
This course uses a free, exam-focused study guide e-book as support material, including definitions and diagrams, to help you navigate the topics and prepare for the AZ-500 exam.
Provide an honest review to help others prepare for the A-Z 500 exam and improve the course content and coverage.
Explore Azure Active Directory in the scope of identities, covering users, groups, conditional access, and privileged identity management with app restrictions to prepare for the exam.
Manage Azure AD users by understanding cloud identities, directory synchronized identities, and guest users, provisioning accounts, configuring authentication and MFA, and performing soft deletion and recovery.
Learn to secure Azure AD groups using security groups and Microsoft 365 groups to assign permissions. Understand static and dynamic membership, dynamic device allocation, and P1 licensing in the portal.
Explore how external identities in Azure AD enable B2B collaboration, B2B direct connect, and B2C scenarios, with social logins, OpenID authentication protocol or SAML, and robust guest access controls.
Explore Azure AD identity protection to automate detection and remediation of identity-based risks. Configure MFA registration, risk remediation, risk events, and actions with licensing options and actionable risk levels.
Create administrative units to group users, groups, and devices, then delegate permissions and assign roles to target groups such as finance to manage access.
Explore passwordless authentication options in Azure Active Directory, including FIDO2 keys, Windows Hello for Business, and Microsoft Authenticator, and learn benefits like reduced phishing and improved user experience.
Enforce strong passwords with Azure AD Password Protection by blocking global and custom banned passwords using fuzzy match and score calculations to deter spray attacks.
Synchronize on-prem identities to Azure AD with Azure AD Connect to enable single sign-on across cloud environments, and configure federation, seamless authentication, and password hash synchronization for multi-cloud enterprise applications.
Configure role-based access control with assignable scopes across management groups, subscriptions, resource groups, and resources to grant granular permissions, using inheritance and the least-privileged principle.
Discover how to interpret built-in and custom roles in Azure resources and Azure AD, and grant the minimum permissions with data actions, data plane, and a granular view of permissions.
Assign built-in azure ad roles from the portal by selecting roles and administrators, then create an active, permanent assignment for the application administrator with a chosen scope and member.
Learn to create and assign custom roles for Azure resources and Azure AD, using built-in roles as a base, configuring actions, data actions, and assignable scopes.
Discover, remediate, and monitor permissions across Azure, AWS, and GCP with Microsoft Entra permissions management to govern identities and automate just-in-time access.
Configure Azure AD Privileged Identity Management to grant just-in-time and time-bound access to Azure AD roles, enforce approval and MFA, and track activations for audits.
Explore how Azure AD access reviews control resource access by periodically validating employees' permissions, selecting reviewers, setting frequency, and automating actions for privileged roles.
Define and enforce conditional access policies in Azure AD using signals to grant or block access to apps like the Azure Portal and Office, including MFA.
Create and configure an app registration as a service principal in Azure AD, assign permissions to access resources like storage accounts or key vault, and manage application secrets.
Configure app registrations to define permission scopes using OAuth 2.0, enabling applications to request delegated or application permissions for resources like Graph API and Azure Vault.
Learn to manage app registration permission consent with Microsoft Graph, comparing delegated permissions that require user or admin consent and application permissions that grant full access without sign-in.
Explore authentication methods for a service principal, including app ID with a secret key, certificate uploads, and federated credentials that impersonate your app registration to Azure AD using OpenID Connect.
Create and manage a managed identity from Azure AD to enable secure, credential-free authentication, and understand system assigned and user assigned identities with Key Vault and function apps.
Explore how to use Azure APIs to manage subscriptions and resources, create resource groups via service principal authentication and a custom role, and test calls with Postman.
Review the key concepts of identity and access management, including managed identities, groups, administrative units, privilege identity management, conditional access, and the principle of least privilege.
Explore networking concepts and protection for compute services, including Azure Firewall, Application Gateway, and serverless compute, as we implement platform protection.
Plan and implement network security groups and application security groups to control traffic in networks. Use priority-based inbound and outbound rules and service tags for easier management and stateful security.
Create and apply network security groups and application security groups to virtual machines, subnets, and NICs, controlling inbound and outbound traffic. Demonstrate denying RDP inbound and enforcing prioritized rules.
Explore hybrid connectivity between on-premises and cloud using VPN gateway or express route; cover point-to-site, site-to-site, and multi-cloud VPNs, along with authentication options (certificate, Radius, Azure AD) and IPsec/IKEv2 encryption.
Configure and deploy a virtual network gateway to secure hybrid network connectivity using VPN, site-to-site, and point-to-site connections. Explore route-based vs policy-based VPN, BGP, throughput considerations, and IPsec/IKE encryption options.
Configure firewall settings on PaaS resources to whitelist IPs, disable public access, and use private IPs or Microsoft trusted services for Key Vault, SQL Server, Storage, and apps.
Plan and implement Azure service endpoints to route traffic internally from subnets to storage and other services, enabling secure, whitelisted access and preventing data exfiltration.
