Cloud Private Public

Implement end‑to‑end security controls for cloud and AI workloads (SC-500T00)

Learn to implement end-to-end security controls for Azure, Microsoft 365, hybrid, multicloud, and AI workloads using hands-on practical security labs.

Register or Request Training

Price per student
$2,445.10
Guaranteed to run
Select a date
Please select a class.
  • Private class for your team
  • Live expert instructor
  • Online or on‑location
  • Customizable agenda
  • Proposal responses same day as request

Course Overview

This course prepares security engineers to design, implement, and manage end-to-end security controls across Microsoft Azure and Microsoft 365, including controls for AI workloads and autonomous agents.

Through instructor-led training and hands-on labs, you will develop practical skills in identity security, infrastructure and data protection, threat detection, regulatory compliance, and security posture management across cloud, hybrid, and multicloud environments.

Course Benefits

  • Secure identities, privileged access, secrets, keys, and certificates with Microsoft Entra ID and Azure Key Vault.
  • Apply governance, least-privilege access, regulatory compliance, and posture-management controls across Azure environments.
  • Protect Azure storage, databases, networks, virtual machines, containers, applications, APIs, and hybrid infrastructure.
  • Secure AI workloads, agents, gateways, and data with Microsoft Defender, Microsoft Foundry, Microsoft Purview, and Microsoft Agent 365.
  • Configure Microsoft Defender for Cloud protections across cloud, hybrid, and multicloud environments.
  • Connect security data sources and implement automation, playbooks, and data management in Microsoft Sentinel.
  • Configure Microsoft Security Copilot workspaces, plugins, and agents.

Delivery Methods

Public Class
Live expert-led online training from anywhere. Guaranteed to run .
Private Class
Delivered for your team at your site or online.

Microsoft Certified Partner

Webucator is a Microsoft Certified Partner. This class uses official Microsoft courseware and will be delivered by a Microsoft Certified Trainer (MCT).

