SC-200 Exam Preparation: Building Your First Microsoft Sentinel SOC Lab on Azure
Setting up a security operations center (SOC) lab is a fundamental step for any security enthusiast looking to gain hands-on experience…
SC-200 Exam Preparation: Building Your First Microsoft Sentinel SOC Lab on Azure
Setting up a security operations center (SOC) lab is a fundamental step for any security enthusiast looking to gain hands-on experience with cloud-native tools. This guide covers the practical steps to initialize your Azure environment, create a data workspace, and deploy Microsoft Sentinel.
Step 1: Setting the Foundation — Creating a Resource Group
In Azure, a Resource Group serves as a logical container that holds related resources for your solution. This is the first step in organizing your lab.
- Navigate to Resource Groups: From your Azure portal home screen, select the Resource groups icon.

- Initiate Creation: If your subscription is new, you may see a screen indicating “No resource groups to display.” Click the Create button to start.
- Fill in Details: On the creation page, select your Subscription (e.g., Azure for Students). Give your group a name, such as soc-lab-rg, and choose your Region, like (Asia Pacific) Central India.

- Finalize: Once created, your new resource group will appear in your list, ready to house your security tools.

Step 2: Preparing the Data Hub — Log Analytics Workspace
Before you can use Microsoft Sentinel, you must create a Log Analytics workspace. This acts as the storage and management unit where your log data is collected and analyzed.
- Search for Workspaces: Use the global search bar to find and select Log Analytics workspaces.

- Create Workspace: Click the Create button on the workspace landing page.

- Configure Instance Details:
- Select your existing resource group, soc-lab-rg.
- Provide a unique name for the workspace, such as soc-sentinel-law.
- Set the Region to match your resource group (e.g., Central India).
- Review and Deploy: Review your settings, ensuring the pricing tier is set correctly (e.g., Pay-as-you-go), and click Create.

- Monitor Progress: You can track the deployment until it is successfully completed.

Step 3: Deploying the SIEM — Microsoft Sentinel
Now that your data hub is ready, you can deploy Microsoft Sentinel, Azure’s cloud-native SIEM that helps you focus on what matters most by analyzing data at scale.
- Find Sentinel: Search for “Microsoft Sentinel” in the Azure portal.

- Add to Workspace: Click Create on the Sentinel landing page. You will be asked to choose a workspace; select the soc-sentinel-law workspace you just created and click Add.

- Explore the Interface: Once added, you will reach the Sentinel overview page. From here, you can access guides to help you install your first content hub solutions and begin collecting data.

Conclusion
By following these steps, you have successfully built the core infrastructure for a cloud-based SOC lab. From here, you can begin connecting data sources, creating detection rules, and hunting for threats in your new environment.
메타데이터
- post_id
- 725dbff77ca2
- slug
- building-your-first-soc-lab-a-step-by-step-guide-to-setting-up-microsoft-sentinel-on-azure-725dbff77ca2
- url
- https://medium.com/@sajjad.hosen/building-your-first-soc-lab-a-step-by-step-guide-to-setting-up-microsoft-sentinel-on-azure-725dbff77ca2
- canonical_url
- https://medium.com/@sajjad.hosen/building-your-first-soc-lab-a-step-by-step-guide-to-setting-up-microsoft-sentinel-on-azure-725dbff77ca2
- author_url
- https://medium.com/@sajjad.hosen
- status
- ok
- fetched_at
- 2026-07-17 21:46:37