Plan and implement private endpoints to securely access Azure services from your virtual network, using private IPs, private DNS zones, and hub-and-spoke traffic routing to prevent data exfiltration.
Plan and implement Azure private link services with private endpoints to securely connect apps inside the Microsoft network, using a standard load balancer, NAT IP, and an approval workflow.
Explore securing Azure App Service and Azure Functions by isolating inbound and outbound traffic with private endpoints, VNet integration, access restrictions, and hybrid connections.
Implement network isolation for Azure Synapse data solutions using service firewalls, private endpoints, and managed virtual networks to secure SQL pool, serverless, Spark pools, pipelines, and Cosmos DB.
Secure communications between clients and servers by enforcing TLS across Azure services, using HTTPS, custom domains, and certificates to prevent man-in-the-middle attacks.
Plan, implement, and manage an Azure firewall to monitor, filter, and route traffic across hub-spoke networks, using force tunneling, threat intelligence, network rules, NAT translation, and RDP blocking.
Deploy and configure an Azure Firewall with a premium policy and set up firewall rules and route tables. Block internet access by default while whitelisting specific domains via DNS.
Discover how Azure firewall manager provides centralized policy management for multiple network security resources, including Azure firewalls, DDoS protection, and web application firewalls, with hub-spoke and secured virtual hub architectures.
Plan and implement an Azure application gateway to load balance http/https traffic at layer 7, route by header or body to backend pools, with listeners, rules, and ssl termination.
Plan and implement Azure Front Door to globally accelerate content delivery by routing traffic to the nearest point of presence, with built-in WAF, DDoS protection, and latency-based routing.
Discover how a web application firewall uses managed and custom rules in detection or prevention mode, safeguarding apps and shaping policies across front door, application gateway, and cdn.
Azure DDoS Protection Standard provides enhanced protection with Azure Monitor visibility for per-application resources, including virtual machines, network interfaces, an application gateway, and virtual networks, plus expert support during attacks.
Discover azure secure networking options, including site-to-site, point-to-site, vnet-to-vnet, and express route, plus ssg traffic filtering and azure front door for globally distributed applications.
Learn to securely access virtual machines with Azure Bastion, using browser-based rdp/ssh without public IPs, plus setup steps, subnet requirements, tier options, and native client support.
Plan and implement remote access to public endpoints using just in time access (JIT) to protect virtual machines by enabling management ports like RDP within time windows and approved IPs.
Secure container services by enabling Defender for container registries and Defender for access, automatically scanning images on push, enforcing only approved images with Azure policies, and monitoring with Azure Monitor.
Discover how to manage access to Azure container registry with service principals, individual identities, and admin users, and understand role permissions like ACR push and pull in the portal.
Configure disk and server side encryption in Azure. Use platform managed or customer managed keys via Azure Key Vault with Windows Disk Encryption and Linux DM Encrypt System.
Configure endpoint protection for virtual machines by installing anti-malware extensions, configuring real-time protection and scans, and integrating with Azure Defender or Azure Policy for automated deployment, auditing, and compliance.
Learn to manage security updates for virtual machines using automatic VM guest patching and update management with automation accounts, linked to log analytics, run books, and Azure Defender reporting.
Configure security for serverless compute across containers, Kubernetes, and function environments with private registry, monitoring and log analytics, key vault, http endpoints, and private endpoints for App Service and Functions.
Explore authentication and authorization options for storage accounts, including account keys, shared access signatures, and Azure Active Directory, with a focus on delegated access and SFTP support for blobs.
Learn to manage storage account keys and SAS tokens, rotate keys, and use account SAS, service SAS, and user delegation SAS with access policies to control permissions.
Configure user delegation SAS with Azure AD credentials, enforce least-privilege permissions and RBAC, and test seven-day duration of access using Storage Explorer.
Enable Azure Active Directory authentication for storage accounts to provide traceable, role-based access to blob data and file shares via Azure Active Directory Domain Services for smb access.
Learn to protect Azure blob storage with data protection features, including soft delete, blob and container recovery, versioning, and backups with configurable retention periods.
Enable blob versioning to track changes, view file history, and restore previous versions by overwriting with the same name, while watching for higher storage costs.
Learn how immutable storage protects Azure blob data with time-based and legal hold policies, covering container and blob version immutability and the implications of policy locking.
Explore how to protect Azure Blob storage with backups, enabling soft delete, versioning, and blob change feeds, and using a backup vault to manage retention and restores.
Learn how bring your own key enables cloud or on-premises encryption using customer keys imported to Azure Key Vault, including software and HSM-protected keys.
Discover how to enable double encryption at the Azure storage infrastructure with customer managed keys from Azure Key Vault or Azure managed HSM, including creation-time setup and encryption scopes.
Become an Azure Security Engineer with this AZ-500 Exam Prep Course! This comprehensive course is designed to provide IT professionals with the knowledge and skills needed to pass the Microsoft AZ-500 exam and obtain the highly-desired Azure Security Engineer Associate certification. You will gain a deep understanding of all exam objectives. Give your career the boost it needs and enroll today!
