
Accelerate cloud adoption with speed and control by applying Azure Policy, management groups, and blueprints as governance. Audit and enforce compliance from the start with Resource Graph and Azure Monitor.
Discover how the Azure enterprise scaffold guides cloud governance by structuring management groups, enterprise enrolment, subscriptions, and resource groups with robust naming standards and role-based access control.
Master Azure Policy by defining, assigning, and enforcing policies across management groups, subscriptions, and resource groups, using built-in and custom definitions, parameters, and initiatives that bundle policies.
Compare built-in and custom Azure policy initiatives to audit VMs with insecure password settings and enforce geo-restricted locations, assign to the DevOps resource group, and monitor compliance.
Organize subscriptions into Azure management groups to enforce governance and access controls across all subscriptions with policy and RBAC inheritance.
Create and manage Azure management groups, move subscriptions between groups, and apply policy initiatives to enforce audit controls, while understanding the separation between Azure Active Directory and Azure resources.
Explore how Azure Resource Graph enhances inventory management by providing cross-subscription visibility and governance through policy-based management, management groups, and blueprints to guard resources, manage spend, and assess policy impact.
Explore Azure Resource Graph across subscriptions with the Kusto language; filter, sort, and project resource properties using count, top, and order-by via Azure CLI or PowerShell, and review change history.
Learn how Azure blueprints package RBAC, policy definitions, and ARM templates into reusable, versioned deployments that enforce standards, enable audits, and apply across multiple subscriptions.
Understand how ISO 27001 frames an information security management system with a six-part, risk-based planning process, using Azure blueprints to deploy a shared services virtual data center.
Map ISO 27001 controls to the shared services blueprint in Azure, auditing subscription owners, RBAC, multi-factor authentication, vulnerabilities, cryptographic controls, and policy definitions to ensure secure access and compliance.
Deploy and configure the ISO 27001 shared services blueprint in an enterprise subscription, publish and assign versions, and manage artifacts and location constraints for governed deployments.
Explore Azure Monitor metrics with Metrics Explorer, configure alert rules, autoscale, and route to logs or an Event Hub for a time-series database of platform, guest OS, and application metrics.
Explore how Azure Monitor categorizes data into metrics, logs, and traces, and learn to analyze activity, diagnostic, and application logs with Log Analytics, alerts, and Event Hubs for end-to-end observability.
Explore how Azure Monitor collects and analyzes telemetry from cloud and on-premises, using metrics and logs, Kusto queries, and built-in analytics to improve availability, performance, and governance.
Explore how a storage account holds blobs, files, queues, tables, and disks within a namespace accessible via http or https, and learn the five storage account types and access tiers.
Explore key management strategies and how Azure Key Vault secures keys and secrets, with authentication, authorization, RBAC, and logging to ensure confidentiality, integrity, and availability.
Discover how Azure Active Directory RBAC uses seven built-in roles to authorize access to blob and queue data, scoped from subscription to container or queue.
Discover how Azure Storage security protects data with storage service encryption, AAD and RBAC for management and data operations, and SAS-based delegated access.
Secure the storage account management plane with RBAC across Azure Active Directory, assigning precise roles to access or restrict keys and protect the data plane.
Explore how Azure Active Directory groups assign access to storage accounts using direct, group, rule-based, and external authority methods, and test role-based permissions like reader and storage account contributor.
See how storage account keys control data plane access, how to rotate Key 1 and Key 2, and how Azure Key Vault with AAD and RBAC secures access.
Grant data plane access to a Key Vault by setting access policies and assigning the Key Vault Contributor role, enabling key management with vault-level permissions for keys, secrets, and certificates.
Use shared access signatures (SAS) to grant time-bound, delegated access to blobs, containers, queues, files, and tables. Do not expose account keys; tailor access with permissions, IP ranges, and HTTPS.
Protect data at rest by encrypting on disk with symmetric keys and a DEK–KEK hierarchy. Manage keys in Azure Key Vault with access control, support for server-side and client-side encryption.
Azure Security Engineers implement security controls and threat protection, manage identity and access, and protect data, applications, and networks in cloud and hybrid environments as part of end-to-end infrastructure. This course provides an in-depth study of the security features needed to secure your storage assets and objects in on Microsoft Azure.
As part of the Microsoft Certified: Azure Security Engineer Associate exam requirements, you will learn how to
Configure encryption for data at rest
Configure and manage Azure Key Vault
Configure and manage management and data plane security for your storage account.