
Learn to secure AI workloads in Microsoft cloud by using Purview for data protection, Defender for Cloud Apps, Defender for Endpoint, Intune, Azure AD, and Sentinel.
Gain a bird's-eye view of security and AI within the Microsoft Cybersecurity Reference Architecture. Discover how Defender, Sentinel, Purview, and Intune enable zero trust and rapid, guided responses.
Master zero trust essentials by applying assume breach, explicit verification, and least privilege (including just-in-time and just-enough access) to identities, endpoints, apps, data, and networks across multi-cloud environments.
Explore how microsoft sentinel unifies multi-cloud visibility with SIEM and SOAR, ingesting data via connectors, running analytic and hunting queries, and automating incident response with playbooks.
Explore Microsoft Defender XDR, a unified security suite that coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications within a zero-trust framework.
Compare Microsoft Sentinel and Defender XDR, outlining siem and soar roles, data connectors, logs, and automated remediation through playbooks.
Microsoft Copilot for M365 enhances security with zero trust, leveraging graph grounding and web grounding, and implementing seven protection layers plus Purview, Defender for cloud apps, and policy controls.
Explore zero trust and seven layers of protection for Microsoft Copilot for 365, focusing on data security across devices and users with Purview demos.
Ensure you have an Office 365 E5 license plus a Copilot for 365 license to run demos integrating Purview with Copilot. An E3 license will not suffice for labeling features.
Explore information protection with Microsoft Purview to apply sensitivity labels, restrict access between finance and HR documents, and enable Copilot to enforce labels and communicate document sensitivity.
Explore information protection in Microsoft Purview: build sensitive info types and sensitivity labels, publish labeling policies, and apply automatic labeling and watermarks in SharePoint and Copilot workflows.
Explore AI-powered auto labeling policies in Microsoft Purview. Automatically apply sensitivity labels to files and emails using trainable classifiers and sensitive info types, with client-side and server-side labeling.
This hands-on lab shows creating an auto labeling policy in Purview, publishing a sensitivity label, and applying labels across Exchange, SharePoint, and OneDrive using sensitive info types and trainable classifiers.
Explore data encryption theory in Microsoft Purview with Copilot, applying sensitivity labels to protect data in OneDrive and SharePoint Online, and enforce restricted access, expiry, and offline restrictions.
Demonstrate data encryption with a protected sensitivity label in Microsoft Purview, showing how to enable control access, configure access settings, set permissions, and protect documents and emails.
Apply data loss prevention policies with Microsoft Purview to prevent sharing of sensitive data like credit card numbers outside the tenant, using custom templates, simulation, and publishing.
This hands-on lab demonstrates creating and enforcing data loss prevention policies in the new Microsoft Purview portal, including custom rules, sensitive data detection, and outside-organization sharing controls.
Explore how alerts and incidents from Microsoft Purview automatically appear in the Microsoft Defender portal, with detailed incident graphs, impacted assets, and assignment options for threat hunting and eDiscovery.
Explore endpoint data loss prevention with Microsoft Purview, onboarding Windows and Mac devices, applying just-in-time protections, and alerting on policy violations in a generative AI era.
Explore a hands-on lab that demonstrates configuring endpoint data loss prevention policies, onboarding devices to Defender for Endpoint, testing GST number detection, and monitoring alerts in Purview and Defender.
Discover how Microsoft Purview communication compliance enforces policy across Copilot, Outlook, Teams, and Exchange Online, detects sensitive info and harassment, and uses templates and remediation workflows to prevent insider risk.
Explore how to create and customize communication compliance policies in the Purview portal, detect sensitive data (GST numbers), set locations and directions, and manage violations end-to-end.
Explore insider risk management with Microsoft Purview, learning to trigger, triage, and escalate data exfiltration and obfuscation threats, use adaptive protection, and involve e-discovery and HR data connectors.
Explore insider risk management in the Microsoft Purview portal, configure alerts and IAM policies, assign users to risk roles, and implement data leak detection via communication compliance and DLP policies.
