
Discover how to secure Azure environments with virtual machines, PIM, multifactor authentication, Azure Key Vault, Conditional Access App Registration, policies, locks, and network and app security groups.
Create a free Azure subscription to access 12 months of free Azure services, a $200 credit, and a 30-day window for labs, enabling virtual machines, databases, and storage accounts.
Entra ID, formerly Azure Active Directory, is a multi-tenant cloud directory and identity service that enables single sign-on for Microsoft 365, Salesforce, and other apps, with users, groups, and devices.
Demo of Entra ID in the Azure portal, covering users, groups, devices, and licenses, with note that Azure Active Directory is now Microsoft Entra ID and basic tenancy concepts.
Create a new Entra ID user named Jake Roberts with a custom password, set usage location, and assign roles such as user administrator, then review audit and sign-in logs.
Learn how to invite external users as guests in Entra ID, send email invitations, set usage location and group roles, and complete activation via the invitation workflow.
Learn about Entra ID groups, including Microsoft 365 groups and security groups, and use direct, nesting, and dynamic membership plus validation tool to manage access in Azure, noting 24-hour propagation.
Create a security group named sales-users in Entra ID, using dynamic user membership with department equals sales; validate the rule to confirm Roy's membership.
Discover how Entra ID manages Microsoft 365 group expiration by configuring group lifetimes, enabling 30/15/1 day renewal notifications, and requiring exchange license for email alerts with an owner or helpdesk.
Create a custom azure rbac role from scratch, selecting permissions like manage user licenses and update basic user properties, then assign the role to users or groups.
Explore privileged identity management (PIM) in Azure, enabling just-in-time activation of roles like user administrator with optional MFA, approvals, and access reviews to control privileged access.
Learn how to configure privileged identity management (PIM) in Azure AD, assign eligible and active roles, and require multi-factor authentication for activation.
Apply the zero trust model that never assumes trust and continually verify users and devices. Limit access based on authentication and device signals, possibly enforcing multi-factor authentication.
Explore how to set up an Azure Key Vault: assign a vault owner, select a resource group and region, grant access to keys, secrets, and certificates, and monitor audit logs.
Discover how Azure Key Vault centralizes secrets, keys, and certificates for app authentication and data encryption. Understand hardware security modules, FIPS 142 and 140-3, and BYOC for trusted key management.
Learn how to manage Azure Key Vault administration, assign security team roles, and enforce access policies for developers, operators, and auditors, including key and secret management, backups, and compliance considerations.
Register your application with Azure Active Directory to outsource authentication and manage access, supporting five primary scenarios.
The lecture guides you through creating a new app registration in Azure Active Directory, selecting account types, defining redirect and branding, and configuring permissions, tokens, and ownership.
Enforce organizational standards with Azure policy and monitor compliance via the dashboard, tracking compliant and non-compliant resources while enabling encrypted drives, threat detection, and location constraints.
Explore the pitfalls of applying Azure locks, including read-only locks on storage accounts, app services, resource groups, and subscriptions, and delete locks that can disrupt keys, backups, and ongoing operations.
Welcome to Azure Security: AZ-500 course!
In this course you will learn how to provide a high level of security to the entire Azure platform, which is currently one of the most in-demand skill sets as cyber security threats continue to rise and target cloud based resources.
