
Explore Azure fundamentals and security across Azure Active Directory, privileged identity management, network and host protection, container security, governance, security operations, and key management.
Get a concise overview of the Azure platform, covering cloud models, regions, resource groups, VNet and NSGs, app and database services, containers, AI, IoT, and the portal and cloud shell.
Learn to create an Azure free account with $200 credit, sign up with a Microsoft account, and manage subscriptions and access via Azure Active Directory roles.
Apply defense in depth as a layered Azure security strategy built on confidentiality, integrity, and availability, enforcing least privilege, securing data with one-way hashes, and ensuring availability for authorized users.
Explore defense in depth by examining security layers—from physical security to identity, perimeter, network, compute, application, and data protection—to ensure data remains secure even if one layer is breached.
Understand shared responsibility model across on premises, IaaS, PaaS, and SaaS, and apply data, endpoints, accounts, and multifactor authentication governance using the trust center, compliance manager, and blueprints for audits.
Explore how Azure Active Directory centralizes identity across on premises and cloud apps, enabling single sign-on, self-service password reset, and multi-factor authentication.
Create a new Azure Active Directory tenant from the Azure portal and assign a unique domain on Microsoft.com. Learn that subscriptions map 1-to-1 with tenants and global administrator manages access.
Move a subscription between Azure directories in the portal, handling directory changes and rbac permissions. Refresh filters and log back in if the subscription doesn't appear after transfer.
Learn to create users and groups in an Azure Active Directory tenant using the portal, assign directory roles, and apply RBAC to manage access at the subscription level.
Configure self-service password reset in Azure AD by selecting users and required verification methods, including email, mobile, or security questions.
Azure AD Connect synchronizes on-premises Active Directory with Azure AD, enabling filtering and password hash synchronization, plus device and password writeback and health monitoring.
Connect on-premises Active Directory to Azure Active Directory using AD Connect, configure synchronization, and verify user provisioning from the domain controller to Azure AD.
Learn to monitor Azure AD Connect Health to track sync status, on-premises domain controllers, and active directory services, including alerts, replication status, and health analytics.
Explore cloud and hybrid authentication options for Azure AD, including password hash sync with seamless SSO, pass-through authentication, and federated authentication with ADFS.
Learn how single sign-on with Azure AD Connect lets you access services after logging into your device with Active Directory credentials, then review multi-factor authentication and its verification methods.
Create an Azure AD application registration, generate a key, and establish a service principal to log in as the application and deploy VMs and ARM templates.
Register a new Azure AD application, create a service principal, assign a contributor role, and secure it with a key to enable authentication for Azure services using PowerShell.
Explore how to create and view an app registration in Azure Active Directory, manage certificates and secrets, and set API permissions and admin consent.
Discover Azure Active Directory identity protection, using adaptive machine learning to detect risky sign-ins and compromised accounts, and protect identities with risk-based conditional access and remediation actions.
Configure identity protection in the Azure portal using Azure AD premium P2, set up conditional access and MFA registration, and review risk events and sign-in risk.
Discover how privileged identity management (PIM) controls high-privilege access in Azure AD and subscriptions, enabling on-demand, time-bound, workflow-driven elevation with MFA, approvals, and activity visibility.
Configure Azure privileged identity management in the portal, enable multi-factor authentication, assign licenses, and manage Azure AD roles with eligible versus permanent access using the setup wizard.
Discover how to assign resource roles with Azure RBAC via Privileged Identity Management, onboard resources to a subscription, and manage owner and contributor roles with eligible and active assignments.
Activate privileged roles in Azure AD and RBAC using Privileged Identity Management, verify identity with MFA, and manage activation duration and deactivation for global administrator and subscription owner.
Explore Azure networking basics: hub-and-spoke model, hub VNet, peering, on-premises connections, VNets and subnets with address space, network security groups, public vs private IP, and SKU options.
Create an Azure virtual network in the portal, define an address space and subnets such as subnet A and subnet B, and explore optional DDoS protection and service endpoints.
Create an Azure virtual network and subnets with PowerShell, including address space and subnet config. Learn to write changes to the vnet and add or adjust subnets as needed.
Explore virtual network connectivity by focusing on hub-and-spoke, daisy chain, and mesh topologies, and understand vnet peering constraints, gateway transit, and non overlapping ip address spaces.
Demo shows creating a resource group and two virtual networks in the Azure portal, then establishing Vnet peering with bidirectional connectivity, IP address range planning, and optional gateway transit.
Manage routing in Azure subnets with route tables for VNet, on premises, and internet paths. Override routes using udrs to enable force tunneling through Palo Alto firewalls.
Create a route table in the azure portal, attach it to a subnet, and configure a route to a virtual appliance using a destination prefix.
explains Azure vnets internet access by default via snat to a public ip and outlines inbound options, DNS scenarios, and private versus customer managed DNS.
Demonstrate setting up a private DNS zone in Azure, link it to a virtual network, create records such as db.private.skylines.com, and verify name resolution between two VMs.
