
Explore azure security capabilities across identity and access, platform protection, security operations, and data and applications, and prepare for the AZ-500 exam with practical tasks and mixed question formats.
Explore managed identities for Azure resources, including system assigned and user assigned options, and how Azure AD authentication secures access to resources without handling credentials.
Discover how to manage app and resource access with Azure Active Directory groups, using group-based permissions, direct vs group assignment, dynamic membership rules, and external authority assignments.
Learn how to manage Azure AD users by creating, configuring, and deleting accounts; assign groups and roles, enable per-user MFA, and handle deleted users with restoration and permanent deletion.
Explore external identities in Azure AD by inviting guest users, managing access via groups and roles, and assigning enterprise applications through the portal, PowerShell, or CLI.
Explore how Azure AD administrative units segment permissions by creating scoped containers, assigning roles, and managing users, groups, and devices via portal, Graph API, or PowerShell with Premium P1 licensing.
Explore Azure AD privileged identity management (PIM) to manage, activate, and monitor just-in-time access to Azure AD, MEM, and other resources with auditing, access reviews, and least privilege.
Learn how to implement conditional access policies in Azure Active Directory by using signals such as device, location, and user risk to grant or deny access under controlled session rules.
Implement Azure AD identity protection to automate detection and remediation of identity risks across users. Configure risk policies, monitor signals, and export risk data to Microsoft Sentinel.
Learn passwordless authentication in Azure AD by comparing authenticator app, Windows Hello for Business, and FIDO2 keys, guided by the Microsoft 365 admin center wizard.
Configure access reviews in Azure AD to verify group and application permissions. Set up reviewers, schedules, multistage reviews, and Azure AD premium P2 licensing under identity governance.
Explore integrating single sign-on with Azure AD across multiple identity providers using federation, OpenID Connect, or SAML. Learn planning, configuration, and options to enable or disable SSO for enterprise applications.
Register an app with Azure Active Directory by creating an application object and its service principal, enabling identity and access management, SSO, and controlled access with permissions and redirect URI.
Configure app registration permission scopes within the Microsoft identity platform by understanding delegated and application permissions, OAuth 2.0 flows, and admin consent in Azure Active Directory.
Manage app registration permission consent in Azure AD by implementing user and admin consent types, configuring app consent policies, and following the admin consent workflow.
Explore managing api permissions in Azure AD by selecting an api, choosing delegated or application permissions, and binding them to an app registration. Learn steps to add and remove permissions.
Explore authentication methods for a service principal in Azure AD, including client secrets and client certificates. Understand how the application object becomes a tenant service principal with three principal types.
Learn to configure azure role permissions across subscription, resource group, and resources using Azure rbac. Distinguish Azure rbac from Azure ad rbac and review roles like owner, contributor, and reader.
Explore how to interpret Azure roles, resources, and permissions in RBAC, distinguish resource and AD roles, review built-in and custom roles, and audit or export role assignments.
Learn how built-in Azure AD roles combine permissions for Azure Active Directory and how to assign them to users or groups using the portal, PowerShell, or Graph API.
Create and assign custom roles in Azure AD RBAC by combining permissions from existing roles or starting from scratch, using the portal, PowerShell, or Azure CLI.
Secure the connectivity of hybrid networks by integrating on-premises and cloud resources with encrypted site-to-site VPNs, Azure Firewall, bastion hosts, and RBAC-controlled access.
Explore securing connectivity between Azure virtual networks by implementing defense-in-depth. Use network security groups, Azure firewall, route controls, VPNs, and Bastion access.
Learn to create and configure Azure firewall, compare standard and premium skews, and apply policy-based management with firewall manager to enforce traffic filtering and ids.
Configure and manage Azure firewall deployments with the firewall manager, a centralized policy and route management tool for hub virtual networks and secured virtual hubs, including standard or premium policies.
Explore how the Azure application gateway delivers layer seven web traffic load balancing with optional web application firewall, and how to create and configure it using quick start templates.
Learn to create and configure Azure Front Door, a content delivery network using edge locations and a web application firewall to route traffic to origins.
Create and configure an Azure web application firewall (WAF) using the Application Gateway, apply a WAF policy with OWASP rules, and customize rules to block or allow traffic.
Configure resource firewalls in azure for storage accounts, key vault, sql server/database, and web apps using portal, PowerShell, and Azure CLI to manage IP rules, virtual networks, and trusted services.
Master network isolation for web apps and Azure functions using firewalls, private endpoints, and service endpoints within an Azure defense-in-depth architecture. Explore hybrid connectivity, site-to-site VPN, and express route.
Explore Azure service endpoints, enabling secure connectivity from a virtual network to Azure resources over the Azure backbone, with on-premises considerations for ExpressRoute and peering.
Explore how Azure private endpoints extend service endpoints by providing private IP connectivity from your VNet, peered networks, and on-premises via private link and DNS.
Discover azure private links, including private endpoints and private link services, and learn to publish services over the azure backbone using a load balancer and private endpoints.
Learn to implement Azure DDoS protection standard plan, bind it to a virtual network, and protect up to 100 public IPs with 24/7 monitoring and adaptive, multilayer defense.
