
Explore Azure cloud computing, its broad services from computing to AI, and learn to set up a free account for hands-on practice aligned with security-focused exam objectives.
Register an Azure free account using Gmail or GitHub to access $200 free credit for new customers for 30 days, with phone verification and multi-factor authentication.
Explore Microsoft Entra ID as the centralized identity and access management solution, create users and groups, and manage Azure roles with built-in and Entra roles.
Explore the Microsoft Entra ID interface, navigate the Azure portal, and learn about default directory, tenant ID, licenses, and basic management of users, groups, and applications.
Learn how Azure virtual machines deliver on-demand compute to host applications, with configurable Windows or Linux OS, CPU, RAM, storage, region, and networking, billed pay-as-you-go.
Explore Azure RBAC as an authorization system for managing access to Azure resources, using built-in and custom roles and scope-based role assignments.
Learn how to assign Azure RBAC roles at the resource level for labuser01, including reader and virtual machine contributor roles, through a step-by-step role assignment, scope, and least-privilege guidance.
Apply role-based access control at the resource group level by granting lab user 01 the reader role to all resources, illustrating scope inheritance and post-lab cleanup.
A hands-on lab demonstrates using RBAC to assign the virtual machine contributor role alongside reader at the resource group level, enabling management actions like stopping a VM.
Explore how the user access administrator role enables you to manage role assignments at a scope, without granting resource permissions, and delegate Azure RBAC control across resource groups.
Define and assign a custom Azure RBAC role at the resource group level by cloning and editing permissions to allow select VM actions like start and restart.
Create and manage security groups in microsoft entra id to centrally assign azure resource permissions and microsoft entra roles, enabling scalable access control and lifecycle management.
Explore Microsoft Entra ID roles and how RBAC grants permission to create users, groups, and applications at the directory level, alongside managing Azure resources.
Demonstrate how lab user 01 is granted a Microsoft Entra ID user admin role to manage users and groups at the directory level, illustrating Entra ID roles versus resource rbac.
Explore Microsoft Entra authentication methods, including primary authentication with username and password or a temporary access pass, plus multifactor authentication and self-service password reset.
Enable multi-factor authentication with the Microsoft Authenticator app in Microsoft Entra ID. Register the app and use a second factor like a one-time code.
Explore passwordless authentication with Microsoft Entra, using key-based credentials stored on devices or security keys, unlocked by a pin or biometrics, including Windows Hello for Business and passkeys.
Explore passwordless authentication with Microsoft Entra ID, compare it to multifactor authentication, and learn to register a device, set a passcode, and approve sign in requests via the authenticator app.
Understand Microsoft Entra ID licenses, especially P2, including pricing, subscription, and how the Microsoft 365 admin center manages licenses and user access for Entra security features.
Subscribe to Microsoft Entra ID P2 trial licenses via the Microsoft 365 admin center, create a user, set up billing, and assign licenses for conditional access and privileged identity management.
Learn how privileged identity management enables just-in-time, temporary access to Microsoft Entra and Azure resource roles through eligibility, activation, MFA, and approvals, with audit and governance.
Explore privileged identity management in Microsoft Entra by granting and activating Microsoft Entra roles, using eligible vs active assignments, and provisioning a user administrator role with time-bound eligibility.
Demonstrates privileged identity management enabling eligible assignments to Microsoft Entra roles. Shows activation of a user admin role for a limited duration with justification.
Navigate Microsoft Entra Privilege Identity Management to configure role settings for the user administrator role, adjusting activation duration, MFA, justification, approvals, assignments, and notifications for roles, groups, and resources.
Learn how privileged identity management extends to Azure resources, managing RBAC roles, activating roles, and handling eligible and active assignments at the subscription or resource group level.
Create a named ip address location, mark it as trusted, and apply a conditional access policy that grants access from trusted locations while requiring multifactor authentication, then review sign-in logs.
Explore how Microsoft Entra Privileged Identity Management reduces standing privileges by enforcing time-based activation, multifactor authentication, approvals, and conditional access for admin roles.
Explore the Azure Key Vault service, a managed solution for storing secrets, encryption keys, certificates, and other sensitive data; learn how apps securely fetch passwords, API keys, and connection strings.
Deploy an Azure key vault from the marketplace, select standard pricing, enable soft delete and purge protection, store secrets, keys, and certificates, and configure role-based access control with public access.
Explore creating secrets, encryption keys, and certificates in Azure Key Vault, and apply RBAC to separate control plane from data plane access, enabling apps to securely fetch secrets.