Explore eDiscovery in Microsoft Purview to investigate DLP and communication policy violations, apply legal holds on custodians, and collect, filter, and export evidences across OneDrive, SharePoint Online, and Exchange Online.
In this eDiscovery hands-on lab, learn how to configure eDiscovery roles, create cases, assign custodians, collect data, build keyword filters, and export a targeted review set as a zip file.
Explore data lifecycle management with retention and deletion policies in Microsoft Purview, covering container vs document level policies, auto deletion, preservation holds, and compliance with SOX.
Explore data lifecycle management in Microsoft Purview, configuring container-level retention policies for SharePoint and OneDrive, along with document-level labeling policies to apply retention and deletion rules.
Explore AI hub in Microsoft Purview to monitor generative AI activity, analyze AI data analytics and sensitive interactions, and auto-create insider risk and data loss prevention policies with a click.
Explore how Microsoft Defender for Cloud secures multi-cloud and hybrid workloads with DevSecOps integration, CSPM, and CWPP, while mapping threats to the Mitre attack framework.
Explore how data connectors in Azure Sentinel centralize security data from cloud services, on-premise devices, and third-party tools, using built-in and custom connectors to feed a Log Analytics workspace.
Explore how the log analytics workspace powers Microsoft Sentinel by unifying data from Azure and non-Azure sources into tables like Azure Activity and Security Alert, queryable with Kusto Query Language.
Set up a Log Analytics workspace in portal.azure.com, attach Azure Sentinel with data connectors, and explore tables such as Azure Activity, Security Event, and Behavioral Analytics using KQL queries.
Set up a Microsoft Sentinel instance on a log analytics workspace, explore the 31-day free trial with 10 gb daily ingestion, and navigate incidents, hunting cases, and workbooks.
Enable Defender for Cloud at the subscription level, upgrade to unlock features, enable Defender plans for servers, SQL, app service, storage, and connect to the log analytics workspace.
Configure Azure Activity and Defender for Cloud data connectors in Microsoft Sentinel, connect them to a Log Analytics workspace, and leverage pre-built KQL templates, workbooks, and hunting queries.
Learn how microsoft sentinel SIEM uses analytics rules and KQL to generate alerts and incidents, with scheduled and near real-time queries for threat detection and insider risk.
Learn how playbooks in Microsoft Sentinel automate security orchestration and automated response, using Azure Logic Apps to isolate endpoints and notify the security operations center team via Teams.
Create and automate incident notifications in Azure Sentinel by building a Logic Apps playbook that posts incident ID, URL, and description to a Microsoft Teams channel via automation rules.
Explore how Microsoft Sentinel workbooks provide interactive dashboards with time series graphs and query results, templates, data connectors, and KQL-driven visualizations for threat-hunting and incident documentation.
Enable UEBA to analyze logs in Microsoft Sentinel using machine learning to build baseline behavioral profiles of users, hosts, and apps, and detect anomalies for insider risk and threat hunting.
Threat hunting uses UEBA data to form and test hypotheses within Microsoft Sentinel. It differs from incident management by proactively addressing insider risk and following the MITRE ATT&CK framework.
Explore advanced multi-stage attack detection in Microsoft Sentinel using the fusion engine to correlate alerts and incidents from multiple data sources, improving detection with Defender connectors.
Defender for Cloud's security posture view for an azure openai resource reveals CSPM recommendations and provides quick fixes or automated remediation scripts to improve security posture.
Explore cloud security explorer to visually query and discover AI services deployed in your Azure subscription, including OpenAI models, and assess internet exposure for governance.
Explore how Azure DevOps unifies planning, building, and deployment through pipelines, boards, repos, and artifacts. Learn how CI/CD and DevSecOps integrate security throughout the lifecycle.
Explore how Azure DevOps enables DevSecOps with zero trust across the full SDLC—from design to operations—using Defender for Cloud and Microsoft Sentinel to secure code, workloads, and incidents.
Build a GPT-4 powered AI chat app and deploy it with Azure DevOps CI/CD, using an Azure OpenAI resource, bicep templates, and a web app tested with postman.
