
Gain real-world, hands-on insights into Azure, cybersecurity, cloud, and AI architectures from a Microsoft veteran architect who teaches by sharing practical, experience-based guidance.
Explore data security as a subset of cyber security that protects sensitive data throughout its life cycle, using access controls, authentication, encryption, backups, data loss prevention, and insider risk management.
Identify and explain data security threats, including hacking, malware, phishing, data leakage, fraud, and insider threats, and highlight the role of natural disasters, negligence, and exfiltration risks to protect assets.
Navigate the growing complexity of cyber security by coordinating people, cloud services, endpoints, and IoT across networks; address challenges like talent gaps, advanced threats, automation, data deluge, and noisy alerts.
A security operations center coordinates threat intelligence, threat hunting, log management, and threat detection to identify adversaries, gather indicators of compromise, and drive incident response and root-cause forensics.
The three-tier SoC model uses automation at base for commodity malware, tier one handles easy alerts, tier two tackles advanced threats, and tier three conducts proactive threat hunting and forensics.
Learn the NIST-developed incident response process: preparation, detection and analysis, containment and eradication, recovery, and post-incident activity, with stakeholder alignment and lessons learned.
Explore how EDR and XDR monitor endpoint and network behavior, how SIEM (Sentinel) collects and correlates logs, and how SOAR (Logic Apps) automates incident response within the Microsoft security ecosystem.
Unify blue and red teams into a purple team to strengthen security posture, combining blue monitoring and incident response with red vulnerability testing and social engineering, and simulating adversary tactics.
Learn the NIST definition of a threat, a circumstance that could adversely affect operations or assets through an information system, including unauthorized access, destruction, disclosure, or denial of service.
Explain intelligence, threat intelligence, and cyber threat intelligence (CTI), noting that CTI focuses on adversaries using tactics, techniques, and procedures in cyber operations, while general threat intelligence can be non-cyber.
Define cyber threat intelligence as knowledge about adversaries' motivations, intentions, and methods, captured as ttps, to inform defense and protect assets.
Clarify threats, vulnerabilities, and risks, identify threat actors, and explain how exploiting vulnerabilities causes downtime, confidentiality breaches, or integrity violations, with risk defined as the combination of impact and likelihood.
Explore threat informed defense, using cyber threat intelligence to align defenses with your mission, identify threat actors and their motivations, and detect and protect against their TTPs.
Explore how tactics, techniques, and procedures (TTPs) define threat actor behavior from high-level objectives to detailed procedures. Compare Mitre Attack framework's approach and illustrate reconnaissance and vulnerability scanning as examples.
Differentiate IOCs, such as file hashes and domains, from IOAs, which focus on attacker intent and behavior. Ingest IOCs into SIEM/EDR/XDR to enable threat-informed defense against observed behaviors.
The pyramid of pain ranks how attackers must work to change indicators, from hashes and IP addresses to domain names, tools, and tactics, techniques, and procedures, encouraging prioritizing TPS detection.
Examine cyber threat intelligence sources across enterprise tools, OSINT, and social media, including Microsoft Defender Threat Intelligence, VirusTotal, Shodan, IOCs, IOAs, and TTPs.
Define zero trust as a security strategy and mindset, not a product, verify explicitly across data points, enforce just-in-time and just-enough access, and assume breach to limit blast radius.
Explore the Microsoft security cosmos, covering defender for identity, endpoint, cloud apps, and defender for cloud, plus sentinel and copilot to boost security operations center effectiveness in a multi-cloud landscape.
Explore a classic cyber kill chain and how Microsoft Defender products defend stages from phishing to data exfiltration, using Defender for Office, Endpoint, Identity Plus, Entra ID protection, and XDR.
Learn how cloud computing enables on-demand self-service, fast network access, resource pooling, rapid elasticity, and measured service, driving scalable, billable, and secure IT resources.
Understand five cloud properties—on-demand self-service, network access, resource pooling, rapid elasticity, and measured service—that enable quick provisioning, scalable workloads, and usage-based billing.
