these skills to realistic triage, investigation, containment and escalation workflows.