
Explore security, compliance, and identity across Microsoft 365 and Azure, covering zero trust, encryption, privacy assurances, and the service trust portal, with Azure AD-based identity management and MFA.
Adjust the Udemy player to 720p to eliminate blurred videos; click the gear icon in the bottom right and apply 720p for clear playback across all Udemy courses.
Adjust playback speed to suit your learning cadence, with a personal recommendation of 1.25x over the default 1x, and experiment to find what works best.
Identify how the SC-900 exam's skills are measured, with emphasis on identity and access management solutions (30–35%), security solutions (35–40%), and compliance solutions (25–30%), and how this course stays current.
Explore the Azure security documentation introduction, covering end-to-end security, shared responsibility, threat detection and mitigation, securing workloads, encryption, identity management, and network best practices.
Create a free Microsoft 365 trial, selecting the E5 option to explore features. Sign in to Office.com to access SharePoint, OneNote, and other Office apps from the admin center.
Explore the core concepts of security, compliance, and identity management, with a focus on Azure security concepts, methodologies, and compliance principles across industries such as healthcare, finance, and government.
Describe zero trust and shared responsibility models, and outline defense-in-depth, encryption, hashing, and digital signing for IT professionals across Azure, Microsoft 365, and cloud environments.
Explore zero trust: verify explicitly before access, enforce least privilege, and assume breach, while segmenting networks and protecting data across on-premise and cloud environments.
Map the shared responsibility model across IaaS, PaaS, and SaaS to show what Microsoft and customers manage for data, identities, devices, networks, and operating systems.
Apply the in-depth defense model from data protection to physical security. Secure data, apps, and identities with encryption, least privilege, Azure Key Vault, MFA, and SSO.
Explore the CIA triad—confidentiality, integrity, and availability—and how encryption and hashing protect data, while strategic access planning and role-based permissions ensure secure, available information.
Explore the threat landscape, including dictionary attacks, ransomware, data breaches, phishing, denial of service, Trojans, root kits, and coin miners, and learn how Microsoft 365 and Azure alert against them.
Understand how password lists fuel brute-force and dictionary attacks, including common password repositories. Learn why downloading such lists is risky and how credential reuse can compromise accounts.
Explain how encryption turns readable data into unreadable form, protecting data at rest with bitlocker and data in transit with IPsec and SSL, and compare symmetric and asymmetric encryption.
Describe security and compliance principles, and Microsoft's privacy principles. Navigate the Service Trust portal and understand the types of data contained on the Trust portal, and locate Azure compliance documentation.
Explore how Microsoft privacy assurances protect your data with user control, transparency, and legal protections; learn about data residency, encryption, and independent audit reports for compliance.
Access the Service Trust portal to view Compliance Manager documents, audit reports, and region- and industry-specific standards for Microsoft security, privacy, and compliance across Azure and Microsoft 365.
Explore the capabilities of identity and access management by describing identity principles, examining identity and authentication types, configuring access management, and examining Azure Active Directory's governance features.
Describe identity principles and treat identities as security perimeters during login risk assessments, including credential leaks and login location. Differentiate authentication from authorization and outline identity related services.
Explore common identity attacks, including leaked credentials, brute-force and dictionary methods, credential stuffing, and phishing variants such as spear phishing, smishing, and whaling, with defenses like LCS and MFA.
Demonstrates launching a credential harvest phishing simulation in Microsoft 365 Defender, guiding you through selecting targets, deploying training, and analyzing user responses to improve security awareness.
Identity is the primary security perimeter in the cloud, enabling access from anywhere. Configure administration, authentication with credentials and MFA, authorization, and audit for compliance across user and device activity.
Explore the shift from basic to modern authentication, where apps use tokens with defined permissions and optional multifactor authentication, including conditional multifactor authentication based on the login context.
Enable modern authentication for Outlook 2013 and later, view sign-in reports in the Azure portal to verify usage, then selectively disable basic authentication protocols.
Explore Azure Active Directory sign-in logs to track application access, including timestamp, application, resource, browser, IP address, and location, noting that authentication used was single-factor with no conditional access.
View sign-in logs in the Azure Active Directory portal to see recent sign-ins, including date, user, latency, location, device, authentication details, and related alerts.
Explore identity types in Azure AD and gain detailed descriptions of Azure Active Directory. Walk through configurations of the identities within Azure AD.
Understand Azure Active Directory, a cloud-based identity and access management service that provides a single identity across Azure, on-premise apps, tenants, and popular services, with built-in security and governance protections.
Explore Azure AD basics by creating users and security groups with dynamic or assigned membership, managing applications and licenses, and navigating the Microsoft 365 admin center and Azure portal.
Compare the four Azure AD editions: free, Office 365 included, and premium P1 and P2, highlighting what each includes, such as multi-factor authentication, application access, and conditional access.
Identify Azure identity types—user identity, service principal, device identity, and managed identities (system assign and user assign)—and how apps use them with Azure Key Vault.
Explore external identities in Azure AD, including B2B collaboration and B2C, and learn how a single cloud-based directory manages employees, customers, and partners with social identity providers and single sign-on.
Explore how hybrid identities fuse on-prem Active Directory with Azure AD, enabling synchronized user accounts and cloud resources via password hash, pass-through authentication, or Adfs federation.
Demonstrates configuring Azure AD cloud sync from on-premises Active Directory to Azure AD, installing the provisioning agent, signing in with admin credentials, and enabling user synchronization.
Explore Azure AD authentication types and the technologies behind them, and examine password management features and the multiple options available.
Explore multi-factor and passwordless authentication, from authenticator apps like Microsoft Authenticator and Windows Hello biometrics to FIDO2 standards and hardware tokens, and understand how modern authentication improves security.
Manage multi-factor authentication in Azure Active Directory, enabling per-user MFA, configuring contact methods, and restoring MFA on remembered devices, plus security defaults and trusted IPs for intranet bypass.
Enable self-service password reset in Azure AD to reduce help desk calls by letting users reset or unlock their passwords, with authentication via authenticator app, in-app code, or email.
Enable self-service password reset for all users in Azure Active Directory, require registration every 180 days, and set authentication methods like email and security questions to securely reset passwords.
Configure smart lockout in azure ad with a ten-password threshold and duration; mirror these settings in the on prem lockout policy, and ban common passwords such as password and 1,2,3.
Explore Azure AD roles assignments, identity protection, and conditional access within Azure and access management, with practical demonstrations.
Explore how Azure AD roles delegate permissions with built-in and custom roles under RBAC, applying least privilege and inheritance from management groups to subscriptions, resource groups, and resources.
Azure identity protection automates detection and remediation of identity based risks, analyzes sign in risk and user identity from portal data, and exports findings categorized as low, medium, or high.
Learn to configure Azure Active Directory identity protection, create user and sign-in risk policies with risk levels, apply risk-based controls, and view risky users and sign-ins.
Explore conditional access that uses real-time risk signals—user, location, app, device, and ip subnet—to decide access, grant MFA, block sign-ins, or apply session controls across cloud apps and on-prem environments.
Learn to configure Azure Active Directory conditional access by linking policies to a specific app like Microsoft Teams, using trusted locations and IP ranges to enforce multifactor or device-compliant access.
Discover how privileged identity management (PIM) enables just-in-time, time-bound privileged access in Azure AD, with MFA, activation windows from 30 minutes to 24 hours, approvals, notifications, and full audit trails.
Explore Azure AD privileged identity management by granting on-demand access to the user administrator role through eligibility, activation, and MFA, with approval and justification.
Learn how access reviews prevent privilege creep and insider threats by automatically verifying and removing unused Azure AD access to applications like Salesforce, using follow-ups and resource owner reviews.
Configure an access review in the 365 admin center to manage all-user access to an application via identity governance, set reviewers, duration, quarterly scheduling, and nonresponse removal.
Explore Microsoft security solutions across 365 and Azure, including Azure Sentinel, 365 Defender, and Intune, and learn about BYOD endpoints and compliance before connecting to resources.
Describe basic Azure security principles and capabilities for virtual networks, virtual machines, and data encryption; explore protecting Azure file shares and different storage types with configuration options.
Configure Azure NSGs to control inbound and outbound traffic for virtual networks, attaching them to subnets or NICs with rules by source, destination, direction, action, priority, protocol, and ports.
Discover how a network security group attaches to a VM's network interface, how inbound rules like port 80 are added, and how NSGs also apply to subnets.
Explore Azure DDoS protection, comparing basic and standard plans with adaptive tuning, network and application layer protection, logging, and rapid response features.
Demonstrates configuring Azure DDoS protection, showing default basic protection integrated at no extra cost, and how to create a DDoS plan to enable standard protection across virtual networks.
Protect virtual networks with the Azure Firewall, a stateful, scalable cloud security service that uses a static public IP. Enforce and log application and network policies across subscriptions.
Use Azure Bastion to securely access virtual machines via ssl on port 443, keeping rdp traffic on port 3389 inside the vnet, with the bastion subnet named accordingly.
Learn to deploy a virtual network and VM in Azure, then configure Azure Bastion with a subnet named Azure Bastion subnet to securely access the VM via the portal.
Explore Azure Front Door as a global, scalable entry point that routes users to regional app instances, delivering high availability, fast performance, built-in DDoS protection, and Microsoft-managed security.
Learn how Azure front door pairs with the web application firewall to centrally protect multiple web apps, with manually configured rules to block SQL injection and cross-site scripting.
Demonstrates configuring an Azure front door with two web app backends across Central US and Canada Central, including frontend, backend pools, and routing rules for high-availability traffic routing.
Learn to deploy a front door integrated web application firewall, configure a new WAF policy in prevention mode for a global front door, and manage rules including geo-location based blocks.
Securely store and access secrets, API keys, passwords, certificates, and cryptographic keys in Azure Key Vault, a centralized cloud service that applications use to manage sensitive credentials.
Describe the security management capabilities of Azure, including the benefits and use case scenarios of Azure Defender, and outline cloud security posture management and the security baseline.
Explore how the Azure Security Center provides continuous assessment, actionable recommendations, MFA for owner accounts, threat protection, a network map, and optional Azure Defender for unified security across workloads.
Navigate the azure portal to Microsoft Defender for Cloud, review security alerts and recommendations, and enable Azure Defender for servers to protect virtual machines and manage firewall policies.
Describe azure sentinel's security capabilities as a siem that ingests and correlates logs from diverse vendors to detect threats across azure and on-premises. Explore saw and XDR concepts.
Explore how SIEM collects and correlates data across your estate to detect threats, while SOAR automates responses and XDR offers integrated security with Azure Sentinel.
Azure Sentinel delivers cloud-scale data collection across users, devices, apps, and on premise environment or clouds, including AWS and Google Cloud Platform, enabling detection and AI-driven investigations with automated responses.
Describe the threat protection in Microsoft 365 Defender and explore the integrated protection you can configure using Microsoft 365 and Microsoft Cloud App Security (casp).
Explore Microsoft 365 Defender, a unified protection suite coordinating identity, endpoints, email, and collaboration with Defender for Identity, Defender for Endpoint, Defender for Office 365, and cloud app security.
Map your cloud environment with cloud app security's cloud discovery, identifying all apps in use, and enforce sanctioned or unsanctioned app policies with conditional access and multifactor authentication.
Discover how Microsoft Cloud App Security (MCAS) uses a cloud discovery dashboard, discovered apps, IP addresses, and policies to monitor and secure cloud usage.
Describe the Microsoft 365 security center, use the secure score, and work with generated security reports to manage Microsoft 365 security.