Explore dns zones in Azure dns, create and manage a dns zone, add an a record, then validate with nslookup while guiding domain configuration with GoDaddy as a security boundary.
Strengthen Azure networking through network access control, NSGs, application security groups, and Azure Firewall, with DNS, traffic routing, and comprehensive threat monitoring and logging.
Explore how Azure network security groups filter traffic with inbound and outbound rules applied at subnet or network interface level, using priorities, default tags, and service tags to control access.
Explore network security groups in the Azure portal by creating a virtual network, configuring inbound and outbound rules, and associating NSGs with subnets to control traffic.
Explore Azure load balancing technologies including basic and standard load balancers, application gateway, and traffic manager; cover layer 4 and 7 concepts, health probes, URL-based routing, and SSL offload.
Configure an internal Azure load balancer to distribute traffic across two virtual machines in an availability set, defining front end, back end pools, health probes, and load balancing rules.
Learn to configure an Azure application gateway in the portal, including public vs private front end IPs, http/https listeners, SSL certificates, and a web application firewall with v2 improvements.
Azure Front Door delivers http acceleration and edge security for web workloads, contrasted with Traffic Manager’s dns-based routing, and routes requests by URL path to backend services.
Set up Azure front door with front end domains, back end pools from two app services, and a default routing rule to forward traffic over https, balancing load across regions.
Azure firewall is a cloud-based, fully stateful security appliance for Azure VNet with built-in high availability, threat intelligence, FQDN filtering, service tags, and SNAT/DNAT support.
Configure an Azure firewall within a single VNet, create jump box and workload subnets, route traffic through the firewall, and enforce application and network rules.
Explore distributed denial of service attacks, how botnets target networks, and how Azure DDoS Protection Standard mitigates volumetric, protocol, and resource-layer attacks with adaptive tuning and 24/7 monitoring.
Configure a standard DDoS protection plan in the Azure portal, attach it to a virtual network, and monitor inbound DDoS metrics for protected public IPs.
Demonstrates how to use Azure Network Watcher to monitor virtual machines, install the Network Watcher agent, and explore topology, connection monitor, ip flow verify, next hop, and security group views.
Learn how Azure Bastion enables RDP and SSH from the Azure portal over TLS, removes public IPs, and enhances security against port scanning and zero-day exploits.
Explore Microsoft Azure virtual machines, including common series and specialized instances, performance with Azure Compute Units, regional availability, and selecting VM types for applications.
Demonstrates deploying a Windows virtual machine from the Azure portal, detailing subscription, resource group, region, image, size, admin, RDP port, disks, networking, availability options, and ARM template options.
Deploy an Azure virtual machine with PowerShell by creating a resource group, a virtual machine, and network components, then connect via RDP and manage using PowerShell commands.
Explore how to configure Azure availability sets and zones for virtual machines, including fault domains, update domains, and region-based data center mapping.
Explore Azure VM storage options from standard HDD to premium and ultra SSD, with managed disks, performance metrics, and replication options (LRS, GRS, RA-GRS) for disaster recovery.
Add a new data disk to an existing Azure VM in the portal, create a premium SSD disk, attach and format it as the F drive in Windows.
Use disk caching to boost performance of virtual hard disks by leveraging local RAM and SSD on the host, including OS disks defaulting to read/write.
Enable disk caching on a virtual machine using PowerShell and the Azure portal, setting the data disk VM zero two disk two to read-write caching and validating the change.
Implement VM security best practices in Azure by applying policies, RBAC, ARM templates, and JIT VM access to control access, enforce encryption, patching, backups, and security posture monitoring.
Learn how Azure disk encryption protects OS and data disks with BitLocker on Windows and DM-Crypt on Linux, integrated with Key Vault for encryption keys.
Demonstrates creating an Azure key vault for disk encryption via portal or cloud shell, including resource group setup in East US and enabling disk encryption access policies.
Configure disk encryption on a Windows VM using an existing key vault via the Azure CLI, enabling BitLocker and verifying encryption with the Azure disk encryption extension.
Learn to configure Azure Security Center with a Log Analytics workspace, provision a Windows Server 2016 VM, install the monitoring agent, and connect data for endpoint protection and vulnerability monitoring.
Hardens a virtual machine in security center by installing the monitoring agent, enabling endpoint protection with Microsoft anti-malware, and connecting to log analytics for data in security center.
Share candid feedback on the course quality and content to help improve this az-500 azure security technologies course.
Explore how docker containers package apps and dependencies to isolate services on the same OS kernel, enabling microservices, horizontal scaling, and data decoupling in Azure.
Install docker desktop for windows and git for windows to enable container demos, sign into docker hub, switch to linux containers for this demonstration, and verify docker and git versions.
Prepare an application for Azure Kubernetes Service by cloning the Microsoft samples repo, configuring a Docker Compose multi-container app with a front end and Redis session store, and testing locally.
Demonstrates creating a private Azure Container Registry with the Azure CLI, tagging a local image, pushing it to the registry, and validating the repository contents.
Create an Azure AKS cluster, configure a service principal and ACR access, and provision a single node using the Azure CLI; then connect with kubectl to verify readiness.