Microsoft Certified Partner

Course Outline

  1. Manage and implement authentication methods in Microsoft Entra ID
    1. Explore Microsoft Entra ID authentication methods
    2. Configure multifactor authentication
    3. Implement passwordless authentication
    4. Configure self-service password reset
    5. Module assessment
  2. Implement and configure Privileged Identity Management (PIM)
    1. Why PIM and just-in-time access matter
    2. Core PIM capabilities
    3. Implement just-in-time access for Microsoft Entra roles
    4. Implement just-in-time access for Azure roles and resources
    5. Scale with PIM for Groups
    6. Apply JIT access to AI workloads, agents, and applications
    7. Use JIT design patterns and best practices
    8. Module assessment
  3. Authenticate API plugins for declarative agents with secured APIs
    1. Integrate an API plugin with an API secured by a key
    2. Integrate an API plugin with an API secured by OAuth
    3. Module assessment
  4. Configure and secure Azure Key Vault
    1. Deploy Azure Key Vault with security controls
    2. Configure access to Azure Key Vault
    3. Configure Key Vault firewall and network settings
  5. Manage keys and secrets in Azure Key Vault
    1. Manage cryptographic keys
    2. Manage secrets
  6. Manage certificates and monitor Azure Key Vault
    1. Manage certificates
    2. Enable Key Vault audit logging
  7. Protect Azure Key Vault with Microsoft Defender for Cloud
    1. Scan for exposed secrets with Defender Cloud Security Posture Management
    2. Enable Microsoft Defender for Key Vault
    3. Investigate and respond to Key Vault alerts
  8. Enforce governance with Azure Policy and resource locks
    1. Assign built-in Azure Policy definitions
    2. Create and deploy custom policy definitions
    3. Implement resource locks
  9. Configure security controls and remediate recommendations in Defender for Cloud
    1. Configure Defender for Cloud and manage security standards
    2. Deploy remediation controls at scale
  10. Evaluate regulatory compliance in Defender for Cloud
    1. Understand compliance standards and controls
    2. Investigate control gaps in the regulatory compliance dashboard
    3. Assign standards and communicate compliance posture
  11. Manage and right-size RBAC role assignments for least privilege
    1. Assign and manage Azure built-in roles
    2. Create custom Azure and Microsoft Entra roles
    3. Evaluate and remediate overprivileged access
  12. Protect backup data with Azure Backup security features
    1. Enable soft delete and immutable vaults
    2. Configure Multi-User Authorization and RBAC for backup
  13. Implement security controls in infrastructure as code
    1. Scan infrastructure-as-code templates with Microsoft Defender for DevOps
    2. Enforce policy compliance in infrastructure-as-code deployments
  14. Describe Azure storage services
    1. Describe storage accounts, redundancy, and services
    2. Identify data migration and file movement options
    3. Module assessment
  15. Implement security and manage access for Azure Storage
    1. Configure storage account security settings
    2. Select an authorization model
    3. Manage access with stored access policies
    4. Disable Shared Key authorization and enforce the setting with Azure Policy
  16. Configure network security for Azure Storage
    1. Describe Azure Storage network security controls
    2. Configure virtual network and IP rules
    3. Configure resource instance rules and trusted services
    4. Implement private endpoints
  17. Implement Microsoft Defender for Storage
    1. Explore Defender for Storage capabilities
    2. Enable and deploy Defender for Storage
    3. Configure malware scanning and sensitive data detection
    4. Configure alert routing and validate coverage
  18. Configure platform-level security for Azure SQL
    1. Configure authentication and managed identity access
    2. Implement network isolation
    3. Protect data in transit and at rest
    4. Apply data masking and row-level security
  19. Configure auditing for Azure SQL Database and SQL Managed Instance
    1. Describe Azure SQL auditing capabilities
    2. Configure audit destinations for Azure SQL Database
    3. Configure auditing for SQL Managed Instance
    4. Design a compliant audit strategy
  20. Implement Microsoft Defender for Databases
    1. Explore Defender for Databases capabilities
    2. Enable Defender for Azure SQL Databases
    3. Enable Defender for open-source relational databases
    4. Configure vulnerability assessment
    5. Configure alert routing and validate coverage
  21. Segment and isolate Azure workloads with network security controls
    1. Assess network segmentation gaps
    2. Control traffic with network security groups
    3. Simplify rules with application security groups
    4. Enforce policy with Azure Virtual Network Manager
    5. Verify effective rules with Network Watcher
  22. Centralize and enforce traffic inspection with Azure Firewall
    1. Determine when centralized inspection is required
    2. Configure Azure Firewall rules and policies
    3. Secure a Virtual WAN hub with Azure Firewall
