SC-500 Implement end‑to‑end security controls for cloud and AI workloads

Course Overview

ABOUT THIS COURSE

This course prepares you to design, implement, and manage end-to-end security controls across Microsoft Azure and Microsoft 365 environments — including the emerging landscape of AI workloads and autonomous agents. Through a combination of instructor-led sessions and hands-on labs, you build practical skills in identity security, cloud infrastructure protection, threat detection, and posture management. This course is intended for security engineers who are responsible for planning and implementing security controls across cloud, hybrid, and multi-cloud environments using Microsoft security technologies.


Training Type

Classroom


Who Should Attend

As a candidate for this course, you’re a security engineer who protects organizational systems and data across cloud and hybrid environments by implementing comprehensive security controls that prevent unauthorized access and mitigate risks proactively. This role spans multiple security domains including identity, network, application, data, and compute. This role also ensures that platforms, data, identities, and infrastructure used by AI workloads are securely implemented and monitored. You work closely with architects, administrators, engineers, analysts, and developers responsible for Azure, Microsoft 365, identity and access, information protection, security operations, devops, application development, database platforms, and networks. You should have practical experience in administration of Microsoft Azure and hybrid environments, including compute, network, and storage. You should have strong familiarity with Microsoft Entra ID and familiarity with Microsoft 365 administration. Your responsibilities for this role include:

  • Securing access to resources by using Microsoft Entra ID and Azure Key Vault
  • Enforcing security and regulatory compliance
  • Securing storage, databases, and networking
  • Securing compute
  • Securing AI solutions
  • Managing and monitoring security posture



Course Duration

4 days


Total Training Duration (Hour)

28 Hours


Course Outline

Learning Path 1: Secure access to resources by using Microsoft Entra

Learn how to protect identities, manage privileged access, and secure AI-powered applications using Microsoft Entra ID. This learning path covers MFA, Conditional Access, passwordless authentication, PIM, Just-in-Time access, and AI security, equipping you with a comprehensive defence-in-depth approach to modern access security.

Modules

  • Manage and implement authentication methods in Microsoft Entra ID
  • Implement and configure Privileged Identity Management (PIM)
  • Authenticate your API plugin for declarative agents with secured APIs



Learning Path 2: Secure Azure Key Vault with defense in depth for the cloud and AI workloads

Implement defence-in-depth security for Azure Key Vault by securing vault configurations, enforcing least-privilege access, managing keys, secrets, and certificates, and using Microsoft Defender for Cloud to detect credential exposure and suspicious access.

Modules

  • Configure and secure Azure Key Vault
  • Manage keys and secrets in Azure Key Vault
  • Manage certificates and monitor Azure Key Vault
  • Protect Azure Key Vault with Microsoft Defender for Cloud



Learning Path 3: Enforce security governance and regulatory compliance

Enforce security governance and compliance in Azure using Azure Policy, resource locks, Defender for Cloud, RBAC governance, ransomware-protected backups, and secure Bicep pipelines to prevent noncompliant resources from reaching production.

Modules

  • Enforce governance with Azure Policy and resource locks
  • Configure security controls and remediate recommendations in Defender for Cloud
  • Evaluate regulatory compliance in Defender for Cloud
  • Manage and right-size RBAC role assignments for least privilege
  • Protect backup data with Azure Backup security features
  • Implement security controls in infrastructure as code



Learning Path 4: Implement security for Azure Storage for the cloud and AI security engineer

Implement a defence-in-depth strategy for Azure Storage by securing access with Microsoft Entra ID, managed identities, and stored access policies; enforcing network controls with firewalls and private endpoints; and using Microsoft Defender for Storage to detect threats such as malicious uploads and compromised AI agent credentials.

Modules

  • Describe Azure storage services
  • Implement security and manage access for Azure Storage
  • Configure network security for Azure Storage
  • Implement Microsoft Defender for Storage



Learning Path 5: Implement security for Azure SQL databases

Implement end-to-end security for Azure SQL Database and SQL Managed Instance. Configure Entra ID authentication with managed identity access, deploy private endpoints, and apply encryption and access controls to protect sensitive financial data. Establish compliant audit trails and enable Microsoft Defender for Databases to detect SQL injection, anomalous access, and vulnerability exposures.

Modules

  • Configure platform-level security for Azure SQL
  • Configure auditing for Azure SQL Database and SQL Managed Instance
  • Implement Microsoft Defender for Databases



Learning Path 6: Implement network security controls in Azure

Implement Azure defence-in-depth security using segmentation, least-privilege access, Azure Firewall, Zero Trust connectivity, and private endpoints to protect workloads and eliminate public exposure.

Modules

  • Segment and isolate Azure workloads using network security controls
  • Centralize and enforce traffic inspection using Azure Firewall
  • Secure remote and hybrid connectivity using VPN gateways and Microsoft Entra Private Access
  • Eliminate public network exposure of Azure PaaS services



Learning Path 7: Implement security for AI

Implement Security for AI covers securing AI workloads across the Microsoft security platform. Learn how to identify AI data risks with Purview DSPM, secure agent identities with Entra Agent ID and Conditional Access, analyse threats in Defender XDR, protect AI agents and model traffic, apply AI guardrails, secure AI workloads with Defender for Cloud, and govern deployed agents using Agent 365.

Modules

  • Secure access for Microsoft Entra Agent Identity
  • Analyze AI identity risks using Microsoft Defender XDR
  • Enable real-time protection for Copilot Studio agents
  • Configure AI Gateway security in Microsoft Foundry
  • Configure and manage guardrails in Microsoft Foundry
  • Protect AI workloads with Microsoft Defender for Cloud
  • Enable Defender for AI Services workload protection in Microsoft Defender for Cloud
  • Manage agents using Microsoft Agent 365
  • Identify AI data risks using Microsoft Purview Data Security Posture Management



Learning Path 8: Implement security for servers and virtual machines

Implement defence-in-depth security for Azure VMs and hybrid servers with encryption, Trusted Launch, Azure Bastion, Azure Arc, Microsoft Defender for Servers, Just-in-Time access, and Azure Machine Configuration to protect, monitor, and enforce security across the entire server estate.

Modules

  • Implement disk encryption for Azure virtual machines
  • Configure trusted launch security features for Azure virtual machines
  • Plan and implement Azure Bastion
  • Manage security for Arc-enabled hybrid servers
  • Implement Microsoft Defender for Servers
  • Enable and enforce just-in-time VM access
  • Enforce VM security configuration with Azure Machine Configuration



Learning Path 9: Secure Azure application platform services for the cloud and AI security engineer

Implement security controls across Azure application services, from containers to APIs. Configure Microsoft Defender for Containers, enforce AKS security baselines, and secure container registries and runtimes. Apply authentication, network access, and policy controls across Azure Functions, Logic Apps, App Service, Web Application Firewall, and Azure API Management.

Modules

  • Detect container risks using Microsoft Defender for Containers
  • Implement security controls for Azure Kubernetes Service
  • Implement security controls for Azure Container Registry, Container Instances, and Container Apps
  • Implement security controls for Azure Function apps and Logic apps
  • Implement security controls for Azure App Services and Web Application Firewall
  • Implement API backend security using Azure API Management



Learning Path 10: Manage security posture by using Microsoft Defender for Cloud

Learn to strengthen security posture across hybrid and multicloud environments using Microsoft Defender for Cloud. Connect Azure, on-premises, AWS, and GCP resources for unified visibility, identify and prioritise risks with CSPM tools, discover external exposures with Defender EASM, assess compliance, and generate audit-ready reports. Enable CWPP protections, then use Defender Vulnerability Management to detect and remediate vulnerabilities across workloads and Azure VMs.

Modules

  • Connect hybrid and multicloud environments to Microsoft Defender for Cloud
  • Identify security risks by using Cloud Security Posture Management
  • Discover unprotected assets and vulnerabilities by using Microsoft Defender External Attack Surface Management
  • Evaluate regulatory compliance in Defender for Cloud
  • Enable and configure workload protection plans in Microsoft Defender for Cloud
  • Configure Microsoft Defender Vulnerability Management settings for Azure VMs



Learning Path 11: Implement activity and event collection in Microsoft Sentinel

Build and manage a Microsoft Sentinel event collection and response solution by securing a workspace, connecting data sources, collecting Linux and Windows events, automating responses with playbooks, and managing retention and audit logs for compliance.

Modules

  • Create and manage Microsoft Sentinel workspaces
  • Manage content in Microsoft Sentinel
  • Connect Microsoft services to Microsoft Sentinel
  • Connect syslog data sources to Microsoft Sentinel
  • Connect Common Event Format logs to Microsoft Sentinel
  • Connect Windows hosts to Microsoft Sentinel
  • Implement automation rules and playbooks in Microsoft Sentinel
  • Manage data storage and query audit logs in Microsoft Sentinel



Learning Path 12: Deploy and operate Microsoft Security Copilot

This learning path introduces Microsoft Security Copilot, covering prompt fundamentals, deployment, and operational management. You'll learn how to configure workspaces, Security Compute Units, data residency, and roles for enterprise environments, then govern plugins and manage Microsoft and partner agents securely throughout their lifecycle.

Modules

  • Describe Microsoft Security Copilot
  • Configure workspaces for Microsoft Security Copilot
  • Manage plugins and agents in Microsoft Security Copilot




Course Learning Outcome
  • Secure access to cloud and AI resources using Microsoft identity and access management solutions.
  • Implement security controls across Azure infrastructure, applications, data, networks, and AI workloads.
  • Apply governance, compliance, and data protection practices to meet organisational and regulatory requirements.
  • Strengthen threat detection and incident response using Microsoft security operations tools.
  • Manage and continuously improve cloud and AI security posture through monitoring, risk assessment, and remediation.

Pre-requisitess

Participants should have:

  • Fundamental knowledge of cloud and cybersecurity concepts.
  • Experience administering Microsoft Azure environments.
  • Familiarity with Microsoft Entra ID and identity management.
  • Basic understanding of Microsoft 365 administration and security.
  • Awareness of security, compliance, and risk management practices.

Medium of Instruction & Trainer

English


Price
Course Fee Payable
Original Fee Before GST With GST (9%)
Course Fee $2,400.00 $2,616.00

Please note that prices are subjected to change.
Back to Catalogue →
Next Available Schedules
Available Seats:
Course Name:
Category:
Mode of Delivery:
Trainer:
Venue:
Language:
Session Dates:

Registration Date:
From To