Explore the Azure global backbone, including data centers, fiber networks, subsea cables, and edge sites. Understand how 60 regions, over 20,000 peering connections, and 500+ network partners deliver resilience.
Explore shared responsibility in Azure, AWS, and GCP, detailing which security tasks fall to customers vs providers across IaaS, PaaS, and SaaS.
Explore the Azure resource hierarchy from management groups to subscriptions and resource groups, and learn how grouping resources by shared life cycle supports governance and cost tracking.
Explore Azure subscription types, including free credits for 30 days and for 12 months on student options, plus pay-as-you-go and enterprise agreements, highlighting demos.
Clarify how Entra ID tenants relate to Azure subscriptions, showing that identities in a tenant access resources in subscriptions and resource groups, not that subscriptions themselves are tenants.
Create your free Azure subscription by following the resources link, compare free and pay-as-you-go options, enter your personal details, then log in to portal.azure.com to start building.
Explore microsoft purview, a unified data governance, security, and compliance platform that governs, protects, and manages data across on-prem, multi-cloud, and saas with visibility and lifecycle management.
Explore the new purview portal with new features and easier navigation than the legacy portal. This course will use the new portal for all demos.
Acquire a Microsoft 365 E5 trial and assign it to your user to enable defender XDR features, using the resources page and portal to complete the license assignment.
Discover the Purview portal, featuring a new, easier-to-use interface with updated features, and follow along as the course demos use the new portal accessible at purview.microsoft.com.
Explore role based access control in Microsoft Purview via the M365 admin portal, assigning built in roles like global administrator or security administrator, and comparing compliance roles to manage permissions.
Identify sensitive information types in Microsoft Purview using manual, pattern-based, or machine learning detection; use built-in, named entity, or custom SITs for data loss prevention policies and labeling.
Explore how Purview uses information protection classifiers to detect sensitive information types, including predefined and custom types, with pattern-based detection for US Social Security numbers and Amazon S3 keys.
Create and manage a custom sensitive information type for credit card numbers in purview, using patterns, proximity, confidence levels, and built-in functions.
Learn how exact data match (EDM) classifiers in information protection detect matches from your organization's data. Create, upload a sensitive-data file, test in simulation, and publish in purview.
Understand trainable classifiers in Microsoft Purview for content categorization and protection. Learn about pre-trained and custom classifiers, manual and automated pattern matching, and auto labeling to enforce sensitivity policy.
Explore trainable classifiers in purview, with 113 pre-populated options for business, finance, and offensive content across languages; create your own by linking a SharePoint site with 50–500 English office documents.
This course contains the use of artificial intelligence.
This SC-400 course by Christopher Nett is a meticulously organized Udemy course designed for IT professionals aiming to pass the SC-400: Administering Information Protection and Compliance exam. This course systematically guides you from the basics to advanced concepts of Microsoft Information Protection and Compliance.