  23. Secure remote and hybrid connectivity with VPN gateways and Microsoft Entra Private Access
    1. Assess hybrid-connectivity risks
    2. Harden VPN gateway security
    3. Replace broad VPN access with Microsoft Entra Private Access
  24. Eliminate public network exposure of Azure PaaS services
    1. Assess public PaaS endpoint risks
    2. Configure private endpoints
    3. Expose internal services with Azure Private Link service
    4. Enforce and audit private endpoint adoption
  25. Secure access for Microsoft Entra Agent Identity
    1. Map authentication flows and Conditional Access scope
    2. Configure Conditional Access policies for agents
    3. Control agent access and lifecycle
  26. Analyze AI identity risks with Microsoft Defender XDR
    1. Discover AI agents in the Microsoft Defender portal
    2. Assess blast radius and attack paths
  27. Enable real-time protection for Copilot Studio agents
    1. Explore Copilot Studio AI agent protection
    2. Enable protection in Microsoft Defender
    3. Review AI agent protection outputs
  28. Configure AI Gateway security in Microsoft Foundry
    1. Examine AI Gateway architecture
    2. Create and configure AI Gateway
    3. Secure and monitor AI Gateway access
  29. Configure and manage guardrails in Microsoft Foundry
    1. Understand guardrails, Microsoft Content Safety, and Foundry safety controls
    2. Try built-in guardrails
    3. Create and manage blocklists
    4. Configure and apply guardrails
    5. Choose and refine guardrails for AI workloads
    6. Module assessment
  30. Protect AI workloads with Microsoft Defender for Cloud
    1. Enable the AI workloads plan
    2. Review the Data & AI security dashboard
    3. Improve AI security posture with Cloud Security Posture Management
    4. Detect runtime threats with Cloud Workload Protection
    5. Investigate AI alerts in Microsoft Defender XDR
    6. Module assessment
  31. Enable Defender for AI Services workload protection
    1. Enable and configure the Defender for AI Services plan
    2. Monitor AI security with the Data and AI dashboard
  32. Manage agents with Microsoft Agent 365
    1. Enable and navigate Microsoft Agent 365
    2. Register agents and apply access controls
    3. Monitor agent activity and enforce governance
  33. Identify AI data risks with Microsoft Purview Data Security Posture Management
    1. Configure Data Security Posture Management for AI
    2. Assess SharePoint overexposure
    3. Identify risks in Copilot and AI application interactions
  34. Implement disk encryption for Azure virtual machines
    1. Choose an Azure VM disk-encryption option
    2. Configure encryption at host with customer-managed keys
    3. Apply confidential disk encryption
  35. Configure Trusted Launch security features for Azure virtual machines
    1. Identify Trusted Launch components and VM security types
    2. Enable Trusted Launch on new and existing Gen2 VMs
    3. Migrate Gen1 VMs and configure Trusted Launch components
    4. Enforce adoption with Azure Policy
  36. Plan and implement Azure Bastion
    1. Plan an Azure Bastion deployment
    2. Deploy and configure Azure Bastion
    3. Connect to VMs through Azure Bastion
  37. Manage security for Arc-enabled hybrid servers
    1. Control access and extension security
    2. Apply Azure Policy
    3. Monitor server security posture in Defender for Cloud
  38. Implement Microsoft Defender for Servers
    1. Onboard servers
    2. Configure vulnerability scanning
    3. Configure Defender for Endpoint integration, agentless scanning, and File Integrity Monitoring
  39. Enable and enforce just-in-time VM access
    1. Examine access requirements and VM eligibility
    2. Enable and configure JIT access policies
    3. Request JIT access and audit activity
  40. Enforce VM security configuration with Azure Machine Configuration
    1. Explore extension capabilities and modes
    2. Apply built-in security baseline policies
    3. Author and assign custom machine configurations
  41. Detect container risks with Microsoft Defender for Containers
    1. Explore Defender for Containers
    2. Enable and configure protection
    3. Assess container image vulnerabilities
    4. Detect runtime threats and misconfigurations
  42. Implement security controls for Azure Kubernetes Service
    1. Control cluster access with Microsoft Entra ID and RBAC
    2. Secure AKS network access
    3. Implement workload identity and secrets management
    4. Enforce pod and container security
  43. Implement security controls for Azure Container Registry, Container Instances, and Container Apps
    1. Secure Azure Container Registry
    2. Secure Azure Container Instances
    3. Secure Azure Container Apps
  44. Implement security controls for Azure Function Apps and Logic Apps
    1. Configure authentication and authorization for Function Apps
    2. Secure Function Apps network access
    3. Implement Logic Apps security controls
  45. Implement security controls for Azure App Service and Web Application Firewall
    1. Implement Azure App Service security controls
    2. Configure Web Application Firewall policies
    3. Protect App Service with Web Application Firewall