Build a simple Python program using Azure Identity and the Azure Key Vault Secrets library to fetch the dbpassword secret from a Key Vault via the Azure CLI as labuser01.
Configure azure key vault firewall to restrict access, enabling public access only from specific virtual networks and IP addresses, add your client IP to authorize secure calls and fetch secrets.
Move the key vault application to an azure virtual machine, configure a virtual network, install python and azure identity and key vault secrets, then log in with a device code.
Enable a virtual network service endpoint for the subnet so the Python program on the virtual machine can securely access the Key Vault's secret.
Register an application in Microsoft Entra ID to give a Python program its own identity, enabling RBAC access to Azure resources like Key Vault and virtual machines.
Register a new application in Microsoft Entra ID, and configure a Python program to authenticate to Azure with a client secret credential, then access a key vault secret.
Learn how Azure managed identities create a resource identity for Azure resources to access Key Vault without az login or client secrets, with Microsoft Entra managing credentials and tokens.
Enable a system assigned managed identity on the virtual machine and grant it role-based access control to access key vault secrets, letting the program use the vm identity.
Explore Microsoft Graph API as a gateway to data across Microsoft cloud services via REST APIs and SDKs. Learn about application and delegated permissions with a Python-based Graph API example.
Explore the key components of a Microsoft Graph request, including the http method, endpoint, api version, resources, access tokens, and delegated and application permissions.
Learn how delegated and application permissions govern access to Microsoft Entra ID via Microsoft Graph, contrasting signed-in-user tokens with app-only tokens for background services.
Learn to call the Microsoft Graph API from Python using GraphServiceClient and application permissions, configure an Entra ID app, grant admin consent for User.Read.All, and read all users.
Learn how to call Microsoft Graph from Python using delegated permissions to sign in a user via device code flow and fetch the signed-in user's profile, contrasting with application permissions.
Explore how Azure Key Vault protects secrets, keys, and certificates; manage access with Microsoft Entra ID and role-based access control; leverage application and managed identities with Graph API permissions.
Assign the built-in not allowed resource types policy to block public IP address creation under microsoft.network, and view compliance in the policy dashboard as you prevent non-compliant deployments.
demonstrates how to create an Azure policy with a remediation task to enforce a default environment tag on resources, using a managed identity, assignment scope, and remediation verification.
Enforce protection with Azure resource locks at subscription, resource group, or resource level, and govern resources using policy, management groups, and policy effects such as audit, deny, modify, and deployIfNotExists.
Explore Azure storage accounts and their blob, file, queue, and table services, learning how general-purpose v2 accounts store unstructured data, host file shares, manage messaging, and enable NoSQL data.
Create an Azure storage account in the portal, selecting a resource group, West US 2 region, and general-purpose v2 with locally redundant storage, then review and create.
Learn to upload and manage binary objects in Azure blob storage by creating containers, uploading documents or code, and using versions, snapshots, access tier, and unique URLs.
Connect to an Azure storage account with Azure Storage Explorer using a storage account access key (key1 or key2) and rotate keys to maintain access to blob containers.
Explore secure, time-bound access to Azure storage using shared access signatures, with granular permissions for blob, container, and object levels and start and expiry times.
Apply role-based access control for Azure blob storage by assigning storage blob data reader and blob data contributor roles at the storage account scope, then verify access in Storage Explorer.
Explore accessing Azure blob storage from an Azure virtual machine using the Azure CLI to list blobs with account key and login authentication, including undelete of deleted blobs.
Learn to use a system-assigned managed identity on an Azure VM to access blob storage, by granting the Storage Blob Data Reader role and authenticating with az login --identity.
Explore how to configure Azure Storage firewalls and networking, including public access controls, private endpoints, virtual network service endpoints, and IP-based restrictions to secure storage accounts.
Learn how stored access policies add a revocable permission layer to shared access signatures at the container level, enabling revocation by editing policy permissions without regenerating account keys.
Explore the Azure SQL Database service as a fully managed relational database in the cloud, covering logical SQL servers, administrators, and firewall rules, with focus on security for the exam.
Create an Azure SQL database by provisioning a logical server and database in a resource group, selecting region and SQL or Entra authentication, and enabling a public firewall endpoint.
Enable Microsoft Entra authentication for an Azure SQL server, create a labuser01 user from external provider, grant data reader role, and verify access.
