Cover of Ultra Transcenders SC-200: Microsoft Security Operations Analyst
ULTRA TRANSCENDERS · AN INDEPENDENT STUDY GUIDE

SC-200 Microsoft Security Operations Analyst

An independent study guide for Microsoft Certified: Security Operations Analyst Associate · by Tony Rough

Know which Defender, Sentinel or KQL move fits the incident in front of you, and why.

  • 12 chapters
  • 11 diagrams
  • 100+ common traps
  • 300+ glossary terms
Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

Free glossary of the book's terms

What's inside

SC-200 doesn't test whether you can find your way round a portal. It tests whether you can choose the right setting, rule type, connector, response action or table for a security operations task in Microsoft Defender XDR and Microsoft Sentinel.

This independent study guide for the Microsoft Certified: Security Operations Analyst Associate exam distils what SC-200 really expects you to understand into the comparisons, configuration choices and traps that security operations decisions turn on, with short KQL and PowerShell examples throughout.

Organised by technology

Twelve chapters, each readable on its own and together covering all three SC-200 skill areas:

Inside

Up to date

Microsoft security operations change quickly. This edition reflects Microsoft's documentation as of October 2026: Microsoft Sentinel in the Defender portal (the Azure portal experience is supported only until 31 March 2027), the Sentinel data lake, risk policies built in Conditional Access after the legacy ID Protection policies retired, and the current names Microsoft Defender XDR (formerly Microsoft 365 Defender) and Security Copilot (formerly Microsoft Copilot for Security).

Understanding, not memorising

This book contains no exam questions. It explains the knowledge the exam expects, so you can answer questions you have never seen and apply the same judgement in a real security operations centre.

Written by Tony Rough, a cloud architect with more than twenty years in IT infrastructure who holds the Azure Solutions Architect Expert, Azure Administrator and Azure Security Engineer certifications.

Part of the Ultra Transcenders series from Distilled Press. An independent publication, not affiliated with, sponsored by or endorsed by Microsoft Corporation.

Is this book for you?

Which certification, which book?

Exam coverage

Every skill area in Microsoft's SC-200 outline (as of October 21, 2026), and the chapters that cover it.

Skill areaWeightChapters
Manage a security operations environment40–45%1, 2, 3, 5, 6, 7, 8, 11
Respond to security incidents35–40%1, 4, 8, 9, 10
Perform threat hunting20–25%11, 12

See every objective and where the book covers it

Chapters

  1. Microsoft Defender XDR: portal, alerts and incidents
  2. Configuring Microsoft Defender for Endpoint
  3. Automation: Microsoft Sentinel automation rules and playbooks
  4. Responding on devices with Defender for Endpoint
  5. Microsoft Sentinel: workspace, roles, retention, workbooks and optimisation
  6. Ingesting data into Microsoft Sentinel
  7. Detections: custom detection rules and Sentinel analytics
  8. Email and data threats: Defender for Office 365 and Microsoft Purview alerts
  9. Cloud, app and identity threats
  10. Investigating incidents across Microsoft 365 and with Security Copilot
  11. Threat hunting with KQL and Advanced hunting
  12. Hunting on the Microsoft Sentinel platform

Plus an appendix glossary of 300+ terms, each linked to Microsoft Learn, with the same terms explained free online for print readers.

Sample diagrams

How the correlation engine turns alerts from every source into incidents
How the correlation engine turns alerts from every source into incidents
The XDR default tier, the analytics tier and the data lake tier, with how data moves between them
The XDR default tier, the analytics tier and the data lake tier, with how data moves between them
Choosing a detection type
Choosing a detection type

Free study notes

Some sections of the book, free to read online:

About the author

Tony Rough is a cloud architect with more than twenty years in IT infrastructure, designing Azure platforms for UK organisations at a Microsoft partner. He holds the Azure Solutions Architect Expert, Azure Administrator and Azure Security Engineer certifications and has passed more than thirty Microsoft exams. Ultra Transcenders is the series he wished he'd had.