Explore the Microsoft 365 Security Center as the hub for monitoring and securing identities, data, devices, and apps, with secure score, alerts, incidents, advanced hunting, and sensitivity labels.
Explore the Microsoft 365 Defender security center, review alerts, incidents, and hunting, and learn how secure score, threat analytics, and identity protection guide MFA, risk policies, and conditional access.
Learn endpoint security with Microsoft Intune, including the purpose of Intune and how to configure and manage devices, plus an overview of the Intune tool and its admin features.
Microsoft Intune combines device management (MDM) and mobile application management (MAM) to enroll devices, enforce compliance, deploy certificates and VPN, manage apps, and securely wipe corporate data if needed.
Explore the Intune overview in Endpoint Manager, learning how to manage devices and applications via Azure Active Directory, enroll Windows devices, and apply configuration policies and Wi-Fi profiles.
Explore Microsoft compliant solutions and learn compliance management, information protection for word documents, spreadsheets, and emails in Microsoft 365, insider risk, and e-discovery with auditing and resource governance.
Navigate the compliance center to understand compliance management capabilities and learn its uses and benefits.
This lecture explains how GDPR governs data collection and retention, and user rights to access, edit, or delete information. It highlights risks of insurance or ad targeting from search histories.
Explore the compliance center to monitor real-time compliance, view alerts, and use the compliance manager with pre-built assessments, risk workflows, improvement actions, live compliance score, and multifactor authentication guidance.
Explore the Microsoft 365 compliance center and Compliance Manager to view improvement actions, enable self-service password reset, and review GDPR and FedRAMP templates, DLP, and e-discovery features.
Explore how information protection works in Microsoft 365, describe data classification, and explain data loss prevention (DLP) practices.
Identify important data across on-premises and cloud environments, protect it with encryption at rest and in transit, and govern through automated classification to prevent oversharing and meet compliance.
Explore sensitivity labels that persist across data, auto-apply on content such as PII or financial data, enable encryption and watermarks, and enforce policies across emails, documents, sites, and third-party apps.
Identify, monitor, and automatically protect sensitive data across Microsoft 365 apps, devices, and non-Microsoft resources with data loss prevention (DLP) policies. Learn how policy tips, blocks, and overrides guard emails, chats, and documents while smart pattern recognition reduces false positives for SSNs and credit card numbers.
Learn to configure data loss prevention in the 365 admin center by creating a custom UK financial data policy, selecting locations, fine-tuning advanced DLP rules, and testing before activation.
Learn how retention policies and labels automatically retain or delete content across Exchange, SharePoint, OneDrive, and Teams, with container-level inheritance and disposition reviews.
Explore how Microsoft 365 records management helps meet legal obligations and demonstrate compliance by labeling content as records, which restricts actions, logs activities, and preserves disposition during the retention period.
Identify insider risks and take proactive actions to protect your organization. Learn how Microsoft 365 helps identify, investigate, and remediate insider-related malicious or accidental activities.
Identify insider risks that threaten data, IP, and confidentiality through cloud storage and removable devices. Learn to detect, investigate, and act on incidents with Microsoft 365 risk management and eDiscovery.
Explore how to configure communication compliance policies in Microsoft 365 for Teams, Exchange Online, Yammer, and third-party tools, then investigate, remediate, and continuously monitor detected issues as a unified workflow.
Learn how information barriers enforce two-way communication restrictions between groups in Microsoft 365 apps, preventing cross-group messaging, file sharing, and access in Microsoft Teams, OneDrive, SharePoint, and Exchange.
Leverage privileged access management to protect your organization with just-in-time elevation for privileged tasks, such as user creation, across Microsoft 365 and Azure resources.
Explore privileged access in the 365 admin center by creating policies, managing requests, and using a manual approval flow with the IT security admins group.
Explore how customer lockbox lets Microsoft access your tenant only with explicit admin approval, ensuring control over Exchange Online, OneDrive for Business, and SharePoint Online.
Explore the customer lockbox workflow in the admin center to submit and track service requests, view status, and approve Microsoft access for support.
Describe the purpose of e-discovery and outline the capabilities of the content search tool within 365.
Master e-discovery in Microsoft 365 to locate electronic information for litigation, retain emails, and export results across Exchange Online, Microsoft Teams, SharePoint Online, OneDrive for Business, Skype, and Yammer.
Demonstrates eDiscovery in the 365 admin center and compliance center, from creating cases and configuring settings to adding members, with an overview of search analytics, custodians, and collections.
Describe the core audit capabilities and the advanced auditing capabilities covered in this lesson, helping you understand and articulate auditing features.
Audit capabilities capture detailed user and administrator activity in audit logs, with configurable date ranges and scope across users, files, and sites, showing timestamps and exact actions, exportable to csv.
Enable the audit log in the 365 admin center's compliance center, start recording user and admin activity, and define the time range and audit types.
Describe resource governance in Azure by outlining resource locks, Azure blueprints, and Azure policy within the cloud adoption framework.
Apply resource locks in Azure at the resource or group level to prevent accidental modification or deletion. Locks are delete or read-only, inheriting to contained virtual machines without impeding operation.
The lecture demonstrates applying Azure resource locks to a VM, including delete and read-only locks that prevent deletion or modification.
Azure blueprints simplify the architecture process by defining repeatable resources to deploy, uniting resource groups, policies, and role assignments under one umbrella for a big-picture view.
Learn how Azure policy enforces organizational standards, audits compliance via a compliance dashboard, and enforces location constraints, threat detection, and encryption across resources, with bulk remediation and reporting.
Explore how the cloud adoption framework provides guidance, best practices, and documentation to define strategy, develop deployment plans, assess readiness, migrate, govern, and continuously optimize Azure and Microsoft 365 deployments.
Explore the cloud adoption framework website to access tools, templates, strategies, and planning guides that help you start, migrate, govern, and architect solutions on Azure and Microsoft 365.
Welcome to course SC-900! This course provides foundational level knowledge on security, compliance, and identity protection concepts on Microsoft Azure and Microsoft 365 solutions required to obtain the SC-900 certification. Most courses focus on Azure or Microsoft 365, but not both. The SC-900 course covers technology within both products. Those that new to Azure and/or Microsoft 365 benefit from learning the security and compliance capabilities that available to protect data and resources. The SC-900 course also contains a practice test which can be used to asses your readiness for the certification exam, and to validate your knowledge.
After completing this course learners will understand Azure security concepts related to networking, firewalls, application security, protection of user and device identities
Course topics include:
Describe Azure security concepts and methodologies
Zero Trust Methodology
Division of Responsibilities
Defensive Approach
Understanding the Threat Landscape
Understanding Encryption
Understanding Azure Compliance
Describe Identity Principles
Understand the most common types of identity attacks
Understanding Azure AD
Understanding Identity Types
Synchronizing an on-premise network to Azure AD
Understanding Self-Service Password Reset (SSPR)
Configuration Multi-Factor Authentication (MFA)
Azure AD Roles and Azure Resource Roles
Conditional Access
Privileged Identity Management (PIM)
Access Review
Describe basic Azure security principles
Network Security Groups
DDoS Protection in Azure
Describe Azure Bastion
Describe Azure Firewall
Describe Azure Front Door
Describe Azure Web Application Firewall
Describe Azure Key Vault basic concepts
Exploring the Azure Security Center
Understanding Azure Sentinel
Microsoft 365 Defender Services
Microsoft Cloud App Security
Microsoft 365 Security Center
Endpoint security with Microsoft Intune
Exploring the Compliance Center
Understanding Sensitivity Labels
Understanding Data Loss Prevention
Retention Policies and Labels
Understanding Insider Risks
Describe eDiscovery
And more.