Learn how Azure SQL Database firewall and public access control connections, including allowing Azure services and adding virtual network service endpoints for secure VM access.
Configure a virtual network service endpoint to access Azure SQL database from a virtual machine, then add the SQL endpoint and a virtual network rule on the server.
Enable Azure SQL Auditing at the server level to record selected database activities and send audit events to a Log Analytics workspace for querying with KQL and auditing insights.
Navigate azure storage accounts and their blob, file, queue, and table services, covering authorization, key management, SAS tokens, RBAC roles, and Azure SQL database authentication and auditing.
Understand how an external identity provider, such as Microsoft ID for Azure, handles authentication and authorization, reduces data store burden, and enables multi-factor authentication, single sign-on, and auditing.
Azure is a cloud platform that eliminates upfront infrastructure costs by hosting apps in global data centers, to deploy a virtual machine using Microsoft ID as the identity provider.
Azure is a popular cloud platform offering services from virtual machines to Azure Kubernetes Service, AI, and app service. Explore the products page and create an Azure account to begin.
Create an azure free account with a Microsoft or GitHub sign-in to access $200 credit for 30 days and 12 months of free services; convert to pay-as-you-go after the period.
Create an Azure free account by setting up a Microsoft account, completing verification, and selecting pay-as-you-go to access $200 free credit for 30 days.
Learn essential Azure basics, including managing identities and permissions, deploying storage accounts and virtual machines, and organizing resources with subscriptions and resource groups, with a focus on securing deployed infrastructure.
This goes through Azure AD
Create and manage a user in Microsoft Entra ID within an Azure account, configuring login details, password constraints, and initial password reset, and assign user to groups.
Understand how to apply role based access control in Azure, assigning permissions at resource, resource group, or subscription levels using built-in roles such as owner, reader, and user access admin.
Assign a role at the resource level using access control, selecting a user or group, applying the reader role, and noting the JSON permissions and assignable scopes.
Assigns the reader role at the resource group level to grant inheritance to all resources, demonstrating access control, role assignments, and eventual visibility of VMs, networks, and IPs.
Assign and switch roles from reader to contributor to explore least-privilege access in an Azure resource group, where permissions are inherited by all resources and VM control is enabled.
Assign two roles to a user and observe how reader and contributor permissions accumulate to determine access on resources, illustrating that permissions sum rather than favor least restrictive permissions.
Learn to create and assign a custom role in Azure RBAC for a resource group, configure virtual machine permissions via JSON, adjust scopes, and clean up.
Discover the built-in roles in Microsoft Entra ID and how they manage features within the identity service, distinct from RBAC, with examples to assign roles to users.
Demonstrate how to assign a user administrator role to user A in the Microsoft Entra admin center in Azure, enabling permissions to manage users and security settings in Entra ID.
Learn how default Microsoft Entra ID user settings enable or restrict actions like registering applications and creating security groups, and how to manage guest access and external collaboration.
Learn to recover deleted users within 30 days and restore user A, and review group management, including Microsoft 365 groups versus security groups, nesting limits, and licensing restrictions.
Subscribe to Microsoft 365 business basic licenses to demonstrate assigning apps to users, using trial licenses, and exploring included services like Exchange, OneDrive, and SharePoint.
Learn how to assign licenses at the group level for security groups in Microsoft Entra Admin Center and Microsoft 365 Admin Center, using group A and its members.
Learn how dynamic user membership rules auto-add users to groups based on department properties, how to create and validate dynamic queries, and the licensing and background processing considerations.
This goes through Applicatin Registration
Register an Entra ID application object to represent the postman tool, then grant Microsoft Graph application permissions to read all users' profiles and grant admin consent for the default directory.
Explore sign-in logs and audit logs in Microsoft Entra ID to monitor user activity, view login details like IP address and location, and learn what's available in the free edition.
Explore enterprise applications with Microsoft Entra ID, register applications, and enable single sign-on to SaaS apps like Dropbox through Android integration.
Learn how to register and manage enterprise applications in Microsoft Entra, assign groups and licenses, and configure single sign-on with SaaS apps like Dropbox Business.
Explore the key properties of an enterprise application, including sign-in enablement, required user assignment, and visibility in the My Apps portal or access URL.
Enable self-service access for an enterprise application by creating a security group for Dropbox users, configuring password-based single sign-on, and implementing an approval workflow to add users automatically.
Learn how users can register and own applications in Entra ID, including default settings, single sign-on, and role-based permissions for registrations, assignments, and proxy settings.
