
Enable on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service to explain why we use cloud computing.
Learn public cloud basics with Azure, AWS, and GCP, and private options like Azure Stack, AWS Outposts, and Google Anthos for hybrid and multi-cloud deployments.
Explore the Azure global backbone, detailing data centers and connectivity across regions. Discover how edge sites, fiber, subsea cables, and peering connections deliver performance, fault tolerance, and disaster recovery.
Explain the shared responsibility model across on premises and cloud service models (iaas, paas, saas) in azure, aws, and gcp, and identify who handles security duties.
Understand the Azure resource hierarchy, with management groups, subscriptions, and resource groups. Group resources with the same lifecycle in a resource group, including VMs, networks, app services, and storage accounts.
Understand how Entra ID tenants host identities that access Azure resources in subscriptions and resource groups, and why subscriptions are not tenants—the tenant is the Entra ID identity provider.
Create a free Azure subscription by choosing free or pay-as-you-go and providing your contact details, then log in to portal.azure.com to start building.
demonstrates obtaining a Microsoft 365 E5 trial, assigning the E5 license to a user via portal.microsoft.com, and enabling Defender XDR features.
Understand how expanding complexity across people, cloud, endpoints, servers, mobile, OT/ICS, and IoT makes securing environments harder, and how talent, automation, data overload, and regulatory changes shape security programs.
A soc uses threat intelligence and threat hunting to identify adversary behavior and indicators of compromise, while managing sim logs and guiding incident response to reduce the attack surface.
Explore the three-tier security operations model, where automation and tier one handle roughly 70% of alerts, tier two handles about 25%, and tier three performs proactive threat hunting and forensics.
Outline the NIST incident response process from preparation through detection and analysis to containment, eradication, and recovery, ending with post-incident activity and lessons learned to improve measures.
Learn how EDR, XDR, SIEM, and SOAR enable behavior-based security monitoring across endpoints and the broader IT environment, using Defender tools, Sentinel, and Logic Apps for automated incident response.
Blue team performs soc duties: monitoring, incident response, forensics, and threat hunting with edr, xdr, siem, and soar; purple teaming unites blue and red to simulate adversaries and strengthen defenses.
Identify vulnerabilities as weaknesses in information systems, procedures, or implementations that threat sources can exploit, noting weaknesses exist beyond CVEs, including people, physical security, and hardware.
Learn how the common vulnerabilities and exposures (CVE) framework categorizes vulnerabilities, assigns CVE IDs, and documents descriptions, data sources, and vendor announcements, including CVSS scoring.
Learn how the common vulnerability scoring system assigns CVSS scores to vulnerabilities detected by scanners, compare version 2 and 3 severities, and weigh asset criticality alongside CVSS rankings.
Treat zero trust as a security strategy and mindset, not a product, guided by Microsoft’s principles. Verify explicitly, enforce least privilege access, and assume breach to minimize blast radius.
Explores the Microsoft security cosmos, focusing on cloud security, soc, and cyber threat intelligence, and surveys defender xdr suite, sentinel, and copilot for security across identities, endpoints, apps, and cloud.
Defend across attack chains with Microsoft security products. Defender for Office blocks phishing, Defender for Endpoint prevents exploits, and Defender for Identity Plus and ID protection safeguard accounts, and Sentinel.
Recognize identities as the new security perimeter as traditional network barriers erode, and prioritize identity security to defend cloud-enabled enterprises against evolving threats.
Learn how authentication (authN) verifies a user's identity to grant access using passwords, biometrics, or OTP, and why it precedes authorization, with Kerberos and SAML as common protocols.
Define authorization (authZ) as determining user permissions after authentication, deciding what you can access, and outline role-based access control, attribute-based access control, and Azure RBAC.
Explore identity providers as centralized services that verify user identities and deliver single sign-on, housing managed, external, on-premises identities in Microsoft Entra ID for unified access across apps.
Explore directory services as central databases of user and device identities. Compare them with identity providers in the cloud, and understand on-premises Active Directory and the role of LDAP.
Federation enables a secure, trusted cross-domain connection with saml or oauth tokens for single sign-on.