  46. Implement API backend security with Azure API Management
    1. Configure API authentication and authorization policies
    2. Implement API network security and threat protection
    3. Secure backend connections
    4. Configure AI Gateway in API Management for Azure AI Foundry
  47. Connect hybrid and multicloud environments to Microsoft Defender for Cloud
    1. Explore the multicloud connectivity model
    2. Plan a hybrid and multicloud connector strategy
    3. Connect on-premises machines with Azure Arc
    4. Connect AWS accounts and GCP projects
    5. Verify coverage and validate protection
  48. Identify security risks with Cloud Security Posture Management
    1. Explore CSPM plans and posture visibility
    2. Analyze risk-prioritized recommendations
    3. Identify attack paths and choke points
    4. Hunt for risks with cloud security explorer
  49. Discover unprotected assets and vulnerabilities with Microsoft Defender External Attack Surface Management
    1. Explore EASM features and capabilities
    2. Discover assets recursively
    3. Analyze the attack surface with dashboards
    4. Integrate EASM insights with Defender for Cloud
  50. Evaluate regulatory compliance in Defender for Cloud
    1. Understand compliance standards and controls
    2. Investigate control gaps in the regulatory compliance dashboard
    3. Assign standards and communicate compliance posture
  51. Enable and configure workload protection plans in Microsoft Defender for Cloud
    1. Understand the Cloud Workload Protection Platform plan catalog
    2. Enable workload protection plans
    3. Configure Defender for Storage and Defender for Databases
    4. Deploy plans at scale and verify coverage
  52. Configure Microsoft Defender Vulnerability Management for Azure VMs
    1. Explore integration with Defender for Servers
    2. Configure vulnerability scanning
    3. Review and manage findings
    4. Apply Plan 2 premium capabilities
  53. Create and manage Microsoft Sentinel workspaces
    1. Plan and create a workspace
    2. Manage workspaces across tenants with Azure Lighthouse
    3. Understand permissions and roles
    4. Manage settings and configure logs
    5. Module assessment
  54. Manage content in Microsoft Sentinel
    1. Use solutions from the content hub
    2. Use repositories for deployment
    3. Module assessment
  55. Connect Microsoft services to Microsoft Sentinel
    1. Plan Microsoft service connectors
    2. Connect Microsoft 365
    3. Connect Microsoft Entra and Microsoft Entra ID Protection
    4. Connect Azure Activity
    5. Module assessment
  56. Connect syslog data sources to Microsoft Sentinel
    1. Plan syslog data collection
    2. Collect data from Linux-based sources
    3. Configure a data collection rule
    4. Parse syslog data with KQL
    5. Module assessment
  57. Connect Common Event Format logs to Microsoft Sentinel
    1. Plan for the Common Event Format connector
    2. Connect an external solution
    3. Module assessment
  58. Connect Windows hosts to Microsoft Sentinel
    1. Plan Windows host security event collection
    2. Connect with the Windows Security Events via AMA connector
    3. Connect with the legacy agent connector
    4. Collect Sysmon event logs
    5. Module assessment
  59. Implement automation rules and playbooks in Microsoft Sentinel
    1. Understand automation options
    2. Create automation rules
    3. Configure and activate a Content Hub playbook
    4. Author a custom playbook with Azure Logic Apps
  60. Manage data storage and query audit logs in Microsoft Sentinel
    1. Create custom log tables
    2. Implement data retention
    3. Connect Microsoft Purview Audit
    4. Query Purview Audit logs in Microsoft Defender XDR
  61. Describe Microsoft Security Copilot
    1. Explore Microsoft Security Copilot and its terminology
    2. Describe prompt-request processing
    3. Describe effective prompt elements
    4. Describe how to enable Security Copilot
    5. Module assessment
  62. Configure workspaces for Microsoft Security Copilot
    1. Plan a workspace deployment
    2. Create a workspace
    3. Configure access and settings
    4. Assign workspaces for integrated agents
    5. Monitor and manage workspace capacity
  63. Manage plugins and agents in Microsoft Security Copilot
    1. Configure plugin settings
    2. Discover and set up Microsoft-built agents
    3. Acquire and configure partner agents from Security Store
    4. Manage Security Copilot agents

Class Materials

Each student receives a comprehensive set of materials, including course notes and all class examples.

Class Prerequisites

Experience in the following is required for this Azure class:

  • Practical experience administering Microsoft Azure and hybrid environments, including compute, networking, and storage.

Experience in the following would be useful for this Azure class:

  • Strong familiarity with Microsoft Entra ID.
  • Familiarity with Microsoft 365 administration.

Have questions about this course?

We can help with curriculum details, delivery options, pricing, or anything else. Reach out and we’ll point you in the right direction.