Learn how multi-factor authentication adds a security layer beyond username and password for privileged users in Azure and Microsoft Entra, with examples like the Microsoft Authenticator app.
This goes through a Lab on Multi-Factor Authentication
Enable multi-factor authentication using the microsoft authenticator app to add a secondary verification step during sign-in, including scanning a qr code, approving a push notification, and entering a one-time code.
Enable passwordless authentication with Microsoft Entra using Windows Hello for business, the Microsoft Authenticator app, or security keys, and sign in without a password for server admin access.
Configure a custom banned password list in password protection to enforce strong, non-common passwords. Enable this in the Microsoft admin center under authentication methods.
Explore conditional access policies in Microsoft Entra to enforce multi-factor authentication after initial sign-in, using if-then access rules, while clarifying they are not the first line of defense.
This goes through a Lab on Conditional Access Policies
Define conditional access locations by adding trusted IP addresses and country locations, then enforce access policies that only allow logins from those locations and test with sign-in attempts.
This lab shows how multiple conditional access policies for the same user and resource can block access when one requires MFA, and how to remove policies to restore access.
Learn how Microsoft Entra ID protection detects sign-in risks from signals across platforms using machine learning to flag compromised accounts and categorize risk levels high, medium, and low.
Explore the Microsoft Entra ID protection features in the Entra Admin Center, review the identity protection dashboard, understand risk levels and sign-in risks, and configure user and sign-in policies.
Explore how access reviews revoke outdated permissions when users change roles or leave. Use the access panel for security groups and applications, and privilege identity management for Azure resources.
Set up an access review for a privileged group in Microsoft Entra, scope Group A and all users, and apply results to remove user B while approving user A.
Learn how to create and manage access reviews in privileged identity management, including selecting scopes, roles like application developer, assigning reviewers, and configuring end dates and notifications.
This goes through Azure AD Connect
Set up a custom domain in Microsoft Entra ID, verify ownership with a TXT record, and map users under the domain for identity syncing with Entra Connect.
Learn to simulate an on-premises network in Azure by provisioning a Windows Server VM and installing Active Directory Domain Services as a domain controller for a new forest.
Demonstrates joining a Windows Server to an on-premises domain, installing Microsoft Entra Connect, and configuring password hash synchronization to sync on-premises Active Directory users to Microsoft Entra ID.
Learn how on-premises Active Directory domain services sync users to Microsoft Entra ID and enable password write-back to reflect changes from Entra ID back to on-premises AD.
Explore how the application proxy service enables remote access to an internal on-premises web application not exposed to the internet, using IIS on Windows Server and Microsoft entry ID.
Deploy a Windows Server 2022 VM, install Internet Information Services to host a web server, join the domain, disassociate the public IP, and access it via the Application Proxy service.
Deploy an Ubuntu Server VM in Azure, configure a virtual network with a subnet and public IP, install nginx, and explore network security groups, virtual network peering, and VPN connections.
Log into an Azure Linux VM and install nginx; run a lightweight web server, test connectivity with private and public IPs, and observe network security groups blocking external traffic.
This chapter looks into Network security groups
Explore how network security groups and subnets enable secure VM communication within a single virtual network, including private IP routing between web VM and app VM.
Attach a single network security group to multiple subnets, detaching NSGs from NICs to simplify management; configure inbound http and ssh rules, with Azure Firewall protecting the entire network.
Explore how multiple network security groups work together by applying NSGs at subnet and network interface levels, and ensure rules exist in both to allow traffic to nginx web page.
Set up application security groups to group linux web servers, attach them to ubuntu-based virtual machines, install nginx, and configure network security group rules to permit ssh traffic.
Discover how to use application security groups to group web servers and simplify NSG rules. Attach groups to network interfaces and replace IP-based entries with group-based rules to reduce maintenance.
This chapter looks into Virtual network peering
Discover how user defined routes steer traffic within a virtual network through a firewall or virtual appliance, replacing the default system route to strengthen security and control.
Create a subnet and central VM to host a firewall appliance. Define a user defined route that directs traffic from app subnet to web subnet via the central VM.
Set up a private web server on Windows Server with a point-to-site vpn, deploying a vpn gateway and gateway subnet, using certificate-based client authentication for secure remote access.
Establish a point-to-site vpn to securely access a private virtual network by downloading and installing a vpn client, verifying the certificate, and connecting to the app gateway.
