StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 1: Manage a security operations environment

Sentinel workspace design: Log Analytics workspace, Sentinel roles (Reader, Responder, Contributor, Automation Contributor), onboarding to the Defender portal

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration, automation and response (SOAR) service. It does not have its own storage: you enable Sentinel on an Azure Monitor Log Analytics workspace, and all ingested data lands in tables in that workspace, such as SigninLogs, SecurityEvent and CommonSecurityLog. So the first design decision is how many workspaces you need, where they live, and who can see them.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan