
Explore deploying and securing Microsoft 365 and Azure in the MS-500 course, with hands-on demonstrations, episode notes, and a certification-aligned exam overview.
Explore hybrid Azure AD authentication options and how Azure AD Connect links on-premises directories to the cloud, covering password hash sync, pass-through authentication, federation, and seamless SSO.
Plan Azure AD synchronization options by using AD Connect to link on-premises Active Directory to Azure AD, covering hybrid, cloud, and single forest to multi-forest architectures.
Monitor and troubleshoot Azure AD Connect events by examining sync status in the Azure portal, using the built-in troubleshoot tool and PowerShell driven diagnostics on the bridgehead server.
Learn how to upgrade Azure AD Connect, including automatic upgrades, in-place upgrades, and swing migrations, and understand prerequisites like TLS 1.2 and the new sync client v2.
Implement password management using Azure Active Directory password protection, policy settings, and band password lists. Extend protection to on-premises with password protection proxy service, AD Connect, and password reset.
Explore how to manage external identities in Azure Active Directory, including B2B guest access and B2C, by configuring identity providers, conditional access, and external collaboration settings for workloads.
Plan sign-on security with Azure Active Directory by evaluating signals, decisions, and enforcement, using conditional access, MFA, and device state to secure cloud apps and identities.
Explore multi-factor authentication in Azure AD, covering per-user MFA, security defaults, and conditional access policies to enforce MFA and protect resources.
Learn to manage and monitor MFA in the Azure portal, configure settings like account lockout and fraud alerts, and review authentication methods and sign-in logs.
Plan and implement device authentication methods by comparing Azure AD register, join, and hybrid join, and learn how Windows Hello for Business enables passwordless, secure access.
Plan conditional access policies to control access to apps and data by evaluating signals, assignments, conditions, and enforcement, using tokens and MFA, with prerequisites such as Azure AD Premium P1.
Learn to configure and manage endpoint security with Microsoft Endpoint Manager, create and assign Windows and macOS compliance policies, and prepare Defender for Endpoint integration.
Learn to implement and manage conditional access by building policies in the Azure portal or Endpoint Manager, assign users and apps, configure conditions and controls, and test with what-if simulations.
Learn to test and troubleshoot conditional access policies with the what-if tool in Azure AD. Assess policy outcomes for users and cloud apps and interpret sign-in results to prevent misconfigurations.
Plan for roles in Microsoft 365 security administration by applying role based access control and built in admin roles, using Azure AD, delegated administration, and least privileged access.
Configure admin roles in the Microsoft 365 admin center and with PowerShell, assigning roles, viewing permissions, exporting lists, and comparing roles while understanding licensing requirements and run as.
Learn how to audit roles in Microsoft 365 by using the compliance center to search audit logs, enable mailbox auditing, and track role-based access across cloud services.
Plan for Azure PIM explains privileged identity management within Azure Active Directory, including just in time access, time bound roles, MFA, approvals, and audit trails.
Learn how to assign and activate privileged identity management roles in Azure AD, manage eligible and active assignments, and handle justification and notifications.
Approve or deny azure ad role requests in privileged identity management (pim) and manage azure resource roles, including onboarding resources, role settings, activations, approvals, and notifications.
Explore monitoring privileged identity management in Microsoft 365 security, track PIM alerts and audit history, manage alert settings, and apply proactive recommendations and access reviews to minimize risk.
Explore entitlement management within Azure Active Directory to govern access at scale through access packages, request and approval workflows, and automated lifecycle under identity governance.
Learn to implement and manage access reviews in Azure AD premium P2. Use reviewers and group owners to verify appropriate access and enforce identity governance.
Implement a user risk policy in Azure Active Directory to detect risky sign-ins. Block access or force password resets via conditional access and monitor risk with reporting.
Explore how sign-in risk policy uses Azure information protection signals to evaluate sign-ins, enforce conditional access with MFA, and monitor risk with identity protection and secure score.
Configure Azure Active Directory Identity Protection notifications to receive user risk alerts and weekly digests by email, with customizable recipients and links to detailed reports.
Review and respond to risk events in Azure AD identity protection using reports on risky users, risky sign-ins, and risk detections; download data and apply remediation.
Plan threat protection with Microsoft Defender for Identity to monitor domain controllers and AD FS, detect advanced threats, and integrate with MCAS for proactive defense.
Install and configure Microsoft Defender for Identity by ensuring licensing and permissions, onboarding the instance, linking to on-premises Active Directory, and deploying the identity sensor via the new portal.
Monitor and manage Microsoft Defender for Identity using the Microsoft 365 defender center; filter alerts, review health, and use entity tags to detect lateral movement and protect sensitive identities.
Plan a Microsoft Defender for Endpoint deployment by evaluating architectures, onboarding options, licensing, and data storage, then configure endpoint sensors and cloud analytics for prevention, detection, and response.
Implement Microsoft Defender for Endpoint by configuring deployment, onboarding devices via a script, and managing endpoints across two security portals, with data retention, alerts, and real-time monitoring.
Explore managing and monitoring Microsoft Defender for Endpoint across the old and new portals, with device inventory, alerts, timelines, vulnerability management, and hands-on lab simulations.
Explore how Microsoft Intune enables cross-platform device and app management via cloud-based policies, enrollment, and app protection policies to secure data across endpoints.
Configure and manage Microsoft Defender Application Guard to isolate Edge and Office executions in sandboxed containers, blocking untrusted sites and files with Intune templates and settings on Windows 10/11 devices.
Understand the differences between Microsoft Defender Application Guard and Microsoft Defender Application Control, and how Microsoft Defender Application Control extends protection to Windows 10/11 with code signing and path rules.
Enable exploit protection to automatically mitigate exploits on Windows 10/11 and Windows Server using Windows Defender, deployable via Intune, Endpoint Manager, group policy, or PowerShell with an XML config.
Configure and manage whole-disk encryption with BitLocker on Windows and FileVault on macOS using Intune and endpoint security policies, TPM settings, and deployment through configuration profiles.
Learn to configure and manage encryption on non-Windows devices—macOS, iOS, and Android—through Intune enrollment, configuration profiles, and platform-specific options like FileVault.
Explore how to implement application protection policies within Microsoft Intune, balancing MAM and MDM for BYOD and corporate data protection across iOS, Android, and Windows, with policy creation and monitoring.
Learn to configure and manage device compliance for endpoint security in Microsoft Intune, create platform-specific policies, enforce security baselines, and handle noncompliant devices with notifications.
The Microsoft 365 Security Administration (MS-500) course is designed to provide learners with a comprehensive understanding of how to secure Microsoft 365 services and data, including Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams.
The Microsoft 365 Security Administration (MS-500) course is designed to provide learners with a comprehensive understanding of how to secure Microsoft 365 services and data, including Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams.
The course covers a range of topics, including implementing and managing identity and access, implementing and managing threat protection, implementing and managing information protection, and managing governance and compliance features in Microsoft 365.
The course is aimed at IT professionals, including administrators and consultants, who are responsible for securing Microsoft 365 environments. It is also suitable for business users who want to understand how to protect their organization's data and assets in Microsoft 365.
The course is suitable for individuals with a basic understanding of Microsoft 365 services, as well as those who have experience in securing enterprise-level IT solutions. It is also suitable for those who are preparing for the Microsoft 365 Certified: Security Administrator Associate certification.
By the end of the course, learners should have a good understanding of how to secure Microsoft 365 services and data and be able to apply their knowledge in a real-world context.