This chapter looks into Site-to-Site VPN connections
Simulate an on-premises network in Azure for site-to-site VPN by deploying a Windows Server 2022 VM, a virtual network, and a software router to route traffic to the gateway.
Create a local network gateway to represent the on-premises network and establish an IPsec site-to-site VPN with a shared key between the Azure gateway and company VM, enabling routing.
Enable energy flow logs to capture IP traffic through network security group. Store logs in an Azure storage account via Network Watcher; migrate to virtual network flow logs after retirement.
Delete unused resources after the network gateway work, keeping only the web vm in the app network and the Azure storage account, while removing the on-prem network and gateway components.
Explore how Azure ExpressRoute establishes a private, non-internet connection from on-premises to an Azure virtual network and to Microsoft 365 via a partner edge and ExpressRoute circuit, with redundancy.
Explore Azure virtual WAN for centralized connectivity across Azure virtual networks and on-premises sites, using virtual hubs to connect site-to-site VPN, point-to-site VPN, and ExpressRoute.
Deploy a virtual hub within the virtual wan to centralize network segments, configure a private ip address space, and set routing for site-to-site and point-to-site vpn connections.
Connect networks to a virtual hub via Azure Virtual WAN using peering to enable access between a Windows web server and a Linux test VM, while monitoring provisioning and routing.
Explore how to securely connect your virtual network to public platform as a service resources such as storage accounts, key vaults, and Cosmos DB, enabling private, secure access.
Secure communication between virtual networks and an Azure storage account, and use blob storage to store unstructured data like images, videos, and audio.
Create a general purpose v2 storage account, enable blob storage, and build containers to host binary objects, then connect via Azure Storage Explorer using account keys for secure access.
Set up service endpoints with a jump server and private IPs, avoiding public IPs on the app vm. Enforce a deny-all rule and permit rdp through the jump server.
Demonstrates implementing Azure service endpoints to securely connect a virtual network subnet to an Azure storage account, after configuring firewall rules and Storage Explorer access.
Explore configuring network security groups to enforce default deny rules and granular outbound access to Azure storage using service tags for North Europe endpoints.
Learn to use service endpoints to securely access Azure Cosmos DB, a managed NoSQL, relational and vector database with APIs like SQL, MongoDB, PostgreSQL, Cassandra, Gremlin, and Table API.
Create and configure an Azure Cosmos DB account, then provision a database and a container to store JSON documents with a partition key, and explore securing access via service endpoints.
Add a Cosmos DB service endpoint from a virtual network, configure firewall rules to allow only selected networks or private endpoints, and verify access through the data explorer.
Discover the Azure Key Vault service, a managed solution for storing secrets, encryption keys, and certificates, and enabling secure communication with virtual networks. It stores database credentials.
Create and configure an Azure key vault in North Europe with standard tier, enable seven-day soft delete, and apply role-based access control for secrets, keys, and certificates.
Explore private endpoints that create a network interface in your subnet to securely connect to Azure services, bringing service into your virtual network and keeping traffic inside, unlike service endpoints.
Discover how the Azure Web App Service provides a managed platform for hosting web applications and integrates with virtual networks, with support for dotnet, Java, Node.js, PHP, and Python runtimes.
Use virtual network integration to let an Azure web app access a database VM inside the virtual network without internet exposure, with a basic or higher app service plan.
Implement virtual network integration for an Azure web app by creating a vnet, deploying an Ubuntu vm with SQL Server, and publishing a .NET app via VS Code.
Deploy Azure Ubuntu Linux VM to host a MySQL database, configure a private IP in a virtual network, create a database, table, and user, and connect a web app securely.
Deploy a dotnet web app to an Azure web app and establish private connectivity to a MySQL database inside an Azure virtual network using VS Code and Azure tools.
Enable Azure web app integration with a virtual network via an empty subnet for private VM access, and verify the app fetches data from the virtual network database.
Add a custom domain to an Azure web app and secure it with SSL. Verify ownership by adding DNS A and TXT records, then bind the certificate and enable HTTPS.
Azure DDoS protection guards your web application against bot-driven traffic with continuous monitoring, real-time attack metrics, and a rapid response team, including IP protection and network protection options.
Discover how the Azure firewall service provides a managed, multi-layer defense for virtual networks with layer 3-7 filtering, threat intelligence, and denial of known malicious IPs or domains.
Deploy an Ubuntu server VM in a production spoke network as the first step toward setting up the Azure firewall, using a hub-spoke model with no public IP or NSG.
