Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
AZ-500 Microsoft Azure Security Exam Certification
Rating: 4.5 out of 5(10,028 ratings)
66,041 students

AZ-500 Microsoft Azure Security Exam Certification

Passing this exam earns you : Microsoft Certified: Azure Security Engineer Associate certification.
Created byAlan Rodrigues
Last updated 7/2026
English
Arabic [Auto],German [Auto],

What you'll learn

  • This course is designed to provide you with a comprehensive understanding of securing Microsoft Azure environments.
  • Utilizing Security services can enhance organizations' security posture and reduce the risk of security breaches in the digital age.
  • Azure security core services and implement security controls and threat protection.
  • To protect data, applications, and networks in a cloud technology environment
  • This course is designed for professionals who want to demonstrate their skills in securing Microsoft Azure environments.
  • Upon completion of this course, you'll not only be well-prepared for the AZ-500 exam, but you’ll also have the expertise to manage security in Azure environment

Course content

8 sections339 lectures26h 36m total length
  • PowerPoint Slides download0:13
  • Azure Foundations for Cloud Security3:55

    Explore Azure cloud computing, its broad services from computing to AI, and learn to set up a free account for hands-on practice aligned with security-focused exam objectives.

  • Creating the Azure Free Account4:48

    Register an Azure free account using Gmail or GitHub to access $200 free credit for new customers for 30 days, with phone verification and multi-factor authentication.

  • About Microsoft Entra ID2:59

    Explore Microsoft Entra ID as the centralized identity and access management solution, create users and groups, and manage Azure roles with built-in and Entra roles.

  • Quick tour of Microsoft Entra ID4:03

    Explore the Microsoft Entra ID interface, navigate the Azure portal, and learn about default directory, tenant ID, licenses, and basic management of users, groups, and applications.

  • Creating a User in Microsoft Entra ID4:04
  • Introduction to Azure Virtual Machines4:59

    Learn how Azure virtual machines deliver on-demand compute to host applications, with configurable Windows or Linux OS, CPU, RAM, storage, region, and networking, billed pay-as-you-go.

  • Lab - Deploying an Azure Virtual machine12:38
  • What is Azure Role-Based Access Control3:21

    Explore Azure RBAC as an authorization system for managing access to Azure resources, using built-in and custom roles and scope-based role assignments.

  • Lab - RBAC - Resource level assignment7:14

    Learn how to assign Azure RBAC roles at the resource level for labuser01, including reader and virtual machine contributor roles, through a step-by-step role assignment, scope, and least-privilege guidance.

  • Lab - RBAC - Resource-Group-Level Assignment7:00

    Apply role-based access control at the resource group level by granting lab user 01 the reader role to all resources, illustrating scope inheritance and post-lab cleanup.

  • Lab - RBAC - Assigning the Contributor Role3:40

    A hands-on lab demonstrates using RBAC to assign the virtual machine contributor role alongside reader at the resource group level, enabling management actions like stopping a VM.

  • Lab - RBAC - User Access Administrator Role5:21

    Explore how the user access administrator role enables you to manage role assignments at a scope, without granting resource permissions, and delegate Azure RBAC control across resource groups.

  • Creating a Custom Azure RBAC Role5:21

    Define and assign a custom Azure RBAC role at the resource group level by cloning and editing permissions to allow select VM actions like start and restart.

  • Creating a Security Group in Microsoft Entra ID6:23

    Create and manage security groups in microsoft entra id to centrally assign azure resource permissions and microsoft entra roles, enabling scalable access control and lifecycle management.

  • About renewing the temporary access pass0:44
  • Introduction to Microsoft Entra ID Roles2:31

    Explore Microsoft Entra ID roles and how RBAC grants permission to create users, groups, and applications at the directory level, alongside managing Azure resources.

  • Assigning a Microsoft Entra Role to a User6:02

    Demonstrate how lab user 01 is granted a Microsoft Entra ID user admin role to manage users and groups at the directory level, illustrating Entra ID roles versus resource rbac.

  • Deleting resources3:19
  • Introduction to Microsoft Entra Authentication Methods4:41

    Explore Microsoft Entra authentication methods, including primary authentication with username and password or a temporary access pass, plus multifactor authentication and self-service password reset.

  • Using the Microsoft Authenticator App9:32

    Enable multi-factor authentication with the Microsoft Authenticator app in Microsoft Entra ID. Register the app and use a second factor like a one-time code.

  • Moving Beyond Passwords with Microsoft Entra Passwordless Authentication2:27

    Explore passwordless authentication with Microsoft Entra, using key-based credentials stored on devices or security keys, unlocked by a pin or biometrics, including Windows Hello for Business and passkeys.