Discover Microsoft Entra, the four-pillar identity and access suite, covering Entra ID, governance, verified ID, external ID, and workload ID, with licensing and key products like Private Access.
Describe Microsoft Entra ID, a cloud-based identity and access management service replacing Azure Active Directory, enabling single sign-on, conditional access, B2B/B2C, MFA, identity protection, and hybrid identity.
Describe Intra ID user identities, including synchronized on-premises Active Directory identities, cloud identities, and guest identities from external providers, and review authentication options like username, password, MFA, and passwordless.
Learn how Azure managed identities authenticate resources without credentials, comparing system assigned and user assigned types, their lifecycles, and when to use each to access key vaults and function apps.
Azure managed identities: creating system and user assigned identities, linking a virtual machine to an SQL server through role assignments, and best practices.
Enable external identities outside your intra ID tenant to collaborate with SharePoint and Teams. Describe B2B collaboration, B2B Direct Connect, B2C, and cross-tenant settings for access and trust.
Describe how to choose the right hybrid authentication method by following a decision flow that weighs cloud and on-premises needs, including password hash sync and pass-through authentication.
Describe Entra ID authentication methods, including password, SMS, voice, OAuth tokens, and Microsoft Authenticator. Note passwordless options like Windows Hello for business, FIDO2 key, or certificate-based authentication, MFA and SPR.
Explore why passwords are inherently insecure, and how phishing, keylogging, brute-force attacks, and rainbow tables threaten accounts, underscoring the need for multi-factor authentication or passwordless options.
Explain how MFA uses at least two properties—something you know, something you have, or something you are—to secure access, favoring passwordless options like Windows Hello, FIDO2, and Microsoft Authenticator.
Describe passwordless authentication using Windows Hello for business, where a device signs a nonce to securely authenticate, enabling single sign-on and reducing password surface area.
Describe Android password protection and enforce real-time validation across cloud and on-premises environments with smart policies that ban weak or compromised passwords via global and custom ban lists.
Enable self-service password reset with the authenticator app to securely reset forgotten or compromised passwords, reduce help desk costs, and write the password back to on-premises Active Directory.
Explore Entry ID roles across the Microsoft ecosystem with examples like Teams administrator and Security administrator. Distinguish these from Azure RBAC to decide when to use which.
Understand Azure RBAC, including security principal, role definition, and scope, and learn to assign built-in or custom roles across resources from management group to resource for least privilege access.
Enforces access control by evaluating user and device signals, such as entry ID, identity protection alerts, defender for identity, and Intune compliance, to grant or block access.
Explain how intra id governance manages identities, permissions, and entitlements across environments, using entitlement management and privileged identity management with just-in-time access and reviews.
Explain how Microsoft Entra privileged identity management provides just-in-time, time-bound access to privileged roles with approval, MFA, justification, and notifications, plus auditing, access reviews, and history.
Describe how Microsoft Entra ID protection monitors and detects user risk and sign-in risk, blocks access, and integrates with conditional access and Microsoft Sentinel using real-time signals.
Explain how Entra permissions management enables cross-cloud permission discovery, remediation, and continuous monitoring, delivering visibility and control across Azure, AWS, and GCP within a zero-trust, least-privilege framework.
Explore how Azure DDoS protection defends apps from volumetric, protocol, and application attacks using network and IP protection, always-on traffic monitoring, adaptive real-time tuning, and rapid response with WAF.
Explore Azure Firewall, a cloud-native Azure service with layer 3 to 7 policies, TLS inspection (premium), threat intelligence, IDS/IPS, and hub and spoke architectures for central traffic inspection.
Deploy Azure firewall in a single region, create a premium firewall with its policy, and attach a new vnet and public IP. Configure rule collections, threat intelligence, and TLS inspection.
Understand Azure WAF for layer seven protection of web apps, blocking XSS, SQL injection, and remote code execution with managed and custom rules; deploy with app gateway.
Explain how network security groups filter inbound and outbound traffic, based on a five-tuple and stateful rules, and how to apply NSGs at subnet or NIC level.
Configure an Azure network security group by provisioning a VM, creating a resource group and VNet, then add inbound rules and associate the NSG with a NIC or subnet.
This course contains the use of artificial intelligence.
This SC-900 course by Christopher Nett is a meticulously organized Udemy course designed for IT professionals aiming to pass the SC-900: Microsoft Security, Compliance and Identity exam. This course systematically guides you from the basics to advanced concepts of Microsoft Security, Compliance and Identity.
By mastering Microsoft Security, Compliance and Identity, you're developing expertise in essential topics in today's cybersecurity landscape.
The course is always aligned with Microsoft's latest study guide and exam objectives:
Skills at a glance
Describe the concepts of security, compliance, and identity (10–15%)
Describe the capabilities of Microsoft Entra (25–30%)
Describe the capabilities of Microsoft security solutions (35–40%)
Describe the capabilities of Microsoft compliance solutions (20–25%)
Describe the concepts of security, compliance, and identity (10–15%)
Describe security and compliance concepts
Describe the shared responsibility model
Describe defense-in-depth
Describe the Zero Trust model
Describe encryption and hashing
Describe Governance, Risk, and Compliance (GRC) concepts
Define identity concepts
Define identity as the primary security perimeter
Define authentication
Define authorization
Describe identity providers
Describe the concept of directory services and Active Directory
Describe the concept of federation
Describe the capabilities of Microsoft Entra (25–30%)
Describe function and identity types of Microsoft Entra ID
Describe Microsoft Entra ID
Describe types of identities
Describe hybrid identity
Describe authentication capabilities of Microsoft Entra ID
Describe the authentication methods
Describe multi-factor authentication (MFA)
Describe password protection and management capabilities
Describe access management capabilities of Microsoft Entra ID
Describe Conditional Access
Describe Microsoft Entra roles and role-based access control (RBAC)
Describe identity protection and governance capabilities of Microsoft Entra
Describe Microsoft Entra ID Governance
Describe access reviews
Describe the capabilities of Microsoft Entra Privileged Identity Management
Describe Microsoft Entra ID Protection
Describe Microsoft Entra Permissions Management
Describe the capabilities of Microsoft security solutions (35–40%)
Describe core infrastructure security services in Azure
Describe Azure distributed denial-of-service (DDoS) Protection
Describe Azure Firewall
Describe Web Application Firewall (WAF)
Describe network segmentation with Azure virtual networks
Describe network security groups (NSGs)
Describe Azure Bastion
Describe Azure Key Vault
Describe security management capabilities of Azure
Describe Microsoft Defender for Cloud
Describe Cloud Security Posture Management (CSPM)
Describe how security policies and initiatives improve the cloud security posture
Describe enhanced security features provided by cloud workload protection
Describe capabilities of Microsoft Sentinel
Define the concepts of security information and event management (SIEM) and security orchestration automated response (SOAR)
Describe threat detection and mitigation capabilities in Microsoft Sentinel
Describe threat protection with Microsoft Defender XDR
Describe Microsoft Defender XDR services
Describe Microsoft Defender for Office 365
Describe Microsoft Defender for Endpoint
Describe Microsoft Defender for Cloud Apps
Describe Microsoft Defender for Identity
Describe Microsoft Defender Vulnerability Management
Describe Microsoft Defender Threat Intelligence (Defender TI)
Describe the Microsoft Defender portal
Describe the capabilities of Microsoft compliance solutions (20–25%)
Describe Microsoft Service Trust Portal and privacy principles
Describe the Service Trust Portal offerings
Describe the privacy principles of Microsoft
Describe Microsoft Priva
Describe compliance management capabilities of Microsoft Purview
Describe the Microsoft Purview compliance portal
Describe Compliance Manager
Describe the uses and benefits of compliance score
Describe information protection, data lifecycle management, and data governance capabilities of Microsoft Purview
Describe the data classification capabilities
Describe the benefits of Content explorer and Activity explorer
Describe sensitivity labels and sensitivity label policies
Describe data loss prevention (DLP)
Describe records management
Describe retention policies, retention labels, and retention label policies
Describe unified data governance solutions in Microsoft Purview
Describe insider risk, eDiscovery, and audit capabilities in Microsoft Purview
Describe insider risk management
Describe eDiscovery solutions in Microsoft Purview
Describe audit solutions in Microsoft Purview
This course contains promotional materials.