Learn how the Azure Bastion service provides secure private connections to virtual machines without public IPs, enabling remote desktop and secure shell within a virtual network.
Connect to remote virtual machines across peered networks using the Azure Bastion service, even without public IPs, then SSH through the portal and install Nginx on Ubuntu.
Deploy the Azure Firewall in the hub network with a dedicated subnet and public IP, enable force tunneling, and manage rules via a firewall policy (standard SKU).
Route internet-bound traffic from the web subnet through the Azure Firewall using a route table and subnet association, then verify outbound requests are blocked.
Configure Azure firewall application rules to allow outbound traffic to a fully qualified domain name like microsoft.com, using rule collections and groups in firewall manager.
Explore how to use denat rules in Azure Firewall for network address translation, mapping a public firewall IP and port to a private VM IP and SSH port.
Implement a hub-spoke architecture with Azure Bastion and Azure Firewall, enabling site-to-site VPN, gateway subnet and network gateway, then configure routes and firewall rules to reach web VM zero one.
Explore how the Azure Application Gateway acts as a layer seven load balancer, inspecting HTTP requests and routing traffic via listeners, rules, and health probes.
Configure two ubuntu web servers with nginx, hosting videos and images, and use the Azure Application Gateway to route /videos to web vm01 and /images to web vm02.
Set up an Azure application gateway with URL routing to direct internet traffic to video and image back-end pools, using path-based rules and a front-end IP.
Enable the Azure Web Application Firewall on the Application Gateway to protect web apps from SQL injection and cross-site scripting, switch between detection and prevention modes, and create custom rules.
Azure Front Door expands the CDN by delivering globally distributed web content with low latency and caching, a global service that speeds and routes content for apps across regions.
Demonstrate Azure Front Door setup alongside an existing Application Gateway, enable WAF detection mode, and deploy a second Web App in UK South to simulate dual web infrastructures.
Deploy and configure Azure Front Door with an endpoint and an origin group containing an Azure Application Gateway and a web app, setting routes and health checks to optimize latency.
Discover Azure SQL managed instance, a managed service with near 100% compatibility to SQL Server, deployed in a virtual network for private, secure access compared to Azure SQL Database.
Deploy an Azure Key Vault in North Europe with standard pricing. Begin with a vault access policy, then switch to RBAC and grant admin permissions for keys, secrets, and certificates.
Learn how to switch an Azure key vault from access policies to role-based access control, assign the key vault secrets user role to the app, and read secrets using RBAC.
Explore encryption at rest for Azure storage and VM disks, where data rests on disks in Azure data centers. Microsoft provides managed keys, with customer keys via Azure Key Vault.
Enable infrastructure level encryption on Azure storage accounts to provide a second layer of at-rest encryption; this setting cannot be changed after creation.
Deploy a Windows VM with 8 GiB data disk, enable Azure Disk Encryption using a Key Vault and customer managed keys, with BitLocker on Windows and DM-Crypt on Linux.
Enable automatic key rotation in Azure Key Vault with rotation policies, rotation time, and notifications to keep customer managed keys fresh for storage and disk encryption.
Explore how management groups organize subscriptions and enforce Azure policies and RBAC across departments, environments, and billing, enabling centralized governance for resources under one root.
Demonstrates applying an Azure policy to require OS and data disks on VMs to be encrypted with customer match keys, and checks compliance at the resource group or subscription level.
Apply an Azure policy with deny effect to enforce OS and data disk encryption with a customer-managed key, affecting new VM deployments while auditing existing resources.
Enforce an Azure blueprint with a do not delete lock in North Europe to protect deployed resources, including a storage account and resource group, by denying deletion until unassignment.
Discover how the Azure Monitor service collects metrics and logs from Azure resources and on-premises systems, using Log Analytics workspaces to analyze data, set alerts, and visualize performance.
Create a Log Analytics workspace in the Azure monitoring service to centralize log and metric data from Azure VMs and web apps, using data collection rules for ingestion and retention.
Microsoft Sentinel, a cloud-native SIEM and SOAR, ingests data via connectors from Azure and SaaS into a log analytics workspace to detect threats with analytics and threat intelligence.
Create a log analytics workspace in a separate resource group in north europe, then add microsoft sentinel to it and start the 31-day free trial.
Learn to connect Azure Activity logs to Microsoft Sentinel by installing the Azure Activity data connector, configuring streaming to a Log Analytics workspace, and using policy-driven remediation.
Collect syslog and common event format logs from Linux-based machines via Microsoft Sentinel, using a Linux VM with the Azure Monitoring Agent as a log forwarder to Log Analytics workspace.
Use KQL to filter data in a log analytics workspace with where clauses and time ranges. Analyze AzureActivity and SecurityEvent data by applying EventID filters and combined criteria.
Learn to project specific columns in log analytics queries and extract values from dynamic data types, using project, square bracket access, and extend to retrieve the client IP address.
Create and manage schedule query rules in Microsoft Sentinel to detect threats in Log Analytics, generate alerts and incidents, map accounts and IP addresses, and apply MITRE techniques.
Learn how Microsoft Sentinel converts alerts into incidents, view incident details, and use playbooks, automation rules, and team assignments to manage threats, tactics, and techniques across data sources.
Create a new hunt in Microsoft Sentinel, run queries from the content hub or Log Analytics, and view results to refine threat hunting rules.
Learn how to automate incident remediation with Microsoft Sentinel playbooks and Azure Logic Apps, creating workflows that trigger on incidents, send emails, and use the automation contributor role.
Protect workloads across Azure resources, on-premises, and other clouds with Microsoft Defender for Cloud, enabling protection for servers, databases, storage, and containers, guided by centralized Azure policy and secure score.
Explore microsoft defender for cloud's basic free features, including recommendations, secure score, and compliance controls, and learn how to enable remediation and encryption with a free trial of enhanced security.
Upgrade to the enhanced Microsoft Defender for Cloud to access a 30-day free trial within your Azure subscription, unlocking more recommendations based on your resources and Log Analytics workspace.
Learn how Microsoft Defender for Cloud evaluates resources against the Microsoft Cloud Security benchmark, and how upgrading to the enhanced plan enables additional standards like PCI DSS version 4.
Explore how just-in-time VM access in Microsoft Defender for Cloud converts a deny network rule into a time-bound allow rule for RDP (3389) access.
Configure Microsoft Defender for Cloud to grant just in time VM access with a custom RBAC role, temporarily opening port 3389 for three hours after a deny rule blocks traffic.
Protect Azure storage data with Microsoft Defender for Storage, which detects threats, malicious uploads, exfiltration, and data corruption. Enable workflow automation to alert security admins when issues arise.
Defender for SQL protects SQL workloads across Azure SQL databases, SQL managed instances, on-premises servers, including AWS EC2. It provides vulnerability assessments, advanced threat protection, and security alerts.
This chapter looks into creating an Azure SQL Database
Enable Microsoft Entra ID authentication for Azure SQL Database by using Entra ID users as dbadmin and dbuser, set Entra admin on the server, and connect with Azure Data Studio.
This chapter looks into Azure SQL Server auditing
This chapter looks into a lab on Azure SQL Database encryption
Enable always encrypted in Azure SQL Database to protect data in transit and at rest with a column encryption key and a column master key. Choose deterministic or randomized encryption.
Install SQL Server Management Studio on Windows and use its always encrypted wizard to encrypt the email column in an Azure SQL Database, storing keys in Azure Key Vault.
Learn how to securely authorize access to data stored in Azure storage accounts, including general purpose v2, blob storage, file shares, queues, and table storage.
This chapter looks into creating an Azure storage account
This chapter looks into working with Azure storage explorer
Generate and apply blob-level shared access signatures to grant read-only access for a defined start-end window, limit permissions, IP restrictions, and share a blob SAS URL.
Generate a container-level shared access signature with read and list permissions and start and expiry times. Connect to the container using the SAS URL in Azure Storage Explorer.
Learn how stored access policies secure blob storage by embedding permissions in shared access signatures (sas) tokens. Discover how to invalidate rogue tokens by rotating keys or updating access policies.
Explore the Azure file share service within an Azure storage account, create a file share, upload files, and connect from Windows, Linux, or macOS using keys.
Generate a shared access signature for the blob service with resource types service and container and permissions read and list, showing that object permissions are needed to access individual blobs.
Create a shared access signature for the file share service with read and list permissions, then verify access in Azure Storage Explorer and confirm downloads are blocked without authorization.
Learn to assign and test Azure storage account access using Microsoft Entra ID identities and role-based access control, applying blob data reader and blob data contributor roles to access data.
Explore the queue service by creating a queue, sending and receiving messages, and granting Microsoft Entra ID access with a storage queue data message sender role for messaging operations.