The course is always aligned with Microsoft's latest study guide and exam objectives:
Implement information protection (25–30%)
Implement DLP (15–20%)
Implement data lifecycle and records management (10–15%)
Monitor and investigate data and activities by using Microsoft Purview (15–20%)
Manage insider and privacy risk in Microsoft 365 (15–20%)
Implement information protection (25–30%)
Create and manage sensitive info types
Identify sensitive information requirements for an organization's data
Translate sensitive information requirements into built-in or custom sensitive info types
Create and manage custom sensitive info types
Create and manage exact data match (EDM) classifiers
Implement document fingerprinting
Create and manage trainable classifiers
Identify when to use trainable classifiers
Design and create a trainable classifier
Test a trainable classifier
Retrain a trainable classifier
Implement and manage sensitivity labels
Implement roles and permissions for administering sensitivity labels
Define and create sensitivity labels
Configure and manage sensitivity label policies
Configure auto-labeling policies for sensitivity labels
Monitor data classification and label usage by using Content explorer, Activity explorer, and audit search
Apply bulk classification to on-premises data by using the Microsoft Purview Information Protection scanner
Manage protection settings and marking for applied sensitivity labels
Design and implement encryption for email messages
Design an email encryption solution based on methods available in Microsoft 365
Implement Microsoft Purview Message Encryption
Implement Microsoft Purview Advanced Message Encryption
Implement DLP (15–20%)
Create and configure DLP policies
Design DLP policies based on an organization’s requirements
Configure permissions for DLP
Create and manage DLP policies
Interpret policy and rule precedence in DLP
Configure a Microsoft Defender for Cloud Apps file policy to use DLP policies
Implement and monitor Endpoint DLP
Configure advanced DLP rules for devices in DLP policies
Configure Endpoint DLP settings
Recommend a deployment method for device onboarding
Identify endpoint requirements for device onboarding
Monitor endpoint activities
Implement the Microsoft Purview Extension
Monitor and manage DLP activities
Analyze DLP reports
Analyze DLP activities by using Activity explorer
Remediate DLP alerts in the Microsoft Purview compliance portal
Remediate DLP alerts generated by Defender for Cloud Apps
Implement data lifecycle and records management (10–15%)
Retain and delete data by using retention labels
Plan for information retention and disposition by using retention labels
Create retention labels for data lifecycle management
Configure and manage adaptive scopes
Configure a retention label policy to publish labels
Configure a retention label policy to auto-apply labels
Interpret the results of policy precedence, including using Policy lookup
Manage data retention in Microsoft 365 workloads
Create and apply retention policies for SharePoint and OneDrive
Create and apply retention policies for Microsoft 365 groups
Create and apply retention policies for Teams
Create and apply retention policies for Yammer
Create and apply retention policies for Exchange Online
Apply mailbox holds in Exchange Online
Implement Exchange Online archiving policies
Configure preservation locks for retention policies and retention label policies
Recover retained content in Microsoft 365
Implement Microsoft Purview records management
Create and configure retention labels for records management
Manage retention labels by using a file plan, including file plan descriptors
Classify records by using retention labels and retention label policies
Manage event-based retention
Manage the disposition of content in records management
Configure records management settings, including retention label settings and disposition settings
Monitor and investigate data and activities by using Microsoft Purview (15–20%)
Plan and manage regulatory requirements by using Microsoft Purview Compliance Manager
Plan for regulatory compliance in Microsoft 365
Create and manage assessments
Create and modify custom templates
Interpret and manage improvement actions
Create and manage alert policies for assessments
Plan and manage eDiscovery and Content search
Choose between eDiscovery (Standard) and eDiscovery (Premium) based on an organization’s requirements
Plan and implement eDiscovery
Delegate permissions to use eDiscovery and Content search
Perform searches and respond to results from eDiscovery
Manage eDiscovery cases
Perform searches by using Content search
Manage and analyze audit logs and reports in Microsoft Purview
Choose between Audit (Standard) and Audit (Premium) based on an organization’s requirements
Plan for and configure auditing
Investigate activities by using the unified audit log
Review and interpret compliance reports and dashboards
Configure alert policies
Configure audit retention policies
Manage insider and privacy risk in Microsoft 365 (15–20%)
Implement and manage Microsoft Purview Communication Compliance
Plan for communication compliance
Create and manage communication compliance policies
Investigate and remediate communication compliance alerts and reports
Implement and manage Microsoft Purview Insider Risk Management
Plan for insider risk management
Create and manage insider risk management policies
Investigate and remediate insider risk activities, alerts, and reports
Manage insider risk cases
Manage forensic evidence settings
Manage notice templates
Implement and manage Microsoft Purview Information Barriers (IBs)
Plan for IBs
Create and manage IB segments and policies
Configure Teams, SharePoint, and OneDrive to enforce IBs, including setting barrier modes
Investigate issues with IB policies
Implement and manage privacy requirements by using Microsoft Priva
Configure and maintain privacy risk management
Create and manage Privacy Risk Management policies
Identify and monitor potential risks involving personal data
Evaluate and remediate alerts and issues
Implement and manage subject rights requests
This course contains promotional materials.