Overview
This two-day instructor-led course provides delegates with the knowledge and skills to effectively use Microsoft Defender XDR and Security Copilot for responding to cyber-attacks. Delegates will learn how to manage and investigate security incidents within the Defender portal, leveraging automated investigations and threat intelligence.
The course also covers the use of Kusto Query Language (KQL) for advanced threat hunting and introduces Security Copilot as a tool to assist in incident response, script and file analysis, and report generation. Designed for security professionals, this course enables participants to enhance their organisation’s cyber resilience by efficiently detecting, analysing, and mitigating security threats.
Prerequisites
An understanding of core technical concepts, including applications, file storage, networking and identities.
An understanding of common security threats and attacks such as malware, phishing, ransomware and software exploits
Instructors will demonstrate features throughout the event. Optional lab exercises are available for students to complete using a commercial Microsoft 365 tenancy with an Azure subscription provided for each student free of charge by QA. The tenancy lasts for 30 days. The Azure subscription will have enough credit to perform lab exercises.
Target audience
This course is designed for:
- Security analysts responsible for monitoring and responding to cyber threats.
- IT administrators with a role in cybersecurity incident response.
Security professionals looking to enhance their skills in Microsoft Defender XDR and Security Copilot.
Delegates will learn how to
By the end of this course, delegates will be able to:
- Navigate the Microsoft Defender portal and explain integrations with Microsoft services such as Entra ID and Azure.
- Use Defender XDR to investigate and respond to cybersecurity incidents, leveraging automated investigations and threat intelligence.
- Build advanced threat-hunting queries using Kusto Query Language (KQL).
- Onboard and use Copilot for Security to assist with incident response, script and file analysis, KQL query writing, and report generation.
Outline
Overview of Microsoft Defender XDR
- Introduction to Microsoft Defender XDR
- Cybersecurity attack methodologies
- Zero Trust model
- MITRE ATT&CK framework
- Example attack chains
- Security news and emerging threats
- Microsoft Defender XDR services
- Services overview and capabilities
- Integrations with other Microsoft solutions
- Investigating and responding to security threats
- Lab: Hands-on exploration of Defender XDR
Incident response
- Managing alerts and incidents
- Alert triage and correlation
- Incident investigation techniques
- Response actions
- Containing and mitigating threats at the device, user, and network level
- Understanding automated attack disruption
- Remediation actions and Action Center
- Automated investigations
- Lab: Incident investigation and response
Advanced threat hunting with KQL
- Introduction to Kusto Query Language (KQL)
- Guided and advanced query modes
- Understanding the schema
- Saving and sharing queries
- KQL syntax and querying techniques
- Searching, filtering, and sorting data
- Using joins for data correlation
- Summarising and visualising threat data
- Working with strings, dates, and times
- Lab: Writing and executing KQL queries for threat hunting
Security Copilot
- Onboarding Security Copilot
- Planning and setup
- Creating a capacity and configuring settings
- Understanding available plugins
- Standalone capabilities
- Using prompts for security insights
- System capabilities and automation
- Prompt books for common security tasks
- Incident summaries and guided response
- Script and file analysis
- Advanced threat hunting with Copilot
- Generating incident reports
- Embedded capabilities
- Lab: Leveraging Security Copilot for threat analysis and automation
Exams and Assessments
This course does not include any formal assessments.

Frequently asked questions
How can I create an account on myQA.com?
There are a number of ways to create an account. If you are a self-funder, simply select the "Create account" option on the login page.
If you have been booked onto a course by your company, you will receive a confirmation email. From this email, select "Sign into myQA" and you will be taken to the "Create account" page. Complete all of the details and select "Create account".
If you have the booking number you can also go here and select the "I have a booking number" option. Enter the booking reference and your surname. If the details match, you will be taken to the "Create account" page from where you can enter your details and confirm your account.
Find more answers to frequently asked questions in our FAQs: Bookings & Cancellations page.
How do QA’s virtual classroom courses work?
Our virtual classroom courses allow you to access award-winning classroom training, without leaving your home or office. Our learning professionals are specially trained on how to interact with remote attendees and our remote labs ensure all participants can take part in hands-on exercises wherever they are.
We use the WebEx video conferencing platform by Cisco. Before you book, check that you meet the WebEx system requirements and run a test meeting to ensure the software is compatible with your firewall settings. If it doesn’t work, try adjusting your settings or contact your IT department about permitting the website.
How do QA’s online courses work?
QA online courses, also commonly known as distance learning courses or elearning courses, take the form of interactive software designed for individual learning, but you will also have access to full support from our subject-matter experts for the duration of your course. When you book a QA online learning course you will receive immediate access to it through our e-learning platform and you can start to learn straight away, from any compatible device. Access to the online learning platform is valid for one year from the booking date.
All courses are built around case studies and presented in an engaging format, which includes storytelling elements, video, audio and humour. Every case study is supported by sample documents and a collection of Knowledge Nuggets that provide more in-depth detail on the wider processes.
When will I receive my joining instructions?
Joining instructions for QA courses are sent two weeks prior to the course start date, or immediately if the booking is confirmed within this timeframe. For course bookings made via QA but delivered by a third-party supplier, joining instructions are sent to attendees prior to the training course, but timescales vary depending on each supplier’s terms. Read more FAQs.
When will I receive my certificate?
Certificates of Achievement are issued at the end the course, either as a hard copy or via email. Read more here.