Provision an Azure OpenAI resource, deploy a GPT-4 model in Sweden Central region via Azure OpenAI Studio, and chat with it using the keys and endpoint.
Create an Azure DevOps organization and a first project, set location and visibility, and learn to use repos and CI/CD pipelines for DevSecOps.
Import a GitHub repository into an Azure DevOps project, explore CI/CD pipelines in YAML, and deploy an Azure OpenAI powered chatbot via containerized web apps and infrastructure templates.
Create a virtual machine in the Azure portal to act as an agent for Azure DevOps, enable virtualization, connect via RDP, run containerized apps, and join an agent pool.
Install Azure CLI, Python, and Docker Desktop on a VM to enable containerized pipeline execution for an Azure DevOps agent in an agent pool, with virtualization considerations.
Register and onboard a self-hosted virtual machine as an Azure DevOps agent in a dedicated agent pool, using a personal access token to configure and launch the agent online.
Launch a CI pipeline to build a container image, push to Azure Container Registry, and deploy via a CD pipeline to an Azure Web App for real-time AI testing.
Run the continuous deployment pipeline to deploy a containerized AI app from the Azure Container Registry to an Azure web app, using Bicep to set the resource group and permissions.
Query an Azure web app hosted in a Linux West Europe environment using Postman, sending a post request with a query to its chat endpoint to test a GPT engine.
Connect your Azure DevOps organization to Defender for Cloud and configure an Azure DevOps connector to enable automatic resource discovery and security alerts across environments.
Learn to run security analysis on Azure DevOps pipelines using the Microsoft Security for DevOps extension, connect DevOps to Defender for Cloud, and view IaC findings in the scans tab.
Learn how defender for cloud delivers CWPP protections for Azure workloads, with vulnerability scans, remediation steps, and just-in-time access.
Explore cloud security explorer in defender for cloud for proactive threat hunting, governance, and discovery across multi-cloud Azure, AWS, and GCP resources via low-code, visual queries.
Explore Defender for Cloud Apps within a zero trust framework, securing SaaS applications like Microsoft 365 and others through explicit verification, least privilege, and data protection using Purview.
Explain how defender for cloud apps offers broad cloud app protection, while Microsoft 365 cloud app security is a subset for 365 apps via an app connector.
Identify licenses covering Defender for cloud apps, including Microsoft 365 E5 and related suites, and note Entra P1 or P2 for conditional access policies.
Explore the defender XDA portal on security.microsoft.com to view cloud apps, exposure management, alerts, incidents, investigations, and policy templates for cloud apps governance.
Create a Windows 11 pro Azure virtual machine, apply app-blocking policies to block generative AI and social apps, and onboard the virtual machine to Defender XDR for asset visibility.
Onboard your virtual machine to Defender for Endpoint using the local onboarding script, then verify the endpoint appears in the Defender XDR portal under assets > devices.
Block access to unsanctioned generative AI apps with Defender XDR and Defender for Endpoint via the cloud app catalog, using custom network indicators to enforce app access.
Discover and classify data across cloud apps using Defender for Cloud Apps, apply sensitivity labels with Microsoft Purview, and govern and monitor data to manage external collaborators and policy compliance.
Learn to create a file governance policy with Defender for Cloud Apps, enable file monitoring, connect Microsoft 365 via the app connector, and apply Purview sensitivity labels to unlabeled files.
Explore threat detection policies in defender for cloud apps, enabling proactive detection of unusual locations, impossible travel, and data exfiltration, with customizable policies and severity-based incident triage.
Create threat detection policies in the Defender XDR portal using activity policies, filters, and governance actions to detect file uploads to OneDrive or Copilot for M365.
Explore how defender for cloud apps integrates with Microsoft Sentinel to centralize alerts and incidents from Defender XDR, enabling Siem, security information and event management, and automated playbooks.
Connect Sentinel workspace with Defender portal by configuring Defender XDR data connectors in Sentinel, ingesting endpoint and cloud app logs, then view and investigate incidents in a unified security view.