  • A look at Microsoft Entra Passwordless Authentication5:10

    Explore passwordless authentication with Microsoft Entra ID, compare it to multifactor authentication, and learn to register a device, set a passcode, and approve sign in requests via the authenticator app.

  • Understanding Microsoft Cloud Licences5:29

    Understand Microsoft Entra ID licenses, especially P2, including pricing, subscription, and how the Microsoft 365 admin center manages licenses and user access for Entra security features.

  • Accessing Microsoft 365 Admin Center11:21

    Subscribe to Microsoft Entra ID P2 trial licenses via the Microsoft 365 admin center, create a user, set up billing, and assign licenses for conditional access and privileged identity management.

  • Summary - Microsoft Entra ID14:34
  • Privileged Identity Management6:36

    Learn how privileged identity management enables just-in-time, temporary access to Microsoft Entra and Azure resource roles through eligibility, activation, MFA, and approvals, with audit and governance.

  • Lab - Privileged Identity Management - Microsoft Entra roles - Assignment7:32

    Explore privileged identity management in Microsoft Entra by granting and activating Microsoft Entra roles, using eligible vs active assignments, and provisioning a user administrator role with time-bound eligibility.

  • Lab - Privileged Identity Management - Microsoft Entra roles - Activation3:53

    Demonstrates privileged identity management enabling eligible assignments to Microsoft Entra roles. Shows activation of a user admin role for a limited duration with justification.

  • Lab - Privileged Identity Management - Role settings2:40

    Navigate Microsoft Entra Privilege Identity Management to configure role settings for the user administrator role, adjusting activation duration, MFA, justification, approvals, assignments, and notifications for roles, groups, and resources.

  • Lab - Privileged Identity Management - RBAC4:24

    Learn how privileged identity management extends to Azure resources, managing RBAC roles, activating roles, and handling eligible and active assignments at the subscription or resource group level.

  • Microsoft Entra Conditional Access4:09
  • Lab - Microsoft Entra Conditional Access9:29
  • Lab - Conditional Access Policy - Locations5:19

    Create a named ip address location, mark it as trusted, and apply a conditional access policy that grants access from trusted locations while requiring multifactor authentication, then review sign-in logs.

  • Summary - PIM and Conditional Access6:49

    Explore how Microsoft Entra Privileged Identity Management reduces standing privileges by enforcing time-based activation, multifactor authentication, approvals, and conditional access for admin roles.

  • Introduction to Azure Key Vault2:42

    Explore the Azure Key Vault service, a managed solution for storing secrets, encryption keys, certificates, and other sensitive data; learn how apps securely fetch passwords, API keys, and connection strings.

  • Lab - Deploy an Azure Key Vault3:30

    Deploy an Azure key vault from the marketplace, select standard pricing, enable soft delete and purge protection, store secrets, keys, and certificates, and configure role-based access control with public access.

  • Lab - Creating a secret in the key vault5:32

    Explore creating secrets, encryption keys, and certificates in Azure Key Vault, and apply RBAC to separate control plane from data plane access, enabling apps to securely fetch secrets.

  • Retrieve a Secret from Azure Key Vault with Python2:04
  • Lab – Retrieve a Secret from Azure Key Vault with Python10:26

    Build a simple Python program using Azure Identity and the Azure Key Vault Secrets library to fetch the dbpassword secret from a Key Vault via the Azure CLI as labuser01.

  • Quick look at creating encryption keys2:59
  • Configure Azure Key Vault Firewall and Network Access1:24
  • Lab - Configure Azure Key Vault Firewall - IP address3:32

    Configure azure key vault firewall to restrict access, enabling public access only from specific virtual networks and IP addresses, add your client IP to authorize secure calls and fetch secrets.

  • Move the Key Vault Application to an Azure Virtual Machine7:41

    Move the key vault application to an azure virtual machine, configure a virtual network, install python and azure identity and key vault secrets, then log in with a device code.

  • Understanding Virtual Network Service Endpoints4:14

    Enable a virtual network service endpoint for the subnet so the Python program on the virtual machine can securely access the Key Vault's secret.

  • Why Applications Need an Identity in Microsoft Entra ID3:17

    Register an application in Microsoft Entra ID to give a Python program its own identity, enabling RBAC access to Azure resources like Key Vault and virtual machines.

  • Lab - Authenticate an Application to Key Vault7:14

    Register a new application in Microsoft Entra ID, and configure a Python program to authenticate to Azure with a client secret credential, then access a key vault secret.

  • Managed Identities for Azure Resources2:23

    Learn how Azure managed identities create a resource identity for Azure resources to access Key Vault without az login or client secrets, with Microsoft Entra managing credentials and tokens.

