
Engage in hands-on, real-world learning for the SC-900 exam with browser-based simulations, Azure policies, and practical Microsoft 365 setup alongside lifetime updates.
Build a foundation in on-premises Active Directory, domain services, DMZ, and virtualization, then explore the Microsoft 365 and Azure cloud and its IaaS, PaaS, and SaaS models.
Explore the foundations of Microsoft domains, Active Directory, domain controllers, DNS, and replication, and understand Kerberos, NTLM, LDAP, and the move toward cloud services.
Explore foundational concepts like active directory domain services, LDAP, and Kerberos, and how VPN, DMZ, and virtualization enable secure remote access and scalable on premise services.
Explore cloud service evolution from IaaS to PaaS and SaaS, with Azure and Microsoft 365. Understand intro ID (Azure AD) and the role of Azure AD Connect for seamless sign-on across on-prem and cloud.
Discover how Microsoft renames frequent services, such as Azure Active Directory to IntraID, and how portals move from portal.Microsoft.com to admin.Microsoft.com, defender.Microsoft.com, purview.Microsoft.com, and Intune.Microsoft.com via portals.examlabpractice.com.
John Christopher explains how to get fast, official answers by consulting Docs.microsoft.com and Microsoft 365 resources, and directs you to exam lab practice, assignment videos, and course updates.
You earn a certificate of completion by watching all course videos; assignments do not matter, and a final video explains how to obtain your certificate.
Learn to use course assignments and simulations, open links in a new tab, submit progress, and know that certificates depend on watched videos, not the checkbox.
Set up a lab environment with Microsoft 365 and Azure using a free Office 365 E5 trial. Note location restrictions and possible 30-day E5 or Teams trials via portal.microsoft.com.
Learn to set up a free Microsoft 365/Azure trial account with a new email, verify by phone, and cancel after 30 days, including portal changes and license options.
Get $200 Azure credit for a 30-day trial by starting the Azure Free trial at portal.azure.com, requiring a credit card and allowing a switch to pay-as-you-go after 30 days.
Explore how the shared responsibility model divides duties between you and the provider across on-premises, IaaS, PaaS, and SaaS, from data center security to identity management.
Explain defense in depth for Azure, layering updates, Azure Firewall, network security groups, access control lists, and rbac across virtual machines, web apps, and virtual networks.
Learn how the zero-trust model verifies every authentication, enforces least privilege, and uses just-in-time and just-enough access with Azure, PIM, and conditional access policies.
Observe how Azure and Microsoft 365 enforce https tls encryption for all interactions and protect passwords with sha 256 hashing and salting, key vaults, hsm appliances, and two-person committee access.
Explore how different industries confront regulatory compliance and discover the Microsoft Purview Compliance Portal as the centralized site for reporting, auditing, forensics, e-discovery, retention, and sensitivity information.
Identify Azure Active Directory identities as the primary security perimeter for both Azure and Microsoft 365, and leverage monitoring, auditing, and threat management across linked services.
Learn how Azure AD enables single sign-on across on-premises and cloud services, integrate with Azure AD connect, and strengthen security with MFA, passwordless options, and Microsoft Authenticator.
Explain authorization in Azure and Microsoft 365, including license based access, role assignments, and resource permissions that control who can use services.
Explain how Active Directory organizes users, groups, and devices using LDAP and X.500, with domain controllers, Kerberos, and DNS-based location.
Learn how to integrate your Azure Active Directory with external identity providers such as Google or Facebook using federation concepts, including SAML and WS-Fed, and manage providers from external identities.
Navigate and administer Microsoft Entra ID across the Azure portal and the intra ID portal, managing users, groups, devices, and roles, identity governance, and identity protection.
Understand identities in Microsoft Entra ID, including user, guest, service principal, managed identity, and device identities, and how they are created (directly or via on premise Active Directory) and secured.
Learn to create and manage user identities in Microsoft Entra ID across Azure portal and admin centers, including user principal names, display names, licenses, and group or role assignments.
Discover how to invite external users as guests in Entra ID through the Azure portal, specify personal emails, send invites, and grant access to Azure resources.
