Microsoft Cybersecurity Certified Path — SOC & Identity
REFERENCE: PARC-SEC-MS
Sessions guaranteed from a single enrolment (no risk of postponement except in cases of force majeure)
— contact us
Do you want to build a solid Microsoft security cell, with skills covering identity protection, SOC operations and incident response on Microsoft Sentinel? The Microsoft Cybersecurity Certified Path — SOC & Identity is a complete curriculum of 4 modules that takes an employee from Microsoft security fundamentals to a dual profile of SOC Analyst (SC-200) + Identity and Access Administrator (SC-300).
Exam voucher SC-900, SC-200, SC-300 included, Sentinel Applied Skill (SC-5001) accessible, small group of 1 to 3 participants, sessions guaranteed from a single enrolment.
Discover our certified training courses · Browse all our certified paths
Who is this path for?
- SOC analysts who want to master threat detection and response on the Microsoft Defender and Sentinel ecosystem.
- Security administrators aiming for the dual identity + security operations profile.
- Microsoft 365 administrators wishing to specialise in security and identity.
- CIOs wishing to train a complete team on modern Microsoft security.
- Security managers who want to build an in-house SOC on the Microsoft stack.
Your objectives at the end of the path
- Understand the fundamental concepts of Microsoft security, compliance and identity (SC-900).
- Detect, investigate and respond to threats with Microsoft Defender XDR and Sentinel (SC-200).
- Administer identities and access with Microsoft Entra ID: MFA, conditional access, governance (SC-300).
- Configure and operate Microsoft Sentinel for concrete SOC use cases (SC-5001 Applied Skill).
- Pass the Security Operations Analyst Associate (SC-200) + Identity and Access Administrator Associate (SC-300) certifications with confidence.
The 4 modules of the path
Each module can be taken separately or as part of the full path. The progression starts from Microsoft security fundamentals and gradually leads to a certified dual SOC Analyst + Identity Administrator profile.
Module 1 · SC-900
Microsoft Security, Compliance and Identity Fundamentals
Get started with Microsoft security, compliance and identity concepts: Zero Trust model, Microsoft Entra ID, Microsoft Defender, Microsoft Purview. Preparation for the SC-900 exam. Exam voucher included.
Indicative duration: 2 days (indicative)
Module 2 · SC-200
Microsoft Security Operations Analyst
Detect, investigate and respond to threats with Microsoft Defender XDR, Defender for Endpoint, Defender for Cloud and Microsoft Sentinel. Threat hunting, KQL, SOAR playbooks. Preparation for the SC-200 exam. Exam voucher included.
Indicative duration: 4 days
Module 3 · SC-300
Microsoft Identity and Access Administrator
Administer identities and access with Microsoft Entra ID: users, groups, applications, MFA, conditional access, Privileged Identity Management, identity governance. Preparation for the SC-300 exam. Exam voucher included.
Indicative duration: 3.5 days
Module 4 · SC-5001
Microsoft Sentinel — Applied Skill
Configure and operate Microsoft Sentinel on concrete SOC use cases: log ingestion, analytics rules, workbooks, playbooks, threat hunting. Validated by the SC-5001 Microsoft Applied Skill.
Indicative duration: 1 day
MFE-IT teaching format
- Small group of 1 to 3 participants, guaranteed from a single enrolment.
- 60% hands-on : guided labs on a demonstration Microsoft Defender and Sentinel tenant, mini-projects, personalised feedback.
- On-site at your premises or synchronous remote, with individualised support.
- SC-900, SC-200 and SC-300 exam vouchers included. Sentinel Applied Skill SC-5001 available free of charge on Microsoft Learn.
- Quiz platform included in our prices: practise under exam conditions, with a detailed report provided at the end of each quiz.
- Solidar-IT : 30 € per participant donated to our partner charities (SPA, Restos du Cœur).
Prerequisites
Prerequisites specific to each module:
- Microsoft Security Fundamentals (preparation for the SC-900 exam): no prerequisites, open to beginners.
- Security Operations Analyst (preparation for the SC-200 exam): Microsoft security basics (acquired in the SC-900 module or equivalent experience).
- Identity and Access Administrator (preparation for the SC-300 exam): basics of Microsoft Entra ID and identity concepts (acquired in the SC-900 module or equivalent experience).
- Microsoft Sentinel — Applied Skill (SC-5001 validation): SC-200 or operational experience with Defender / Sentinel recommended.
If you are unsure about your starting level, we offer a preliminary 30-minute discussion to assess your profile and tailor the progression.
Pricing and financing
The price for the full path or for each module is set on a quote basis, depending on the number of participants and the chosen format (on-site at your premises or synchronous remote).
Financing solutions : skills development plan, self-financing. All arrangements and eligibility conditions are detailed on our dedicated page.
Request a personalised quote: we reply within 48 h.
Would you like the detailed programme of the path?