Configure endpoint protection for virtual machines in Azure using Microsoft Defender for Cloud, install Defender for Endpoint, and leverage Log Analytics and EDR to harden VMs.
Enable and manage security updates for Azure VMs using update management in the portal, deploying patches across Windows and Linux with an agent and automated schedules.
Explore how to secure Azure container instances by protecting images in private registries with access control and credentials, scanning for vulnerabilities, and using Defender for Containers and the security baseline.
Explore how to manage access to the Azure container registry (ACR) using Azure RBAC, AD service principals, private links, and keys, while leveraging docker commands, TLS, and Defender for Cloud.
Configure security for Azure functions and other serverless compute using defense-in-depth, RBAC and managed identities, key vault access, SAS tokens, secure networking, secrets, and monitoring.
Explore how to secure an Azure app service by applying the cloud shared responsibility model, configuring authentication, TLS, IP restrictions, private networking, and Defender for Cloud protections to guard workloads.
Explore how Azure encrypts data at rest with AES-256 storage encryption, key vaults, and Azure AD, covering platform-managed vs customer-managed keys and disk encryption with BitLocker or bcrypt.
Learn how to secure data in transit in Azure with TLS/SSL, VPN connections, ExpressRoute, and Private Link, protecting data as it moves across networks.
Explore configuring custom security policies in Azure: create policy definitions, bundle into initiatives, assign for compliance, and use remediation and noncompliance messages with Defender for Cloud.
Create policy initiatives by bundling policy definitions to manage them at scale, define metadata, and assign grouped policies for scalable compliance.
Learn to use the Azure policy tool to create definitions and initiatives, monitor compliance, and apply remediation across subscriptions, with policy events and Microsoft Defender for Cloud integration.
Configure Microsoft Defender for Servers to extend Defender for Cloud across Windows and Linux workloads. Enable enhanced security features, onboard subscriptions, and install agents for threat detection and vulnerability management.
Learn how to run and evaluate vulnerability scans in Azure Defender for Cloud, comparing built-in vulnerability assessment with Qualys integration, and remediate findings for secure workloads.
Enable Microsoft Defender for SQL across Azure SQL databases, managed instances, and Azure Synapse by three methods: Defender for Cloud subscription level, resource level, or at creation time.
Explore Microsoft threat modeling tool to visualize data flows, identify threats, and determine mitigations using ready-made templates for Azure threat modeling, medical devices, and software development life cycle.
Azure Monitor alerts empower proactive visibility by defining alert rules, signals, thresholds, and action groups to monitor metrics, logs, and health across resources.
Configure logging for Azure Monitor to collect and analyze telemetry from cloud resources. Route logs to storage, Event Hubs, or Log Analytics for insights, alerts, and visualization.
Learn to monitor security logs with Azure Monitor by configuring diagnostic settings, using log analytics queries, and integrating with Microsoft Sentinel for centralized security log management.
Learn how analytics rules drive alerts in Microsoft Sentinel, including scheduled and near real-time queries, KQL testing, entity mapping, and automated incident workflows via a playbook.
Learn how data connectors enable Microsoft Sentinel to ingest logs from sources like Azure Active Directory and Microsoft 365, and how to configure connectors, workbooks, and analytics rules for insights.
Explore how alerts become incidents in Microsoft Sentinel, using analytics rules and data connectors to automate incident generation and enable efficient incident response.
Learn to control storage account access in Azure using Azure Active Directory authentication or storage keys, with role based access control and portal, PowerShell, and Azure CLI demonstrations.
Learn to manage storage account access keys, rotate them one at a time, and use Azure Key Vault with Azure Active Directory for secure key management.
Enable delegated, time-bounded access to specific Azure storage resources (blob, queue, file, table) using SAS tokens, across account, service, and user delegation SAS, with least privilege.
Configure Azure AD authentication for Azure Storage and Azure Files using SMB and Azure AD DS.
The Microsoft Azure Security Technologies (AZ-500) course is designed to equip learners with the knowledge and skills required to implement security controls, maintain the security posture, and identify and remediate vulnerabilities in Microsoft Azure. The course covers the following topics:
1. Identity and Access Management: Learners will learn how to manage access to Azure resources by implementing Azure AD identities, role-based access control (RBAC), and Azure AD Privileged Identity Management.
2. Platform Protection: Learners will learn how to protect Azure resources by implementing various security controls, including network security, Azure Security Center, and Azure DDoS Protection.
3. Data and Application Protection: Learners will learn how to protect data and applications in Azure by implementing Azure Backup and Azure Site Recovery, and by configuring security settings for Azure Storage and Azure SQL Database.
4. Security Operations: Learners will learn how to monitor and respond to security events in Azure by implementing Azure Monitor and Azure Log Analytics, and by creating custom alerts and queries.
5. Governance and Compliance: Learners will learn how to maintain compliance with industry regulations and internal policies by implementing Azure Policy and Azure Blueprints, and by configuring auditing and logging.
The prerequisites are not mandatory, but they are recommended to ensure that learners can keep up with the course content and have the necessary skills and knowledge to succeed in securing and administering Microsoft 365 effectively. Learners who do not meet these prerequisites can still benefit from the course but may need to invest additional time and effort to understand some of the more advanced concepts covered in the course.