  • Lab - Managed Identities for Azure Resources3:41

    Enable a system assigned managed identity on the virtual machine and grant it role-based access control to access key vault secrets, letting the program use the vm identity.

  • Introduction to Microsoft Graph API1:50

    Explore Microsoft Graph API as a gateway to data across Microsoft cloud services via REST APIs and SDKs. Learn about application and delegated permissions with a Python-based Graph API example.

  • How a Microsoft Graph request works2:09

    Explore the key components of a Microsoft Graph request, including the http method, endpoint, api version, resources, access tokens, and delegated and application permissions.

  • Delegated and application permissions4:33

    Learn how delegated and application permissions govern access to Microsoft Entra ID via Microsoft Graph, contrasting signed-in-user tokens with app-only tokens for background services.

  • Lab - Call Microsoft Graph from Python - Application permissions10:16

    Learn to call the Microsoft Graph API from Python using GraphServiceClient and application permissions, configure an Entra ID app, grant admin consent for User.Read.All, and read all users.

  • Lab - Call Microsoft Graph from Python - Delegated permissions7:38

    Learn how to call Microsoft Graph from Python using delegated permissions to sign in a user via device code flow and fetch the signed-in user's profile, contrasting with application permissions.

  • Summary - Key vault and identities9:57

    Explore how Azure Key Vault protects secrets, keys, and certificates; manage access with Microsoft Entra ID and role-based access control; leverage application and managed identities with Graph API permissions.

  • Protecting Azure Resources with Resource Locks3:58
  • Enforcing Security Standards with Azure Policy3:10
  • Understanding Azure Management Groups2:42
  • Lab - Block public IP address creation with Azure Policy7:52

    Assign the built-in not allowed resource types policy to block public IP address creation under microsoft.network, and view compliance in the policy dashboard as you prevent non-compliant deployments.

  • Remediate Existing Azure Resources with Azure Policy4:54

    demonstrates how to create an Azure policy with a remediation task to enforce a default environment tag on resources, using a managed identity, assignment scope, and remediation verification.

  • Summary - Locks, policy, management groups7:02

    Enforce protection with Azure resource locks at subscription, resource group, or resource level, and govern resources using policy, management groups, and policy effects such as audit, deny, modify, and deployIfNotExists.

Requirements

  • Learners are required to have a basic understanding of managing several security aspects such as managing identities and securing data and infrastructure.
  • Learners need to have a basic understanding on base-level services provided on the Azure platform like AZ 900

Description

v 4.0 - October 2024

  • Refreshed course with newer videos to reflect the changes in exam objectives and changes in Azure services

  • Updated Practice Tests

  • Updated Quizzes at the end of each section

v 3.0 - February 2022

  • Refreshed course with newer videos to reflect the changes in exam objectives and changes in Azure services

  • Added new Practice Test questions

  • Added Quizzes at the end of each section

v 2.0 - April 2021

  • Refreshed videos on various chapters which includes the following

    • Role-based access control

    • Azure AD Privileged Identity Management

    • Conditional Access Policies

    • Azure Firewall

    • Azure Bastion

    • Point-to-Site and Site-to-Site VPN connections

    • Network Security Groups

    • Update Management

    • Security for Azure SQL databases - Includes Azure AD Authentication, Data masking , Always Encrypted feature


  • Added new videos which includes the following

    • Azure AD Roles - User and Password Administrator role

    • More chapters regarding aspects for Conditional Access policies

    • Azure AD Applications - Delegated permissions

    • Hub and Spoke Architecture using Azure Bastion, Azure Firewall and Azure VPN gateway

    • Working with various new aspects in Azure Security Center

    • Working with various new aspects in Azure Sentinel

    • Azure Key Vault - Using RBAC access policies

v 1.1 - August 2020

  • Updated contents of course as per changes in objectives - 29th July 2020


This course will make students be prepared to take on the following exam

Exam AZ-500: Microsoft Azure Security Technologies

All concepts covered in this course are aligned to the following Exam Objectives

  • Manage identity and access

  • Implement platform protection

  • Manage security operations

  • Secure data and applications

There are labs that focus on various security aspects on Azure. This includes working with Azure AD, Protection for workloads on Azure that includes virtual machines, Azure SQL databases and Azure storage accounts.

Security is a very important aspect in today's world. And this course will ensure that students are prepared when it comes to security on the Azure cloud platform.

Who this course is for:

  • Learners who wants to ace Azure security core services and implement security controls and threat protection.
  • Students who wants to be a valuable asset to any organization looking to secure its cloud infrastructure.