Skip to content

Latest commit

 

History

History
62 lines (37 loc) · 1.3 KB

File metadata and controls

62 lines (37 loc) · 1.3 KB

Project 0 — SOC Environment Setup

Objective

Establish a Microsoft cloud-based SOC environment aligned with the SC-200 exam.


Focus Areas

  • Identity setup (Microsoft Entra ID)
  • Log ingestion
  • SIEM enablement using Microsoft Sentinel
  • Security monitoring infrastructure

Outcome

A functional SOC Lab ready for:

  • Threat detection
  • Incident investigation
  • Security monitoring
  • Automation use cases
  • Real-time security monitoring
  • Attack simulation and detection testing

Environment Components

  • Microsoft Entra ID (Identity)
  • Azure Log Analytics Workspace
  • Microsoft Sentinel (SIEM)

Microsoft Entra ID Tenant

The Microsoft Entra ID tenant was used as the identity provider for the SOC lab environment.

Tenant Overview


Users Created for the Lab

Test users were created within the tenant to simulate identity activity inside the SOC environment.

Users Created


Microsoft Sentinel Workspace Enabled

A Log Analytics Workspace was created and Microsoft Sentinel was enabled to function as the SIEM platform for the SOC lab.

Sentinel Workspace Enabled


Status

Completed — SOC environment successfully configured and operational.