Search icon CANCEL
Subscription
0
Cart icon
Cart
Close icon
You have no products in your basket yet
Save more on your purchases!
Savings automatically calculated. No voucher code required
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Microsoft 365 Security Administration: MS-500 Exam Guide

You're reading from  Microsoft 365 Security Administration: MS-500 Exam Guide

Product type Book
Published in Jun 2020
Publisher Packt
ISBN-13 9781838983123
Pages 672 pages
Edition 1st Edition
Languages
Author (1):
Peter Rising Peter Rising
Profile icon Peter Rising
Toc

Table of Contents (29) Chapters close

Preface 1. Section 1: Configuring and Administering Identity and Access in Microsoft 365
2. Chapter 1: Planning for Hybrid Identity 3. Chapter 2: Authentication and Security 4. Chapter 3: Implementing Conditional Access Policies 5. Chapter 4: Role Assignment and Privileged Identities in Microsoft 365 6. Chapter 5: Azure AD Identity Protection 7. Section 2: Implementing and Managing Threat Protection
8. Chapter 6: Configuring an Advanced Threat Protection Solution 9. Chapter 7: Configuring Microsoft Defender ATP to Protect Devices 10. Chapter 8: Message Protection in Office 365 11. Chapter 9: Threat Intelligence and Tracking 12. Chapter 10: Using Azure Sentinel to Monitor Microsoft 365 Security 13. Section 3: Information Protection in Microsoft 365
14. Chapter 11: Controlling Secure Access to Information Stored in Office 365 15. Chapter 12: Azure Information Protection 16. Chapter 13: Data Loss Prevention 17. Chapter 14: Cloud App Discovery and Security 18. Section 4: Data Governance and Compliance in Microsoft 365
19. Chapter 15: Security Analytics and Auditing Capabilities 20. Chapter 16: Personal Data Protection in Microsoft 365 21. Chapter 17: Data Governance and Retention 22. Chapter 18: Search and Investigation 23. Chapter 19: Data Privacy Compliance 24. Section 5: Mock Exam and Assessment
25. Chapter 20: Mock Exam 26. Chapter 21: Mock Exam Answers 27. Chapter 22: Assessments 28. Other Books You May Enjoy

Managing and monitoring Azure Sentinel

Now that you have configured your Azure Sentinel instance and set up some workbooks and playbooks, it is important to manage and monitor Azure Sentinel in order to ensure that you are regularly reviewing and responding to any threats and taking any corrective action that may be required.

Some of the methods available to manage and monitor Azure Sentinel are described as follows.

Azure Sentinel Overview

From the Azure Sentinel | Overview section, you are able to review a selection of alerts and metrics, as shown in the following screenshot:

Figure 10.37 – Azure Sentinel Overview screen

Here you will be able to review events and alerts, usage, and metrics.

Azure Sentinel Logs

From the Azure Sentinel | Logs section, you may choose from a large number of built-in queries under Log Analytics workspaces and see information on things such as Unauthorized Users and Throttled Users, as shown in the following...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime}