
Learn practical cloud, cybersecurity, and AI architectures from a Microsoft expert with over a decade of Azure experience, blending real-world hands-on insights with clear teaching.
Explore the five cloud computing properties—on-demand self service, network access, resource pooling, rapid elasticity, and measured service—and how they enable fast provisioning, scalable resources, and usage-based billing.
Define public, private, hybrid, and multi-cloud models with examples from Azure, AWS, and GCP, and explain how enterprises combine these offerings.
Describe the Azure global backbone, its data centers and global connectivity. Highlight regions, fiber and subsea cables, edge sites, and peering connections that boost performance and resilience.
Explain the shared responsibility model across on premises, IaaS, PaaS, and SaaS in Azure. Identify which tasks are customer versus Microsoft responsibility, including OS, network, identities, and data.
Explore the Azure resource hierarchy from management groups to subscriptions, resource groups, and resources, and learn how lifecycle-based grouping supports security and governance.
Explore Azure subscription types such as free, student, pay-as-you-go, and enterprise agreement, highlighting free credits, 12-month offers, demo setup steps, and typical enterprise discounts.
Clarify how Entra ID tenants relate to Azure subscriptions, showing that identities in the Entra ID tenant access resources in subscriptions and resource groups, not the tenants themselves.
Create your free Azure subscription by choosing between free and pay-as-you-go, enter personal details, then log in at portal.azure.com to start building in Azure.
Activate and assign a Microsoft 365 E5 license via a free trial to enable Defender XDR features.
Explore Defender XDR, a unified Microsoft security operations platform uniting endpoint, office, identity, cloud apps, and cloud protection with DevOps security, posture management, and cloud workload protection.
Create an all access Defender XDR role by adding a new custom role and granting security operations, posture, authorizations, and settings read and manage permissions, then assign to a user.
Download and install VirtualBox to host Kali Linux, using default settings, then review the installation overview and proceed to the next section.
Download and extract Kali Linux, set up a VirtualBox VM with increased RAM and cores, log in as Kali, and begin attacking our infrastructure.
Configure the keyboard layout in Kali Linux by opening the settings manager from the Kali icon, adding German and US keyboards, adjusting priority, and removing unused layouts.
Install the Tor browser in Kali using apt update and apt install tor with the Tor browser launcher, verify the signature, and prepare to connect to Tor for defender testing.
Frame zero trust as a security mindset, not a tool, and follow its five principles—no implicit trust, verify every access request, least privilege, micro-segmentation, and continuous monitoring.
Explain the NIST 800-207 zero trust architecture, where a policy enforcement point with a policy engine and administrator evaluates signals from identity, threat intelligence, and logs before granting access.
Learn the zero trust architecture per NIST, including the control plane, data plane, policy engine, policy enforcement point, and policy decision point, with session-specific credentials for dynamic access.
Apply Microsoft’s zero trust principles by assuming breach, verifying explicitly, and using least privilege access to continuously authenticate and authorize every resource request with telemetry and risk-based controls.
Map and implement the Microsoft zero trust architecture by aligning endpoint security, identity management, policy enforcement, and Defender XDR across on-premises and cloud workloads using Entra, Intune, and conditional access.
Explore the Microsoft security cosmos, focusing on cloud security, SOC, and CTI, and see how Defender XDR, Sentinel, and Copilot enhances multi-cloud protection.
Explore a classic cyber kill chain and how Defender for Office, Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps stop phishing, exploits, and data exfiltration with XDR.
Explore exposure management in Defender XDR, a unified portal for proactive security. Review attack surface exposure insights, secure score, data connectors, and connected assets across Azure, endpoints, and on-premises resources.
Explore the attack surface map in exposure management with defender XDR, revealing attack paths and cross-environment vulnerabilities across Azure resources, endpoints, and cloud services.
Explore exposure insights in Defender XDR, including initiatives, metrics, recommendations, and events; learn to improve ransomware protection and cloud security through actionable security recommendations and threat actor alignment.
Explore how secure score integrates with exposure management in defender XDR, showing how addressing exposure insights recommendations improves your organization's security posture across identity, data, device, and apps.
Explore how a security operations center uses threat intelligence and iocs, threat hunting, log management, and incident response to detect, investigate, and curb attackers.
Most SoCs use a three-tier model: automation handles commodity malware; tier one handles easy tasks; tier two tackles advanced threats, while tier three conducts proactive threat hunting and forensics.
Learn the NIST-based cyber security incident response process, from preparation and detection and analysis to containment, eradication, recovery, and post-incident activities that drive lessons learned and adaptation for various enterprises.
Explore EDR, XDR, SIEM, and SOAR in the Microsoft ecosystem, including Defender for Endpoint and Defender for Cloud, Sentinel, and Logic Apps, to streamline detection and automated incident response.
Learn blue, red, and purple teaming in enterprise security: blue team defenses and incident response, red team testing and social engineering, and purple collaboration to boost defense and skills.
Define cyber threat per NIST standard: any circumstance or event that threatens operations, assets, or individuals through an information system, including unauthorized access, destruction, disclosure, modification, or denial of service.
Understand the distinctions between intelligence, threat intelligence, and cyber threat intelligence (CTI), and identify how adversaries use tactics, techniques, and procedures in cybersecurity.
Define cyber threat intelligence as knowledge about adversaries' motivations, intentions, and methods gathered to protect critical assets and inform TTPS-based defense.
Threat actors carry out threats by exploiting vulnerabilities, such as Log4j2, causing downtime, confidentiality breaches, or integrity violations, and cyber risk combines impact with likelihood.
Learn threat informed defense within cyber intelligence by defining your mission, identifying threat actors in your industry, their motivations, and how to detect and protect against tactics, techniques, and procedures.
Explain how tactics, techniques, and procedures map from high-level threat actor behavior to detailed actions, clarifying how reconnaissance, scanning, and vulnerability scanning differ in the Mitre Attack framework.
Differentiate iocs from ioas by noting iocs are evidence such as file hashes and domains, while ioas reveal attacker intent and behavior for threat-informed defense.
Explore the pyramid of pain, which shows how attackers struggle to change indicators—from hashes and IPs to domain names, tools, and finally TPS.
Explore enterprise, OSINT, and social media sources for cyber threat intelligence, from paid tools like Microsoft Defender Threat Intelligence to VirusTotal, Pulse Check, and IOCs on Twitter, LinkedIn, and Medium.
define vulnerabilities as weaknesses in information systems, security procedures, or implementations that threats can exploit. these weaknesses include human factors, physical security, hardware, and misconfigurations beyond CVEs.
Explore the CVE framework and how vulnerabilities receive a CVE id, with Cvss scores and vendor announcements. See a Chrome vulnerability example showing remote code execution via crafted JavaScript.
Learn how the common vulnerability scoring system (CVSS) ranks vulnerabilities, why CVSS scores alone can be misleading for asset criticality, and how CVSS version two and CVSS version three differ.
Explore threat analytics in Defender XDR, linking vulnerabilities and active threats to prioritize protections against misconfigurations. Review threat profiles, analyst reports, detections, and recommended actions for exposure management.
Explore Defender XDR intel profiles, exposing 219 threat actors with aliases, country origins, targets, ttps, IOCs, phishing tactics, and C2 infrastructure for threat-informed defense.
Explore Microsoft's Intel Explorer to search threat intelligence content, including IOCs, techniques, and articles, and learn to query profiles, domains, and MITRE tactics for Defender XDR.
Explore Microsoft Sentinel, a cloud native SIEM and SOAR on Azure with pay-as-you-go pricing. Ingest data from any source, use connectors, and detect, investigate, and respond to threats.
Identify deployment prerequisites for Sentinel by ensuring an active Azure tenant and subscription, creating resource groups, and provisioning a Log Analytics workspace as the backbone for Sentinel.
Create a Log Analytics workspace within a new resource group to deploy Sentinel, selecting the correct subscription and East US region, and complete validation before deployment.
Demonstrates creating a Sentinel workspace by adding it to an existing Log Analytics workspace, and highlights a free first-month allowance of ten gigabytes per day for Sentinel and Log Analytics.
Explore Sentinel rbac roles from view-only reader to central contributor who creates rules and configures data connectors, with Sentinel Responder and playbook operator managing incidents and playbooks.
Connect Microsoft Sentinel with Defender XDR by installing Defender XDR in Sentinel content hub and linking the Sentinel workspace to access workbooks, hunting queries, and notebooks in unified SoC portal.
Identify typical SIEM data sources across application, network, OS, and platform layers, including SAP access logs, Azure Firewall, Windows events, Azure activity, and Defender for Cloud.
Explore the content hub and its integration of data connectors and solutions. Filter by status, content type, and provider to discover Azure Active Directory with analytics rules, playbooks, and workbooks.
Ingest threat intelligence into sentinel by installing a threat intel solution and configuring the pulse dive data connector. Register for an API key and set hourly ingestion of indicators.
Validate CTI ingestion by selecting the taxi data connector and running a query to view the threat intelligence indicator table in Microsoft Sentinel. Note these are test indicators.
Learn to ingest Entra ID into Sentinel by installing the Azure Active Directory (Entra ID) data connector, enabling audit logs, and validating workspace permissions and required roles.
Verify Entra ID ingestion by checking the entry ID connector and log analytics, confirming six audit log events and a newly created user in target resources.
Learn to use data collection rules and the Azure Monitor agent to route security logs from eight VMs to Sentinel and observability logs from two VMs to a separate workspace.
Provision a Windows Server 2022 virtual machine in Azure, configure the Azure Monitor Agent Connector data collection rule to ingest Windows security events into Sentinel, and verify via Log Analytics.
Set up a Sentinel workspace, ingest data with connectors, and develop analytic rules to convert logs into alerts and incidents, then use automation rules and playbooks to respond.
Master analytic rules in Microsoft Sentinel to detect threats using KQL, leveraging over 500 predefined templates and seven rule types, with a 512 rule per workspace limit.
Explore analytic rules in the analytics console of your Sentinel workspace, using Content Hub rule templates for intra and threat intelligence, including the entra data source.
Learn to build a scheduled analytic rule in Sentinel by querying audit logs for new user additions, using a five-minute schedule, zero threshold, and incident creation with automation rules.
Create and configure a scheduled analytic rule in Microsoft Sentinel using a KQL query on audit logs to detect new user additions, set a five-minute schedule and automated incident responses.
Create a scheduled analytic rule to monitor Windows security event logs for new process creation (event id 4688) every five minutes and observe persistence and create or modify system process.
Explore near real time rules in Sentinel that run every minute for up-to-the-minute detections with a one-minute lookback, plus the 50-rule per workspace limit.
Create a near real time (NRT) rule in Sentinel, name it 'User Added to enter NRT', and enable grouping for a single alert.
Enable and configure the fusion engine in Sentinel to leverage Microsoft’s multi-stage detection across data sources, shifting detections to Microsoft with a single fusion rule per workspace.
Configure fusion rules in your Sentinel workspace using the fusion rule template for advanced multi-stage attack detection, select data sources, include or exclude severities, and maintain one fusion rule.
Explore machine learning behavior analytics in microsoft sentinel, detecting unusual rdp or ssh activity from unseen IPs, geos, or new users, with a seven-day baseline and two rules.
Enable ML behavior analytics rules for RDP and SSH by selecting the anomalous RDP login detections template and allow seven days to build a profile of normal activity.
Enable threat intelligence rules in sentinel to alert on defender threat intelligence indicators matching event logs, delivering high fidelity detection with low false positives when using paid defender threat intel.
Demonstrates creating threat intelligence rules in sentinel using rule templates, enabling an active rule that relies on defender threat intelligence and IOCs while noting licensing considerations.
Forward alerts from other Microsoft security services into Sentinel as incidents using the Microsoft Security rule type, such as Defender for Endpoint alerts turning into Sentinel incidents.
Demonstrates creating a Microsoft incident creation rule to forward Defender for Cloud alerts to Sentinel, generating incidents for any Defender for Cloud alert with automated response.
Explore the incident queue and view open and new incidents, then use the investigation dashboard, incident graph, entities, alerts, tasks, and automation options including playbooks and a teams channel.
Explore UEBA in Sentinel by building behavior profiles to baseline entity activity and detect early anomalies, ingesting data from on-premises, SaaS, cloud providers, and Entra into Log Analytics.
Enable ueba in sentinel by turning on intra audit logs, selecting anomalies from entra, and tuning production versus flighting modes to detect anomalous sign-ins and account changes.
Explore automation rules in Sentinel to centrally automate incident handling and assist with initial triage by actions like assigning users, tagging incidents, changing status, and triggering playbooks.
Demonstrates an automation rule tied to a scheduled rule for incident triage, using Sentinel or m365 Defender triggers and new user added to update status, severity, owner, and tag.
Learn how Sentinel playbooks automate complex security tasks by triggering Azure Logic Apps and integrating with automation rules, other Microsoft security products, and third-party systems.
Compare automation rules and playbooks in Azure Sentinel: automation rules are free and limited to Sentinel triage, while playbooks trigger Logic Apps for complex automations with nearly limitless connectors.
Automate security workflows with Azure Logic Apps by triggering Sentinel incidents to create ServiceNow tickets and by letting users submit incidents via Microsoft Forms, powered by pre-built connectors.
Learn to use the get geo from IP and tag incident playbook to derive geo location from an IP and tag incidents in Azure Sentinel.
Explore notebooks in Sentinel to use Python and Jupyter notebooks for threat hunting, data analysis, and machine learning. Set up an Azure Machine Learning workspace and note potential costs.
Demonstrates creating Sentinel notebook from the getting started template and provisioning an Azure Machine Learning workspace. Uses MSTICPy to query Sentinel data and enrich results with VirusTotal and Geo Lite.
Compare Sentinel's legacy pricing with its current model, covering Log Analytics, data retention, restoring, archiving, and advanced capabilities; the current model centers pricing on data ingested and Logic Apps.
Explore commitment tiers in Sentinel to optimize costs by daily ingestion, unlocking discounts from 34% at 100 GB to 55% at 50 TB, with monthly commitment and easy switch back.
Understand Sentinel log types: analytics for continuous monitoring, basic for high‑volume inquiries, and archive for storage. Save costs by moving analytics to archive after 90 days and restoring when needed.
Discover how analytics and archive logs in Microsoft Sentinel interact, with automatic transfer after 90 days, and how to restore archived logs to analytics for forensic investigations.
Configure the Microsoft Sentinel optimization workbook to analyze data ingestion, costs, and commitments. Filter by subscription and workspace and view template to save the central optimization workbook.
Explore building Kusto query language queries from a security hypothesis, identify the right tables, examine schema, filter with where, and summarize results.
Learn to write kql queries in log analytics, using where, take, count, summarize, project, distinct, order by, and visualization options like bar and pie charts to analyze security events.
Copilot for security offers a generative AI-powered assist to boost defender efficiency in incident response, threat hunting, intelligence gathering, and posture management, including incident summarization and guided remediation.
Explore how prompting and context drive Copilot for security's responses, with plugins shaping execution and the impact of good versus bad prompts on quality.
Understand the copilot for security architecture, built on three pillars—organizational security data, Microsoft Threat Intelligence, and copilot data—and its embedded and standalone experiences with plugins.