Learn to deploy a containerized app on Azure Kubernetes Service, update manifests, expose via an external IP, and scale pods and the cluster with kubectl and AKS tools.
Secure the container registry by managing access keys, enabling admin login, rotating passwords, and applying RBAC with service principals, plus firewalls, a premium SKU, and resource locks.
Secure AKS with layered protections from Microsoft-managed master security to node and container controls, including identity and access management with RBAC. Upgrade Kubernetes safely in the Azure portal.
Learn about container vulnerability management and container scanning in securing deployments. Explore third-party tools like Twistlock, Aqua, and Sysdig in Azure Marketplace for image scanning in the DevOps lifecycle.
Demonstrates implementing role-based access in Azure by creating a security group, assigning the reader role at the subscription or resource group, and applying access to users or groups.
Enforce governance with Azure policy, using built-in or custom rules to restrict actions across subscriptions or resource groups, created and assigned via portal or PowerShell.
Demonstrates implementing an Azure region policy to restrict deployments to approved locations via portal or ARM templates, assigning allowed locations, and enforcing governance with policy violations for disallowed regions.
Explore subscription policies in the Azure portal to enforce what users can do within a subscription. Assign policies, choose scope, and apply built-in definitions for common controls.
Explore how Azure resource locks prevent accidental deletion, with two options: cannot delete and read only, and why read only is the most restrictive.
Demonstrates implementing a delete lock on an Azure resource group to prevent deletion of storage accounts, using the Azure portal and testing the protection.
Discover Azure Monitor and alerts in the Azure portal, view metrics and logs, create alert rules with action groups, pin dashboards for VM zero one, and monitor host metrics.
Explore how log analytics centralizes monitoring by ingesting data sources such as Windows events, perf counters, and Azure Security Center, then querying, visualizing, and sending alerts across dashboards.
Explore Log Analytics in the Azure portal: create a Log Analytics workspace, connect data sources, run queries like heartbeat and performance logs, and build dashboards with alerts and solutions.
Explore Azure Security Center overview, featuring centralized policy management, continuous security assessment with actionable recommendations, just-in-time access, network and VM threat detection, and cross-solution integrations.
Explore how to prevent and respond to threats using Azure Security Center, configuring data collection, security policy, and alerts, and enabling just-in-time VM access, endpoint protection, and adaptive application controls.
Explore Azure Security Center to configure policy and compliance and view secure score. Install agents on VMs, enable threat and endpoint protection, and activate just-in-time access and adaptive network hardening.
Explore Azure SQL services as a managed relational database, with predictable DTUs, high compatibility, and simplified management, plus migrations via the Data Migration Assistant and managed instances.
Explore Azure SQL auditing options for compliance and data access, distinguishing server-level from database-level policies, with logs stored in Azure blob storage and routed to event hubs or Splunk.
Explore SQL long term backup retention in Azure, configure weekly, monthly, and yearly backups up to ten years, and admire the cloud-managed alternative to tape vaults.
Explore Azure Cosmos DB, a globally distributed schemaless NoSQL database for low-latency apps. See how regional routing, multi-region replication, and native APIs like Documentdb and MongoDB enable portable, scalable data.
Explain Cosmos DB consistency levels from strong to eventual, detailing primary replicas, bounded staleness, session guarantees, and the trade-offs between performance and data consistency for global apps.
Learn to secure the Azure Data Lake Store by authenticating with Azure Active Directory, applying access and default ACLs, and managing encryption with Key Vault options and keys.
Demonstrates provisioning an Azure data lake store, enabling encryption, configuring firewall rules, and assigning access with Azure AD identities for secure data access.
Explain structured, semi-structured, and unstructured data, including SQL-relational tables, NoSQL tagging, and blob storage for PDFs, images, and videos, and identify suitable Azure storage and database services for various applications.
Welcome to the Refactored AZ-500 Course! (UPDATED September 2020)
Properly securing resources while making them available to users that require access is a constant concern within an IT and cloud environment. This course will explore how to manage identities, provide role-based access, and secure data within an Azure ecosystem.
During your journey, Refactored will lead you through a series of sections, modules, and demos to prepare you for taking, and ultimately passing, the Microsoft Azure AZ-500 exam.
What you will learn:
Know how to implement secure infrastructure solutions in the Microsoft Azure platform
What you need to pass the AZ-500 - Microsoft Azure Security Technologies Certification
Azure security core services and capabilities
Refactored Course Outline:
Introduction and Study Resources
Azure Security Overview
Azure Active Directory Workloads
Privileged Identity Management & Tenant Security
Platform Protection: Network Security
Platform Protection: Host Security
Containers and Security
Governance and Role-Based Access Control (RBAC)
Security Operations
Securing Data Services
Storage Security
Key Management
Application Security
Lectures will educate you on the fundamental terms and principles of the Azure platform and demos will enable you with a hands-on experience using scenarios to empower you in the real world.
Thank you for joining us,
Nick, Dwayne, & the Refactored Team