Create and populate a storage table in Azure using the table service, define partition and row keys, and access it with a shared access signature via Azure Storage Explorer.
Explore authentication methods for Azure Storage across blob, file, queue, and table. Include storage account keys, anonymous access, shared access signatures, and Microsoft Entra ID with Microsoft Entra Domain Services.
Explore blob snapshots as a read-only, point-in-time copy in Azure storage, and learn how to promote a snapshot to restore a blob’s previous version.
Enable blob versioning to preserve every change to a blob, view and revert to a prior version, and understand the cost trade-offs between versions and snapshots.
Explore how soft delete protects Azure blobs and containers by retaining deleted data for seven days, enabling restoration to the prior state after accidental deletion or override.
Explore how to deploy container-based applications on Azure, using Docker concepts and container runtimes to isolate apps and manage dependencies for secure, scalable deployments.
Deploy an Ubuntu Linux Azure VM, install the Docker tool set, and run a simple container, while learning how Azure services secure container based deployments.
Run nginx in a docker container on an Azure Linux VM. Pull the nginx image from Docker Hub, run it, map ports, and verify with the VM's public IP.
Learn how to create and deploy a private Azure Container Registry and publish your custom Docker image to Azure Container Registry, enabling private image hosting within Azure.
Create a Docker base image for a php app with Apache on Linux, copy files to /var/www/html, and upload the image to Azure Container Registry after transferring files with FileZilla.
Publish your docker image to Azure Container Registry by enabling the admin user, logging in, tagging the image, and pushing it to your private registry.
Discover how Microsoft Defender for Cloud protects workloads on Azure Kubernetes and Azure Container Registry, with container image scanning, workload protections, and actionable recommendations.
v5.0 – August 2026 – Major SC-500 Course Update
The course has been significantly expanded to support Microsoft's new SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads exam.
Microsoft is retiring the AZ-500 exam and replacing the Azure Security Engineer certification path with the new Microsoft Certified: Cloud and AI Security Engineer Associate certification.
This course now includes new and updated lessons aligned with the SC-500 exam objectives, including:
Microsoft Entra ID identity, application access, managed identities and Privileged Identity Management
Azure Key Vault, security governance, Azure Policy, RBAC and regulatory compliance
Security for Azure Storage, Azure SQL databases and Azure networking
Security for virtual machines, containers, Azure App Service, Functions, Logic Apps and APIs
Microsoft Defender for Cloud, Defender CSPM and workload protection
Microsoft Sentinel security monitoring and event collection
The course continues to include practical demonstrations and hands-on Azure scenarios so that you can understand not only what the security controls do, but also how to implement them.
Also updated:
New SC-500 exam-focused lessons
Additional hands-on demonstrations
Updated quizzes
New and updated practice test questions
v 4.0 - October 2024
Refreshed course with newer videos to reflect the changes in exam objectives and changes in Azure services
Updated Practice Tests
Updated Quizzes at the end of each section
v 3.0 - February 2022
Refreshed course with newer videos to reflect the changes in exam objectives and changes in Azure services
Added new Practice Test questions
Added Quizzes at the end of each section
v 2.0 - April 2021
Refreshed videos on various chapters which includes the following
Role-based access control
Azure AD Privileged Identity Management
Conditional Access Policies
Azure Firewall
Azure Bastion
Point-to-Site and Site-to-Site VPN connections
Network Security Groups
Update Management
Security for Azure SQL databases - Includes Azure AD Authentication, Data masking , Always Encrypted feature
Added new videos which includes the following
Azure AD Roles - User and Password Administrator role
More chapters regarding aspects for Conditional Access policies
Azure AD Applications - Delegated permissions
Hub and Spoke Architecture using Azure Bastion, Azure Firewall and Azure VPN gateway
Working with various new aspects in Azure Security Center
Working with various new aspects in Azure Sentinel
Azure Key Vault - Using RBAC access policies
v 1.1 - August 2020
Updated contents of course as per changes in objectives - 29th July 2020
This course will make students be prepared to take on the following exam
Exam AZ-500: Microsoft Azure Security Technologies
All concepts covered in this course are aligned to the following Exam Objectives
Manage identity and access
Implement platform protection
Manage security operations
Secure data and applications
There are labs that focus on various security aspects on Azure. This includes working with Azure AD, Protection for workloads on Azure that includes virtual machines, Azure SQL databases and Azure storage accounts.
Security is a very important aspect in today's world. And this course will ensure that students are prepared when it comes to security on the Azure cloud platform.