Explore how to extend Copilot for security with Microsoft and third-party plugins, including Defender XDR, Sentinel, Intune, Purview, Entra, and connectors to Azure Logic Apps.
Discover how Copilot for security keeps data private, prevents it from training models, encrypts data at rest and in transit with EU data residency, and avoids sharing with OpenAI.
Explore how authentication and RBAC govern Copilot for security access, plugins, and prompts, detailing Copilot roles, Entra roles, and Azure RBAC, plus licensing requirements.
Compare the standalone and embedded experiences of Copilot for security, and learn when to use each within Defender XDR, Intune, and Purview.
Explore Copilot for security pricing with security compute units provisioned by the hour, $4 per skew per hour, and guidance to start with three skews per hour.
Identify the three onboarding requirements for Copilot for security: an Azure subscription, an Entra ID tenant with roles, and provisioning security capacity units.
Create an Azure resource group named Copilot demo, then deploy Microsoft Copilot for security compute capacities in Europe West. Review the validation and view the resource to verify deployment.
Set up Copilot for security by selecting the created capacity, then explore prompts, prompt books, and plugins to enable incident analysis and guided responses.
Craft effective prompts for Copilot in security by defining objectives, providing context, and setting expectations. Use plugins, specify audiences and sources, and iterate with prompt books.
Monitor prompt usage with a quick, filterable dashboard that shows per-hour provisioning and consumption, and lets you view 24 hours, 3 days, 7 days, or a custom range for transparency.
Generate a defender XDR incident from sample alerts for a virtual machine, highlighting high-severity events like Petya ransomware indicators, digital currency mining, and suspicious PHP execution.
Explore a demo of the suspicious script analysis promptbook, detailing six prompts that analyze a log4j2 exploit script, extract indicators, assess threat intel, and guide incident response.
Dive into the vulnerability impact assessment for log4shell, exploring four prompts on CVE summaries, threat intelligence, mitigations, and executive reports, with emphasis on remote code execution and patching.
Explore cyber threat intelligence prompts to summarize threats, build actor profiles like Ghost Blizzard and Ghost Lizard, map TTPs to MITRE, collect IOCs, and generate Defender XDR KQL detections.
Learn to manage vulnerabilities with Copilot prompts, using Defender Threat Intelligence to extract CVEs, identify public exploits, and map threat actors to vulnerabilities in a practical workflow.
Explore the MITRE ATT&CK framework, outlining adversarial tactics and techniques to enable threat-informed defense. Discover how MITRE provides resources and Sentinel case studies to apply the framework in Microsoft security.
Align the pyramid of pain with Mitre attack offerings, emphasizing tactics, techniques, and sub techniques over artifacts. Note that tools like Mimikatz appear but are not the focus.
Miter matrices categorize enterprise, mobile, and ICS, with Windows, Linux, Mac OS, networks, containers, and cloud tools like Azure AD (entry id), O365, Google Workspaces; mobile covers iOS and Android.
Explore the Mitre attack framework's tactics, their high-level objectives, and the typical kill chain from reconnaissance to exfiltration and impact, including examples like Mimikatz.
Explore how attackers apply 201 techniques across tactics, from active reconnaissance and phishing to credential access and data exfiltration, with examples like scheduled tasks, masquerading, and encrypted C2 channels.
Implement preventative configurations to reduce the attack surface and minimize data exposed to external parties. Establish privileged account management to mitigate privilege escalation risks in Active Directory and scheduled tasks.
Explore how attack groups are identified by common behaviors and vendor naming conventions, including Apt41, Fancy Bear, and Midnight Blizzard, and why multiple names exist across Microsoft, CrowdStrike, and Mandiant.
Explore how software, malware, and tools used by adversaries link to techniques, groups, and campaigns, including built-in, public, commercial, and open or closed source options such as PowerShell.
Campaigns are orchestrated intrusion operations over a defined period with targets across multiple organizations, often by nation-state actors, such as the 2016 Ukraine power grid attack by Sandworm.
Explore how groups, tactics, objectives, and motivations relate, how exploit tools like Mimikatz enable techniques and sub techniques, and how data sources drive detections against adversaries.
Explore the MITRE ATT&CK enterprise matrix in the browser, examining tactics, techniques, sub-techniques, data sources, mitigations, and CTI to detect and defend against adversaries.
Explore how the Mitre attack framework is visualized in Sentinel's public preview heat map, showing active detection rules, anomalies, and coverage across tactics, techniques, and environments.
Explore building a ChatGPT powered playbook in Sentinel to enrich incident data with MITRE ATT&CK context. Automate comments and explanations using a logic app and OpenAI GPT-3.
Discover how Microsoft Entra unifies identity and access across four pillars—Entra ID (Azure Active Directory), zero-trust access with Entra Private Access, Entra Internet Access, and Entra ID governance—and permissions management.
Discover Microsoft Entra ID, the cloud identity and access management solution formerly Azure Active Directory, covering conditional access, B2B/B2C, application proxy, MFA, and identity protection.
Explore intra ID user identities, including synchronized on-premises active directory, cloud identities, and guest identities, and learn authentication options like username, password, MFA, and passwordless.
Create and configure a new user in Azure AD, including user principal name and display name. Assign roles or add the user to groups and provision in the tenant.
Discover Azure managed identities that eliminate credential management by handling authentication for resources, and compare system assigned and user assigned identities and their lifecycles.
Explore how to use managed identities in Azure by provisioning a resource group, a virtual machine, and a SQL database, and configuring system and user assigned identities with role assignments.
Explore how Entra ID groups simplify access management by assigning roles to groups instead of individuals, and learn about security groups, Microsoft 365 groups, and dynamic memberships.
Create a security or M365 group in Entra ID, name and describe it, choose membership type, and assign owners, members, and optional Azure role assignments.
Learn how administrative units cluster intra ID tenants to restrict role permissions by geography or division, enabling regional help desk control and streamlined identity management.
Create and manage administrative units in intra ID by adding a Europe unit, then assign members, groups, devices, and roles to this logical container for easier tenant management.
Explore Android authentication methods, including password, SMS, voice, OAuth tokens, Microsoft Authenticator, Windows Hello for Business, FIDO2 key, and certificate based authentication, and discuss passwordless options, MFA, and SPR.
Explore how Entra ID external identities enable secure collaboration with guests and customers through B2B collaboration, B2B Direct Connect, and B2C, including cross-tenant settings and access controls.
Configure external collaboration settings in Entra ID to manage guest access, invitations, external user leave settings, and domain-based restrictions for secure external partnerships.
Identity protection monitors identities, detects risk signals, and feeds decisions to conditional access and SIM tools like Microsoft Sentinel; it blocks access, triggers password resets, and enforces MFA.
Explore how Entra identity protection works with conditional access to monitor user and sign-in risk, configure policies, and migrate to conditional access for advanced controls.
Recognize passwords remain insecure, with 20% help desk resets, 72% reused, and 85% breaches leveraging passwords. Highlight phishing, keylogging, and brute force as threats; advocate multifactor authentication or passwordless options.
Examine how MFA options combine something you know, something you have, and something you are, highlighting passwordless like Windows Hello, FIDO2, and Microsoft Authenticator for phishing-resistant security.
Explore passwordless authentication with Windows Hello for business, where a device-tied nonce signs with a private key, enabling TPM-protected token and seamless single sign-on, while biometrics simplify end-user access.
Enforce real-time Android password protection with global and custom ban lists to block weak or compromised passwords across cloud and on-premises environments, including on-premises Active Directory via interconnect.
Explore single sign-on in the Microsoft ecosystem by authenticating once to access multiple apps. Entra ID enables SSO for internal and external users via on-premises AD sync.
Entra Verified ID enables decentralized identity by allowing users to establish a credential wallet with identity, work history, and certifications once, then trusted applications like LinkedIn can verify without re-verification.
Enable self-service password reset in Entra ID, apply to all users, and configure a converged policy with one or two authentication methods such as mobile app, email, or SMS.
Explore intra connect for hybrid environments, enabling password hash synchronization and pass-through authentication between on-premises Active Directory and cloud identity, with optional federation and health monitoring.
Explore hybrid authentication in a Microsoft environment, comparing cloud-only sign-in, on-premises active directory policies, and options like password hash sync and pass-through authentication to fit your requirements.
Enable intra domain services in the cloud to provide managed domain services such as domain join, LDAP, Kerberos, and NTLM authentication for legacy apps without deploying domain controllers.
Leverage Entra ID roles to grant permissions across the Microsoft ecosystem, not just Azure, with built-in roles like teams administrator, security administrator, and global reader for teams management and audits.
Enable secure Azure access with rbac by assigning security principals, role definitions, and scope; leverage built-in roles like AKS cluster admin and Sentinel contributor, plus custom roles for least privilege.
Azure RBAC manages access to Azure resources like VMs and databases, while Entra ID roles govern directory-level tasks for users and groups, clarifying scope and use.
Learn how conditional access enforces access control by evaluating user and device signals, including location, device compliance, and risk, during authentication to enable zero-trust security for cloud and on-prem resources.
Explore how to configure a conditional access policy in Azure, targeting Office 365 for all users with high user and sign‑in risks, and test in report only mode.
Defender for identity conducts proactive posture assessments to reduce identity risk, then identifies, detects, and investigates threats like pass the hash, with Defender XDR integration.
Identities form the new security perimeter, replacing traditional firewalls between network edges and internet, enabling identity security in cloud environments under zero-trust models.
Explain the properties of cryptographic hash functions—preimage resistance, second preimage resistance, and true collision resistance—and NTLM’s challenge-response authentication flow, noting that hashing is not encryption and NTLM lacks mutual authentication.
Describe how attackers exploit pass-the-hash attacks to authenticate with NTLM hashes using tools like Mimikatz, enabling lateral movement from a standard user device to privileged accounts.
Kerberos uses tickets for network authentication, issuing a short-lived TGT via the KDC, then service tickets from the TGS to access resources, enabling mutual authentication.
Attackers extract Kerberos tickets from a user device using Mimikatz and pass the ticket to other machines to authenticate with the TGT and TGS, enabling lateral movement.
Explore brute force attacks, including domain controller compromise, pass-the-hash attacks on privileged users, and rainbow tables that precompute string-to-hash mappings like MD5 to crack hashes.
Remote code execution lets attackers run code on a remote machine, often unauthenticated, enabling lateral movement to privileged assets via techniques like log4shell, pass the hash, or pass the ticket.
Learn how to create an app registration in Entra ID, configure account types and redirect URI, and reference the resulting client and object IDs for authentication.
Enable secure remote access to on-premises web apps via the Entra application proxy, offering single sign-on, conditional access, and MFA without inbound VPN or firewall changes.
Explore Entra ID governance and role in managing identity and access. Learn about entitlement management, privileged identity management with just-in-time access and approval workflows, and access reviews with lifecycle workflows.
Enable scalable identity governance with Entra ID entitlement management by creating role-based access packages and collections, automating access requests, approvals, and reviews for internal and external users.
Discover privileged identity management in Entra ID (PIM) and how just-in-time, time-bound access with approval and multifactor authentication protects privileged roles, with auditing and notifications.
Explore how access reviews in azure and entra help manage and audit group memberships, application access, and privileged role assignments, reducing permission creep through monthly manager reviews with automatic application.
EPM provides cross-cloud visibility, control, and continuous monitoring of permissions across Azure, AWS, and GCP, enabling least privilege, just-in-time access, and automated risk remediation.
Discover Microsoft Purview, a unified platform for data security, governance, and risk compliance across on-prem, multi-cloud, and SaaS. It enables data loss prevention, labeling, encryption, and eDiscovery to protect data.
Identify sensitive information types in Microsoft Purview using manual, automated pattern recognition, or machine learning, then define patterns with primary and supporting elements, proximity, and confidence levels to drive DLP.
Discover how to access Microsoft’s predefined sensitive information types in Purview, including social security numbers and Amazon S3 client secret access key, and examine details, matches, and patterns.
Explore sensitivity labels in Microsoft Purview to classify and protect data with encryption and content markings. Extend protection to meetings, Power BI, and third-party apps through Defender for Cloud Apps.
Identify and manage sensitivity labels in Purview, including creating a top secret label with file and email scope and configurable protection settings.
Protect sensitive data with data loss prevention (DLP) in Microsoft Purview by enforcing policies that identify, monitor, and block risky sharing across M365.
Demonstrates creating a DLP policy in Microsoft Purview for US financial data, protecting credit card and bank details across Exchange, SharePoint, OneDrive, Teams, and devices with alerts and policy tips.
Purview records management enables organizations to govern regulatory, legal, and business critical records. Apply retention labels to declare items as records, restrict actions, and capture proof of disposition for compliance.
Explore retention labels and retention label policies in Purview, learn how to retain or delete content, and apply item-level versus policy-level settings for scalable governance.
Learn insider risk management in purview, detecting and mitigating internal threats such as data leakage and IP theft, with policy creation and privacy by design.
Explore insider risk management in Microsoft Purview, including auditing, analytics, policy creation, and alert tuning to detect insider threats and integrate with Defender XDR.
Explore purview eDiscovery and its three solutions: content search, eDiscovery standard, and eDiscovery premium, to identify, hold, collect, review, and export electronic information across Microsoft 365 for legal cases.
Create and manage eDiscovery cases in Purview, build searches across mailboxes and sites, use the query builder to locate keywords like payroll, and export case information.
Defender for Cloud unifies devsecops, cspm, and cloud workload protection as a cnapp solution, scanning GitHub, Azure DevOps, and GitLab for misconfigurations, secrets, and CVEs.
Explore defender for cloud plans across CSPM and CW, including a free foundational CSPM plan and defender for app services, servers, databases, storage, containers, key vault, and APIs.
Explore Defender for Cloud RBAC roles, including security reader, security admin, and resource group and subscription permissions; learn to assign contributor or owner rights and create custom roles.
Enable all Defender for Cloud plans in your Azure subscription, noting cost implications; configure CSPM, Defender for Service, databases, storage, and containers plans from Defender for Cloud settings.
Explain cloud security posture management (CSPM) as a proactive, preventive approach that hardens resources, provides detailed visibility into assets and workloads, and guides security-state improvements with hardening guidance.
Compare two Defender for cloud cspm plans: foundational cspm free and Defender cspm paid. Foundational offers asset inventory, secure score, and recommendations; Defender cspm adds agentless scanning and container security.
Defender for cloud's asset inventory lists resources across Azure, AWS, and GCP, letting you see subscriptions with outstanding recommendations and identify tag critical VMs missing the Azure Monitor agent.
Explore asset inventory in Defender for Cloud to view resource counts and unhealthy resources, then filter by type, environment, or recommendations; export a CSV or run a KQL query.
Explore how Defender for Cloud generates security recommendations by assessing resources across Azure, AWS, GCP, and on premises to identify improvements against security controls, evaluated and implemented via Azure policy.
Explore Defender for Cloud security recommendations, view active items by severity, and identify unhealthy resources. Filter by Azure, AWS, GCP and DevOps tools to target unassigned high severity fixes.
Explore secure score in defender for cloud, a 0–100 metric that signals your security level across cloud and on-prem resources, guided by recommendations for virtual machines, identities, apps, and databases.
Explore how to view and improve the Microsoft Secure Score in Defender for Cloud by reviewing recommendations, enabling MFA, and applying system updates to boost the score.
Explore Azure Workbooks to visualize data and build dashboards across Defender for Cloud, Sentinel, and Azure Monitor, using KQL or drop down menus, including pre-built secure score over time.
Explore Defender for Cloud workbooks to visualize active alerts and system updates, build custom visualizations, and monitor VMs' patch levels and CPU usage across subscriptions.
Configure data exporting in Defender for Cloud to stream security findings, secure score, and alerts to an event hub or log analytics workspace, with selectable benchmarks and frequencies.
Defender for cloud offers remediation guidance and quick fixes. Do not use quick fixes with infrastructure as code to avoid drift; remediate in source code and consult workload owners.
Explore Defender for Cloud remediation options, from manual fixes to quick fixes, enabling MFA for accounts with write permissions and auto-updating two Windows VMs within a 30-minute freshness interval.
Explore the microsoft cloud security benchmark to apply best practices and recommendations for cloud resources across defender for cloud, covering control domains such as network security and identity management.
Discover defender for cloud, covering domains like network security, incident response posture, and vulnerability management, with 137 controls and quick fixes for aws and gcp.
Enforce governance rules to automatically assign an owner and a due date to remediation recommendations, establishing accountability and an SLA while automating background processes to reduce manual work.
Connect to Defender for Cloud to create governance rules, set scope, priority, impacted recommendations, and assign owners with a seven-day remediation window and weekly email notifications.
See how defender for cloud assesses regulatory compliance against ISO 27,001, NIST benchmark, PCI DSS, Soc2 type two, and CIS by checking technically verifiable controls.
Explore regulatory compliance in defender for cloud by importing standards like the Microsoft Cloud Security benchmark and ISO 27,001, and enable NIST 853 and CIS benchmarks for Azure.
Use the cloud security explorer in Defender for Cloud to query logs and resources with drop-downs, no sql or kql needed, to identify internet-connected, vulnerable virtual machines.
Explore the cloud security explorer in defender for cloud using dropdowns and prebuilt query templates to find resources, VMs, and vulnerabilities without writing kql.
Use attack path analysis with defender CSPM to visualize exploitable paths, showing internet-exposed VMs with vulnerabilities accessing a key vault or a public Azure Blob storage.
Explore agentless vulnerability scanning for virtual machines across Azure, AWS, and GCP, delivering zero performance impact by scanning disk snapshots in an isolated environment feeding results to Defender for Cloud.
This course contains the use of artificial intelligence.
This SC-100 course by Christopher Nett is a meticulously organized Udemy course designed for IT professionals aiming to pass the Microsoft SC-100: Microsoft Cybersecurity Architect Expert exam. This course systematically guides you from the basis to advanced concepts of Cyber Security.
By mastering Microsoft Cybersecurity Architectures, you're developing expertise in essential topics in today's cybersecurity landscape.
The course is always aligned with Microsoft's latest study guide and exam objectives:
Skills at a glance
Design solutions that align with security best practices and priorities (20–25%)
Design security operations, identity, and compliance capabilities (25–30%)
Design security solutions for infrastructure (25–30%)
Design security solutions for applications and data (20–25%)
Design solutions that align with security best practices and priorities (20–25%)
Design a resiliency strategy for ransomware and other attacks based on Microsoft Security Best Practices
Design a security strategy to support business resiliency goals, including identifying and prioritizing threats to business-critical assets
Design solutions for business continuity and disaster recovery (BCDR), including secure backup and restore for hybrid and multicloud environments
Design solutions for mitigating ransomware attacks, including prioritization of BCDR and privileged access
Evaluate solutions for security updates
Design solutions that align with the Microsoft Cybersecurity Reference Architectures (MCRA) and Microsoft cloud security benchmark (MCSB)
Design solutions that align with best practices for cybersecurity capabilities and controls
Design solutions that align with best practices for protecting against insider, external, and supply chain attacks
Design solutions that align with best practices for Zero Trust security, including the Zero Trust Rapid Modernization Plan (RaMP)
Design solutions that align with the Microsoft Cloud Adoption Framework for Azure and the Microsoft Azure Well-Architected Framework
Design a new or evaluate an existing strategy for security and governance based on the Microsoft Cloud Adoption Framework (CAF) for Azure and the Microsoft Azure Well-Architected Framework
Recommend solutions for security and governance based on the Microsoft Cloud Adoption Framework for Azure and the Microsoft Azure Well-Architected Framework
Design solutions for implementing and governing security by using Azure landing zones
Design a DevSecOps process that aligns with best practices in the Microsoft Cloud Adoption Framework (CAF)
Design security operations, identity, and compliance capabilities (25–30%)
Design solutions for security operations
Design a solution for detection and response that includes extended detection and response (XDR) and security information and event management (SIEM)
Design a solution for centralized logging and auditing, including Microsoft Purview Audit
Design monitoring to support hybrid and multicloud environments
Design a solution for security orchestration automated response (SOAR), including Microsoft Sentinel and Microsoft Defender XDR
Design and evaluate security workflows, including incident response, threat hunting, and incident management
Design and evaluate threat detection coverage by using MITRE ATT&CK matrices, including Cloud, Enterprise, Mobile, and ICS
Design solutions for identity and access management
Design a solution for access to software as a service (SaaS), platform as a service (PaaS), infrastructure as a service (IaaS), hybrid/on-premises, and multicloud resources, including identity, networking, and application controls
Design a solution for Microsoft Entra ID, including hybrid and multi-cloud environments
Design a solution for external identities, including business-to-business (B2B), business-to-customer (B2C), and decentralized identity
Design a modern authentication and authorization strategy, including Conditional Access, continuous access evaluation, risk scoring, and protected actions
Validate the alignment of Conditional Access policies with a Zero Trust strategy
Specify requirements to harden Active Directory Domain Services (AD DS)
Design a solution to manage secrets, keys, and certificates
Design solutions for securing privileged access
Design a solution for assigning and delegating privileged roles by using the enterprise access model
Evaluate the security and governance of Microsoft Entra ID, including Microsoft Entra Privileged Identity Management (PIM), entitlement management, and access reviews
Evaluate the security and governance of on-premises Active Directory Domain Services (AD DS), including resilience to common attacks
Design a solution for securing the administration of cloud tenants, including SaaS and multicloud infrastructure and platforms
Design a solution for cloud infrastructure entitlement management that includes Microsoft Entra Permissions Management
Evaluate an access review management solution that includes Microsoft Entra Permissions Management
Design a solution for Privileged Access Workstation (PAW), including remote access
Design solutions for regulatory compliance
Translate compliance requirements into security controls
Design a solution to address compliance requirements by using Microsoft Purview
Design a solution to address privacy requirements, including Microsoft Priva
Design Azure Policy solutions to address security and compliance requirements
Evaluate and validate alignment with regulatory standards and benchmarks by using Microsoft Defender for Cloud
Design security solutions for infrastructure (25–30%)
Design solutions for security posture management in hybrid and multicloud environments
Evaluate security posture by using Microsoft Defender for Cloud, including the Microsoft cloud security benchmark (MCSB)
Evaluate security posture by using Microsoft Secure Score
Design integrated security posture management solutions that include Microsoft Defender for Cloud in hybrid and multi-cloud environments
Select cloud workload protection solutions in Microsoft Defender for Cloud
Design a solution for integrating hybrid and multicloud environments by using Azure Arc
Design a solution for Microsoft Defender External Attack Surface Management (Defender EASM)
Specify requirements and priorities for a posture management process that uses Exposure Management attack paths, attack surface reduction, security insights, and initiatives
Specify requirements for securing server and client endpoints
Specify security requirements for servers, including multiple platforms and operating systems
Specify security requirements for mobile devices and clients, including endpoint protection, hardening, and configuration
Specify security requirements for IoT devices and embedded systems
Evaluate solutions for securing operational technology (OT) and industrial control systems (ICS) by using Microsoft Defender for IoT
Specify security baselines for server and client endpoints
Evaluate Windows Local Admin Password Solution (LAPS) solutions
Specify requirements for securing SaaS, PaaS, and IaaS services
Specify security baselines for SaaS, PaaS, and IaaS services
Specify security requirements for IoT workloads
Specify security requirements for web workloads
Specify security requirements for containers
Specify security requirements for container orchestration
Evaluate solutions that include Azure AI Services Security
Evaluate solutions for network security and Security Service Edge (SSE)
Evaluate network designs to align with security requirements and best practices
Evaluate solutions that use Microsoft Entra Internet Access as a secure web gateway
Evaluate solutions that use Microsoft Entra Internet Access to access Microsoft 365, including cross-tenant configurations
Evaluate solutions that use Microsoft Entra Private Access
Design security solutions for applications and data (20–25%)
Evaluate solutions for securing Microsoft 365
Evaluate security posture for productivity and collaboration workloads by using metrics, including Microsoft Secure Score
Evaluate solutions that include Microsoft Defender for Office and Microsoft Defender for Cloud Apps
Evaluate device management solutions that include Microsoft Intune
Evaluate solutions for securing data in Microsoft 365 by using Microsoft Purview
Evaluate data security and compliance controls in Microsoft Copilot for Microsoft 365 services
Design solutions for securing applications
Evaluate the security posture of existing application portfolios
Evaluate threats to business-critical applications by using threat modeling
Design and implement a full lifecycle strategy for application security
Design and implement standards and practices for securing the application development process
Map technologies to application security requirements
Design a solution for workload identity to authenticate and access Azure cloud resources
Design a solution for API management and security
Design solutions that secure applications by using Azure Web Application Firewall (WAF)
Design solutions for securing an organization's data
Evaluate solutions for data discovery and classification
Specify priorities for mitigating threats to data
Evaluate solutions for encryption of data at rest and in transit, including Azure KeyVault and infrastructure encryption
Design a security solution for data in Azure workloads, including Azure SQL, Azure Synapse Analytics, and Azure Cosmos DB
Design a security solution for data in Azure Storage
Design a security solution that includes Microsoft Defender for Storage and Microsoft Defender for Databases
This course contains promotional materials.