Configure conditional access policies in the admin center to require multi-factor authentication for cloud apps like Exchange Online, and test access via Outlook.com and portal.office.com.
Learn how conditional access app control, powered by Defender for Cloud Apps, provides real-time data loss prevention and session controls through a reverse proxy to secure cloud apps.
Create a conditional access app control policy in Defender for Cloud Apps to enforce a data loss prevention policy for Microsoft 365 apps, blocking copy-paste from unmanaged devices.
Discover how OAuth apps use the open authorization standard to grant token-based, limited access to resources like your calendar and files, with governance from Defender for Cloud Apps.
Govern OAuth applications with policy-driven governance in Microsoft cloud security, analyzing app permissions, governance actions, and revoking or blocking risky OAuth apps using Defender for Cloud Apps.
Explore defender for Office 365 to protect email, OneDrive, and the Office portal from phishing and malware, using Exchange Online Protection and zero trust with automated investigation and response.
Learn the differences between exchange online protection and defender for office 365 plan 1 and plan 2, including email threat protection, phishing defenses, and automated investigation and response.
Explore Defender for Office 365 and Exchange Online Protection to guard mail flow with anti-phishing, anti-spoofing, anti-malware, safe links, attachments, and zap policy under zero-trust.
Explore default, preset, and custom security policies in Defender for Office 365, detailing their baseline protection, priority, and the ability to tailor rules for specific user groups.
Configure Defender for Office 365 with default protection and standard or strict preset policies, targeting specific user groups while balancing security and productivity, and customize protection settings.
Explore why email authentication matters for Exchange Online Protection, and learn how SPF, DKIM, DMARC, and ARC work together to reduce spoofing, phishing, and false positives while preserving legitimate mail.
Configure SPF for your Microsoft 365 tenant by connecting DNS, generating SPF txt records, and authorizing mail servers to enable email authentication and prevent spoofing.
Set up DKIM in Microsoft Defender for Office 365 by configuring DNS CNAME records, adding selector1._domainkey entries, and enabling the policy for email authentication.
Configure dmarc for your organization using a dmarc generator, create a dns txt record, and enforce a 100% reject policy for emails failing spf or dkim, with aggregate reports.
Configure ARC in Defender for Office 365 to authenticate relayed emails with ARC sealer and trusted domains, ensuring messages pass ARC checks even when SPF and DKIM fail.
Explore email security by using the message headers analyzer to inspect SPF, DKIM, and DMARC results, view authentication data, and understand header details like origin, signatures, and RSA SHA-256 encryption.
Protect data and users by applying threat protection policies in Defender for Office 365, stopping phishing and malware at the gate with safe attachments, URL detonation, and anti-spam measures.
Create a safe attachments policy in Defender for Office 365, specify targets, and choose actions like quarantine or block, using sandbox scanning to assess attachments.
Track and detect user activity with defender for office 365 by defining policies that flag sign-ins, file uploads, and privilege changes, raising alerts to identify compromised identities and insider risks.
Create a custom user activity policy in Defender for Office 365 by selecting activities such as file, folder, and synchronization events, applying it to users, and configuring email alerts.
Connect Defender for Office 365 to Microsoft Sentinel with the Defender XDR data connector to create a unified SIEM and SOAR view, and synchronize incidents across portals.
Explore how Microsoft Intune unifies mobile device and application management to secure endpoints, with BYOD and corporate devices, and integrates Defender for Endpoint for pre and post breach protection.
Explore how Intune and Microsoft Defender for Endpoint implement zero trust through explicit verification, least privilege access, and breach-aware controls, using device compliance, app protection policies, and real-time threat remediation.
Enroll corporate owned devices (cods) and BYOD into Microsoft Intune, using Autopilot for zero-touch deployment and the Company Portal for policy, app protection, and data governance.
Create an Azure virtual machine as an endpoint for onboarding to Microsoft Intune and Defender for Endpoint. Learn trusted launch security features and prepare the VM for lab enrollments.
Enroll a Windows VM in Microsoft Intune by enabling automatic enrollment, configuring device limits and platform restrictions, and using device enrollment managers for mass onboarding in pre-deployment.
