
An independent study guide for Microsoft Certified: Security Operations Analyst Associate · by Tony Rough
Know which Defender, Sentinel or KQL move fits the incident in front of you, and why.
Due on Amazon in November 2026, in Kindle and paperback editions.
This independent study guide for the Microsoft Certified: Security Operations Analyst Associate exam distils what SC-200 really expects you to understand into the comparisons, configuration choices and traps that security operations decisions turn on, with short KQL and PowerShell examples throughout.
Twelve chapters, each readable on its own and together covering all three SC-200 skill areas:
Microsoft security operations change quickly. This edition reflects Microsoft's documentation as of October 2026: Microsoft Sentinel in the Defender portal (the Azure portal experience is supported only until 31 March 2027), the Sentinel data lake, risk policies built in Conditional Access after the legacy ID Protection policies retired, and the current names Microsoft Defender XDR (formerly Microsoft 365 Defender) and Security Copilot (formerly Microsoft Copilot for Security).
This book contains no exam questions. It explains the knowledge the exam expects, so you can answer questions you have never seen and apply the same judgement in a real security operations centre.
Written by Tony Rough, a cloud architect with more than twenty years in IT infrastructure who holds the Azure Solutions Architect Expert, Azure Administrator and Azure Security Engineer certifications.
Part of the Ultra Transcenders series from Distilled Press. An independent publication, not affiliated with, sponsored by or endorsed by Microsoft Corporation.
Every skill area in Microsoft's SC-200 outline (as of October 21, 2026), and the chapters that cover it.
| Skill area | Weight | Chapters |
|---|---|---|
| Manage a security operations environment | 40–45% | 1, 2, 3, 5, 6, 7, 8, 11 |
| Respond to security incidents | 35–40% | 1, 4, 8, 9, 10 |
| Perform threat hunting | 20–25% | 11, 12 |
Plus an appendix glossary of 300+ terms, each linked to Microsoft Learn, with the same terms explained free online for print readers.



Some sections of the book, free to read online:
Which background query tool fits a requirement, compared by data source, joins, schedule, lookback, timeout and result limits.
How Defender XDR custom detections, scheduled, NRT, threat intelligence, Fusion, ML and anomaly rules differ, and the capability gaps that still decide between them.
How the two Azure Monitor Agent connectors differ, how a Linux log forwarder is set up, and how to avoid ingesting the same messages twice.
What ASR rules need to run, the difference between Audit, Warn, Block, Disabled and Not configured, and which deployment methods support per-rule exclusions.
The full and semi-automated remediation levels set per device group, how pending actions expire, and what automation folder exclusions do and don't affect.
The three advanced feature toggles, basic versus advanced live response permissions, the key commands and the session and file size limits.
Which email protection and investigation tools each plan includes, with the Safe Attachments responses, impersonation settings and zero-hour auto purge actions.
How the two risk types and their detections work, where to see them, and how risk-based Conditional Access now replaces the retired legacy risk policies.