Describe hybrid identity by comparing intra connect sync and intra cloud sync for linking on-premises Active Directory with Azure AD and Microsoft 365, covering authentication options and writeback.
Learn to redo simulations in the course by going to summary, returning to the assignment, opening instructions, and clicking the simulation link to access the simulations again.
Explore Microsoft Entra authentication methods, including passwords, passwordless options, MFA, phishing-resistant methods like Fido2 and Tap temporary access pass, and token-based access with OAuth 2.0, OpenID Connect, and SAML.
Master multifactor authentication (MFA) by using two or more factors from knowledge, possession, and something you are to prevent unauthorized access and mitigate phishing and other identity threats.
Enable multi-factor authentication across Azure and Microsoft 365 using security defaults or conditional access policies, and configure authentication methods to deploy MFA for all users or specific groups.
Describe conditional access in Azure, outlining signals from identities, devices, apps, and data, and how zero-trust enforcement uses MFA and device and app policies to block or grant access.
Create conditional access policies in portal.azure.com, linking Intro ID (formerly Azure AD) and Intune, with protections across apps and users. Configure conditions, risks, grant or block, MFA, and device compliance.
Explore how Azure RBAC roles and Intra ID permissions control access to resources, using least privilege across management groups, subscriptions, resource groups, and resources.
Explore how to implement role-based access control in Azure using Microsoft Entra, define roles with permissions, and assign them to users or services with activation and approvals.
Explore how to view, search, and assign Microsoft 365 roles in the admin center, tied to Microsoft Entra ID, with role permissions and user assignments across Defender, Purview, and Exchange.
Describe how to set up and use access reviews in identity governance to periodically revoke unnecessary access for guests and teams, with review workflows, recurrence, and audit logs.
Explore how Entra ID privileged identity management enables just-in-time access and role-based access control, enforcing zero-trust, least privilege, and privilege bracketing across Azure, Microsoft 365, and Intune.
Implement Microsoft Entra privileged identity management (PIM) to grant temporary access by creating assignments, activating eligible roles, and verifying with multi-factor authentication.
Configure intra-identity protection with risk-based conditional access policies in Intra and Azure portals, enforcing multi-factor authentication for medium and high risk sign-ins.
Visualize how Azure virtual networks segment address spaces into subnets, assign DHCP via VNet, and connect through peering, NSG filtering, and optional on-premises links via VPN gateway or ExpressRoute.
Learn how to enable Azure DDoS protection, add protected resources like VNets and firewalls in the portal, and review monthly per-resource costs with the pricing calculator.
Describe Azure firewall options and policy concepts, including standard, premium, and basic SKUs, threat intelligence with IDS/IPS, firewall policy with rule collections for inbound and outbound traffic.
Discover how Azure web application firewall protects web services with front door, using global and regional policies, custom rules, and rate limiting to block sql injection and cross-site scripting.
Learn to create and configure Azure virtual networks and subnets, assign address spaces such as 10.1.0.0/16 and 10.1.1.0/24, and explore NAT gateway, Azure Bastion, firewall, DDoS protection, and service endpoints.
Explain how Azure NSG and ASG control inbound and outbound traffic by applying rules at subnets or network interfaces, using priority and implicit deny.
Learn how to create an Azure virtual machine, selecting a Windows Server 2022 image, resource group, size, storage, and networking. Connect via Remote Desktop and manage security settings.
Explore why Azure Bastion secures remote VM access by routing through port 443, avoiding exposure of RDP on 3389, with browser-based SSH/RDP via Azure Bastion.
Explore how to create an Azure key vault to centralize and securely store secrets, keys, certificates, with monitoring, access control, and integration with Azure disk encryption, tde, and app services.
Explore Microsoft Defender for Cloud as a single pane of glass for Azure security, showing security posture, security score, alerts, and actionable CSPM recommendations.
Discover how Defender for Cloud analyzes your environment for vulnerabilities using active recommendations, severity rankings, and remediation steps, including policy definitions and optional vulnerability assessments for servers, databases, and storage.
Learn how Azure security baselines support regulatory compliance by aligning with NIST and CIS open standards, using Defender for Cloud to assess, remediate, and export reports.
We really hope you'll agree, this training is way more then the average course on Udemy!
Have access to the following:
Training from an instructor of over 20 years who has trained thousands of people and also a Microsoft Certified Trainer
Lecture that explains the concepts in an easy to learn method for someone that is just starting out with this material
Instructor led hands on and simulations to practice that can be followed even if you have little to no experience
TOPICS COVERED INCLUDING HANDS ON LECTURE AND PRACTICE TUTORIALS:
Introduction
Welcome to the course
Understanding the Microsoft Environment
Having a Solid Foundation of Active Directory Domains
Having a Solid Foundation of RAS, DMZ, and Virtualization
Having a Solid Foundation of the Microsoft Cloud Services
Questions for John Christopher
Performing hands on activities
IMPORTANT Using Assignments in the course
Creating a free Microsoft 365 Azure AD Account
Getting your free Azure credit
Describe security and compliance concepts
Describe the shared responsibility model
Describe defense in depth
Describe the Zero-Trust model
Describe encryption and hashing
Describe compliance concepts
Define identity concepts
Define identity as the primary security perimeter
Define authentication
Define authorization
Describe the concept of directory services and Active Directory
Describe the concept of federation
Describe function and identity types of Microsoft Entra ID
Describe Azure AD
Describe Azure AD identities including external identities
Describe hybrid identity
Describe the authentication capabilities of Azure AD
Describe the authentication methods available in Azure AD
Describe Multi-factor Authentication
Describe self-service password reset
Describe password protection and management capabilities available in Azure AD
Describe access management capabilities of Azure AD
Describe conditional access
Creating conditional access polies
Describe the benefits of Azure AD roles
Describe the benefits of Azure AD role-based access control
Describe the identity protection and governance capabilities of Azure AD
Describe identity governance in Azure AD
Describe entitlement management
Describe access reviews
Describe the capabilities of Azure AD Privileged Identity Management (PIM)
Implementing Azure AD Privileged Identity Management (PIM)
Describe Azure AD Identity Protection
Describe basic security capabilities in Azure
Visualizing general Azure networking
Describe Azure DDoS protection
Describe Azure Firewall
Describe Network Segmentation with VNet
Describe Azure Network Security groups
Create a virtual machine in Azure
Describe Azure Bastion and JIT Access
Describe ways Azure encrypts data
Describe security management capabilities of Azure
Describe Microsoft Defender for Cloud & Cloud security posture management (CSPM)
Describe the enhanced security features of Microsoft Defender for Cloud
Describe security baselines for Azure
Describe security capabilities of Microsoft Sentinel
Define the concepts of security information and event management (SIEM) and SOAR
Describe threat detection and mitigation capabilities in Microsoft Sentinel
Describe threat protection with Microsoft 365 Defender
Describe Microsoft 365 Defender services
Describe Microsoft Defender for Office 365
Describe Microsoft Defender for Endpoint
Describe Microsoft Defender for Cloud Apps
Using Microsoft Defender for Cloud Apps for policy creation
Describe Microsoft Defender for Identity
Basics of setting up Microsoft Defender for Identity
Describe the Microsoft 365 Defender portal
Describe Microsoft’s Service Trust Portal and privacy principles
Describe the offerings of the Service Trust portal
Describe Microsoft’s privacy principles
Describe the compliance management capabilities of Microsoft Purview
Describe the Microsoft Purview compliance portal
Describe compliance manager
Describe the use and benefits of compliance score
Describe information protection & data lifecycle management of Microsoft Purview
Describe data classification capabilities
Describe the benefits of content explorer and activity explorer
Describe sensitivity labels
Basics of using sensitivity labels
Describe Data Loss Prevention (DLP)
Basics of using Data Loss Prevention (DLP)
Describe Records Management
Describe Retention Polices and Retention Labels
Describe insider risk capabilities in Microsoft Purview
Describe Insider Risk Management
Describe communication compliance
Describe information barriers
Describe resource governance capabilities in Azure
Describe Azure Policy
Describe Azure Blueprints
Describe the capabilities of the Microsoft Purview governance portal
Finishing Up
Where do I go from here?