This hands-on lab guides onboarding a Windows VM to Entra join and auto enrollment into Microsoft Intune MDM, including managing via static and dynamic groups and KQL queries.
Create a Windows 10 and later compliance policy in Microsoft Intune, set a minimum OS version, and assign it to the Udemy demo group, then sync to verify compliance.
Learn to create and apply Intune configuration policies to Windows endpoints, blocking gaming and start options, graying out UI areas, and managing Windows Defender exclusions on a VM.
Showcases deploying Microsoft 365 apps to Intune-managed devices via the company portal, configuring the Office apps suite, and marking them as required to install on the VM after policy sync.
Create app protection policies for cloud apps on managed iOS devices, enabling data loss prevention by blocking cut, copy, paste and backups to iCloud from Outlook.
Learn to create conditional access policies in the Intune admin center that grant Office.com access only from compliant devices, using all users and testing with compliant vs noncompliant devices.
Explore configuring endpoint security policies in Microsoft Intune to enable BitLocker disk encryption on Windows devices, leveraging TPM, startup PIN, and recovery key storage to protect corporate data.
Connect Microsoft Intune with Defender for Endpoint, onboard devices to MDE via a Defender for Endpoint connector, and monitor onboarding, compliance policies, and exposure in security.microsoft.com and Defender portal.
Demonstrates connecting Defender for Endpoint to a Microsoft Sentinel workspace via the Defender XDR connector to feed endpoint data and alerts for a unified SIEM with hunting queries.
With the ever increasing experimentation with AI applications like Copilot, ChatGPT and Google Gemini, securing your organization from the threats of these AI workloads has become the need of the hour.
In this course we will deep dive into how you can improve your CSPM (Cloud Security Posture Management) and Cloud Security Hygiene with various Microsoft security solutions like Purview for Information Protection and Governance, Defender for Extended Detection and Response, Sentinel for SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation and Response), Microsoft Entra ID for Identity and Access Management etc.
The following Microsoft security solutions will be covered in this course:
1) Microsoft Entra ID - Cloud-based identity and access management service for secure resource access.
2)Microsoft Entra Conditional Access - Centralized policy control for authentication conditions and data/application security.
3)Microsoft Defender for Identity - Detects on-premises identity attacks using behavioral analysis and specific threat detections.
4)Intune - Cloud-based mobile device and application management service, integrates with Conditional Access for device security.
5)Defender for Endpoint - Provides Endpoint Detection and Response (EDR), Threat and Vulnerability Management (TVM), and automated incident investigation/remediation for multiple OS platforms.
6)Defender for Cloud Apps - Provides XDR capabilities for SaaS applications, Shadow IT risk management, Info Protection/DLP, and session monitoring/control.
7) Defender for Office 365 - Offers XDR capabilities including sandbox detonation, integrated threat intelligence, and attack simulation across various Microsoft 365 services.
8) Defender for Cloud - Simplifies detection, automated investigation, and response for Azure resources.
9) Microsoft Purview DLP - Implements data loss prevention by defining and applying DLP policies to protect sensitive items across various Microsoft 365 services, Office applications, endpoints, non-Microsoft cloud apps, on-premises file shares, and Power BI.
10) Microsoft Purview Information Protection - Protects sensitive data in documents and emails with a built-in, intelligent, unified, and extensible solution.
11) Intune Mobile App Management (MAM) - Uses app configuration profiles to deploy or configure apps on unenrolled devices, protecting data within apps when combined with app protection policies.
12) Defender for Cloud Apps - Provides security capabilities for cloud applications.
13) Microsoft Defender XDR provides a unified detection and response platform (XDR + SIEM) designed to simplify security operations with integrated detection, automated investigation and response across platforms and clouds.
14) Microsoft Sentinel is a cloud native SIEM+SOAR solution that integrates with Microsoft Defender XDR and enables you to use UEBA and ML to detect, hunt for, and remediate threats across data sources in your enterprise.
Note: Although you might seem a lot of topics not covered in this course as of now, those topics will be added as the course moves forward in due time.