Learn by Doing
Hands-on activities
157-page e-book (free and exclusive)
Access to resource template library on GitHub
In-depth demonstrations led by a Microsoft Certified Trainer
Quizzes to test your knowledge
30-Day Money Back Guarantee ★★★★★
I want you to be satisfied, so if for whatever reason you are unhappy with the course, you can request a partial or full refund within 30 days.
Skills Measured
Below you can find the list of topics covered in this course.
Manage Identity and Access
Manage Identities in Azure AD
Secure users in Azure AD
Secure Directory Groups in Azure AD
Recommend When to Use External Identities
Implement Azure AD Identity Protection
Manage Administrative Units
Manage Authentication by Using Azure AD
Implement Passwordless Authentication
Implement single sign-on (SSO)
Integrate Single Sign-on (SSO) and Identity Providers
Manage Authorization by Using Azure AD
Configure Azure Role Permissions for Management Groups, Subscriptions, Resource Groups, and Resources
Assign Built-in Roles in Azure AD
Interpret Role and Resource Permissions
Create and assign custom roles, including Azure roles and Azure AD roles
Configure Azure AD Privileged Identity Management (PIM)
Configure Role Management and Access Reviews by using Microsoft Entra Identity
Implement Conditional Access policies
Manage Application Access in Azure AD
Manage App Registrations in Azure AD
Configure App Registration Permission Scopes
Manage App Registration Permission Consent
Manage and Use Service Principals
Manage Managed Identities for Azure Resources
Manage API Permissions to Azure Subscriptions and Resources
Secure Networking
Plan and Implement Security for Virtual Networks
Plan and implement Network Security Groups (NSGs) and Application Security Groups (ASGs)
Secure the connectivity of virtual networks
Configure firewall settings on PaaS resources
Plan and Implement Security for Private Access to Azure Resources
Plan and Implement Virtual Network Service Endpoints
Plan and Implement Private Endpoints
Plan and Implement Private Link services
Plan and Implement Network Integration for Azure App Service and Azure Functions
Implement Network Isolation for Data Solutions, Including Azure Synapse Analytics and Azure Cosmos DB
Plan and Implement Security for Public Access to Azure resources
Plan and Implement TLS to Applications, Including Azure App Service and API Management
Plan, Implement, and Manage an Azure Firewall
Plan, Implement, and Manage an Azure Firewall Manager and Firewall Policies
Plan and Implement an Azure Application Gateway
Plan and implement an Azure Front Door, Including Content Delivery Network (CDN)
Plan and implement a Web Application Firewall (WAF)
Recommend when to use Azure DDoS Protection Standard
Secure Compute, Storage, and Databases
Plan and Implement Advanced Security for Compute
Plan and implement remote access to public endpoints, including Azure Bastion
Plan and implement remote access to public endpoints, including Just-in-Time Access (JIT)
Configure Security for Container Services
Manage access to Azure Container Registry (ACR)
Configure Disk Encryption, Including Azure Disk Encryption (ADE), Encryption as Host
Configure Endpoint Protection for virtual machines (VMs)
Implement and manage security updates for VMs
Configure Security for Serverless Compute
Plan and Implement Security for Storage
Configure Access Control for Storage Accounts
Manage Fife Cycle for Storage Account Access Keys
Configure Delegated Access
Select and Configure an Appropriate Method for Access to Azure Files
Plan and Implement Security for Azure SQL Database and Azure SQL Managed Instance
Enable Database Authentication by Using Microsoft Azure Active Directory (Azure AD), part of Microsoft Entra
Enable Database Auditing
Plan and Implement Dynamic Masking
Implement Transparent Database Encryption (TDE)
Manage Security Operations
Plan, Implement, and Manage Governance for Security
Create, Assign, and Interpret Security Policies in Azure Policy
Create, Assign, and Interpret Security Initiatives in Azure Policy
Create and Configure an Azure Key Vault
Recommend when to use a Dedicated HSM
Configure Access to Key Vault, Including Vault Access Policies and Azure Role Based Access Control
Manage Certificates, Secrets, and Keys
Configure Key Rotation
Configure Backup and Recovery of Certificates, Secrets, and Keys
Configure and Manage Threat Protection by Using Microsoft Defender for Cloud
Add industry and regulatory standards to Microsoft Defender for Cloud
Configure and Manage Threat Protection by Using Microsoft Defender for Cloud
Configure Microsoft Defender for Servers
Configure Microsoft Defender for Azure SQL Database
Evaluate Vulnerability Scans from Microsoft Defender for Server
Configure and Manage Security Monitoring and Automation Solutions
Create and Customize Alert Rules by Using Azure Monitor
Configure Diagnostic Logging and Log Retention by using Azure Monitor
Monitor Security Events by Using Azure Monitor
Configure Data Connectors in Microsoft Sentinel
Create and Customize Analytics Rules in Microsoft Sentinel
Evaluate Alerts and Incidents in Microsoft Sentinel