Frequently asked questions about the Microsoft Cybersecurity path
WHO IS THE MICROSOFT CYBERSECURITY PATH — SOC & IDENTITY FOR?
This path is aimed at systems and network administrators, cloud engineers, IT support profiles, SOC analysts and hands-on CISOs who want — or need — to take charge of security in a Microsoft 365 and Azure environment. Target profiles: M365/Azure admins wishing to specialise in security, security engineers upskilling on Microsoft tools (Defender, Sentinel, Entra ID), cybersecurity consultants extending their stack towards Microsoft. Prior knowledge of Azure (equivalent to AZ-900) or Microsoft 365 is useful but not mandatory.
What Microsoft cybersecurity skills and certifications does the path cover?
The path covers Microsoft security focused on SOC and identity: fundamentals (SC-900), security operations and SOC (SC-200), identity and access (SC-300) and Microsoft Sentinel (SC-5001: SIEM/SOAR, KQL).
Does the path cover the SIEM (Sentinel) and the KQL language?
Yes. A dedicated Microsoft Sentinel module (SC-5001) covers SIEM/SOAR, writing rules and queries in KQL, investigations and automation (playbooks).
HOW LONG DOES THE PATH LAST AND CAN IT BE SPREAD OUT?
The path represents 10.5 days of training, i.e. 67 hours, at a rate of 6 hours per day. You can take it continuously over three weeks or spread it over several months depending on your constraints. At MFE-IT, sessions are guaranteed from a single enrolled participant (except in cases of force majeure), which allows you to schedule each module at your own pace without depending on a group’s calendar.
WHAT EXACTLY DOES THE PRICE INCLUDE?
The price covers the four official trainings (SC-900, SC-200, SC-300 and SC-5001), the three Microsoft exam vouchers for the paid certifications (SC-900, SC-200 and SC-300), and several MFE-IT mock exams to practise in real conditions. The Applied Skill SC-5001 is free on the Microsoft side and therefore at no extra cost. Everything is delivered on-site or remotely depending on your choice, with 30 days of post-training follow-up by email.
WHAT ARE THE PREREQUISITES TO START THE PATH?
The path starts with the fundamentals (SC-900) and therefore does not require any Microsoft security knowledge. However, familiarity with Azure (equivalent to AZ-900) and Microsoft 365 is necessary for the SC-200, SC-300 and SC-5001 modules, which are more technical. If you lack these prerequisites, we can add an AZ-900 training or a Microsoft 365 introduction beforehand — feel free to contact us to discuss it.
REMOTE OR ON-SITE? HOW DO THE SESSIONS TAKE PLACE?
Both formats are possible, including a hybrid mix from one module to another. On-site training can take place directly at your premises, and remote sessions can be recorded on request so that you can review key passages. Each session has between 1 and 3 participants maximum, with around 60% of the time devoted to hands-on practice in real Microsoft environments (demonstration tenants, Defender/Sentinel/Entra labs). You leave each module with concrete deliverables (playbooks, KQL queries, configurations) directly reusable in your professional context.
WHICH JOB DOES THIS PATH LEAD TO?
This path prepares you for the roles of Microsoft Sentinel SOC analyst, Microsoft 365 security engineer (Defender for Office, Defender for Endpoint, Defender for Cloud Apps), Entra ID identity engineer, and hands-on CISO in Microsoft environments. The opportunities span cybersecurity-focused IT services companies, the in-house SOCs of large enterprises, MSSPs and the public sector, which are industrialising their Microsoft security operations.
WHAT IS THE MARKET VALUE OF THE CERTIFICATIONS OBTAINED?
At the end of the path, you obtain three globally recognised Microsoft certifications (SC-900 Security Fundamentals, SC-200 Security Operations Analyst, SC-300 Identity and Access Administrator), plus the Applied Skill SC-5001 (Configure SIEM Security Operations Using Microsoft Sentinel) which appears directly on your Microsoft Learn and LinkedIn profile. It is the most sought-after combination for SOC and Identity roles on Microsoft Sentinel, and it clearly sets you apart from profiles that only hold a general certification such as SC-900 alone.
WHAT IS THE DIFFERENCE WITH THE CLOUD AZURE PATH — FROM BEGINNER TO ARCHITECT?
The Cloud Azure path trains you in general cloud administration and architecture (AZ-104, AZ-305): deployment, governance, infrastructure. The Microsoft Cybersecurity path, on the other hand, is a defensive specialisation: you learn to detect, investigate and block attacks on Microsoft environments (SOC, Identity, SIEM). The two are complementary: one trains the cloud admin who builds, the other trains the defender who protects. If you are hesitating between the generalist route and the security specialisation, the preliminary interview will help us guide your choice according to your target role.
Ready to build a Microsoft security cell within your team?
Let’s talk for 30 minutes to scope your needs: your team’s current level, business objectives, scheduling constraints, financing. You will receive a costed quote and a tailored path within 48 h.