May 2024 updates:
8: Entra ID Overview
9: Demo: Entra ID Overview
10: Entra ID Users
11: Demo: Entra ID Users
12: Demo: Entra ID External Users
13: Demo: Creating an Admin Entra ID User Account
14: Demo: Entra ID Premium 2 (P2 ) Activation
15: Entra ID Groups
16: Entra ID Group Expiration
17: Demo: Creating a New Entra ID Group
18: Demo: Entra ID Group Expiration
19: Self-Service Password Reset (SSPR)
20: Demo: Self-Service Password Reset (SSPR)
21: Planning for Role Based Access Control (RBAC)22: Demo: Entra ID Roles
23: Management Groups
24: Demo: Azure Roles
25: Custom Roles Based Access Control (RBAC)
26: Demo: Custom Roles Based Access Control (RBAC)
37 Demo: Conditional Access
28: Privileged Identity Management (PIM) Scenario
29: Demo: Privileged Identity Management (PIM) Scenario
31: Identity Protection
32: Identity Protection Roles
33: Demo: Identity Protection Roles
34: Security Defaults
35: Demo: Security Defaults
36: Conditional Access
37: Demo: Conditional Access
43: Demo: Azure Key Vault
45: Demo: MFA Configuration
46: Demo: Enable MFA
72: Demo: Just In Time (JIT)
74: Azure Firewall Deployment scenario
75: Demo: Deploying Infrastructure using a Custom Template
76: Azure Firewall Deployment
77: Demo: Azure Firewall Deployment
78: Adding Default Routes for the Azure Firewall
79: Demo: Adding a Default Route
80: Adding Application Rule Collections and Network Rule Collections
81: Demo: Application Rules Collection and Network Rules Collection
82: Configuring DNS settings and testing the Azure Firewall Deployment
83: Demo: Testing the Azure Firewall
85: Demo: DDoS Protection Settings
94: Demo: Connecting to Linux Virtual Machines using SSH
July 2023 updates:
This is a list of the skills you will acquire from this course:
Manage Azure Active Directory (Azure AD) identities
• Create and manage a managed identity for Azure resources
• Manage Azure AD groups
• Manage Azure AD users
• Manage external identities by using Azure AD
• Manage administrative units
Manage secure access by using Azure AD
• Configure Azure AD Privileged Identity Management (PIM)
• Implement Conditional Access policies, including multifactor authentication
• Implement Azure AD Identity Protection
• Implement passwordless authentication
• Configure access reviews
Manage application access
• Integrate single sign-on (SSO) and identity providers for authentication
• Create an app registration
• Configure app registration permission scopes
• Manage app registration permission consent
• Manage API permissions to Azure subscriptions and resources
• Configure an authentication method for a service principal
Manage access control
• Configure Azure role permissions for management groups, subscriptions, resource groups, and Resources
• Assign built-in Azure AD roles
• Create and assign custom roles, including Azure roles and Azure AD roles
Implement advanced network security
• Secure the connectivity of hybrid networks
• Secure the connectivity of virtual networks
• Create and configure Azure Firewall
• Create and configure Azure Firewall Manager
• Create and configure Azure Application Gateway
• Create and configure Azure Front Door
• Create and configure Web Application Firewall (WAF)
• Configure a resource firewall, including storage account, Azure SQL, Azure Key Vault, or Azure App Service
• Configure network isolation for Web Apps and Azure Functions
• Implement Azure Service Endpoints
• Implement Azure Private Endpoints, including integrating with other services
• Implement Azure Private Links
• Implement Azure DDoS Protection
Configure advanced security for compute
• Configure Endpoint Protection for virtual machines (VMs)
• Implement and manage security updates for VMs
• Configure security for container services
• Manage access to Azure Container Registry
• Configure security for serverless compute
• Configure security for an Azure App Service
• Configure encryption at rest
• Configure encryption in transit
Configure centralized policy management
• Configure a custom security policy
• Create a policy initiative
• Configure security settings and auditing by using Azure Policy
Configure and manage threat protection
• Configure Microsoft Defender for Servers
• Configure Microsoft Defender for SQL
Configure and manage security monitoring solutions
• Create and customize alert rules by using Azure Monitor
• Configure diagnostic logging and log retention by using Azure Monitor
• Monitor security logs by using Azure Monitor
• Create and customize alert rules in Microsoft Sentinel
• Configure connectors in Microsoft Sentinel
• Evaluate alerts and incidents in Microsoft Sentinel
Configure security for storage
• Configure access control for storage accounts
• Configure storage account access keys
• Configure Azure AD authentication for Azure Storage and Azure Files
• Configure delegated access
Configure security for data
• Enable database authentication by using Azure AD
• Enable database auditing
• Configure dynamic masking on SQL workloads
• Implement database encryption for Azure SQL Database
• Implement network isolation for data solutions, including Azure Synapse Analytics and Azure Cosmos DB
Configure and manage Azure Key Vault
• Create and configure Key Vault
• Configure access to Key Vault
• Manage certificates, secrets, and keys
• Configure key rotation
• Configure backup and recovery of certificates, secrets, and keys