ABOUT THIS COURSE
This course prepares you to design, implement, and manage end-to-end security controls across Microsoft Azure and Microsoft 365 environments — including the emerging landscape of AI workloads and autonomous agents. Through a combination of instructor-led sessions and hands-on labs, you build practical skills in identity security, cloud infrastructure protection, threat detection, and posture management. This course is intended for security engineers who are responsible for planning and implementing security controls across cloud, hybrid, and multi-cloud environments using Microsoft security technologies.
Classroom
As a candidate for this course, you’re a security engineer who protects organizational systems and data across cloud and hybrid environments by implementing comprehensive security controls that prevent unauthorized access and mitigate risks proactively. This role spans multiple security domains including identity, network, application, data, and compute. This role also ensures that platforms, data, identities, and infrastructure used by AI workloads are securely implemented and monitored. You work closely with architects, administrators, engineers, analysts, and developers responsible for Azure, Microsoft 365, identity and access, information protection, security operations, devops, application development, database platforms, and networks. You should have practical experience in administration of Microsoft Azure and hybrid environments, including compute, network, and storage. You should have strong familiarity with Microsoft Entra ID and familiarity with Microsoft 365 administration. Your responsibilities for this role include:
4 days
28 Hours
Learning Path 1: Secure access to resources by using Microsoft Entra
Learn how to protect identities, manage privileged access, and secure AI-powered applications using Microsoft Entra ID. This learning path covers MFA, Conditional Access, passwordless authentication, PIM, Just-in-Time access, and AI security, equipping you with a comprehensive defence-in-depth approach to modern access security.
Modules
Learning Path 2: Secure Azure Key Vault with defense in depth for the cloud and AI workloads
Implement defence-in-depth security for Azure Key Vault by securing vault configurations, enforcing least-privilege access, managing keys, secrets, and certificates, and using Microsoft Defender for Cloud to detect credential exposure and suspicious access.
Modules
Learning Path 3: Enforce security governance and regulatory compliance
Enforce security governance and compliance in Azure using Azure Policy, resource locks, Defender for Cloud, RBAC governance, ransomware-protected backups, and secure Bicep pipelines to prevent noncompliant resources from reaching production.
Modules
Learning Path 4: Implement security for Azure Storage for the cloud and AI security engineer
Implement a defence-in-depth strategy for Azure Storage by securing access with Microsoft Entra ID, managed identities, and stored access policies; enforcing network controls with firewalls and private endpoints; and using Microsoft Defender for Storage to detect threats such as malicious uploads and compromised AI agent credentials.
Modules
Learning Path 5: Implement security for Azure SQL databases
Implement end-to-end security for Azure SQL Database and SQL Managed Instance. Configure Entra ID authentication with managed identity access, deploy private endpoints, and apply encryption and access controls to protect sensitive financial data. Establish compliant audit trails and enable Microsoft Defender for Databases to detect SQL injection, anomalous access, and vulnerability exposures.
Modules
Learning Path 6: Implement network security controls in Azure
Implement Azure defence-in-depth security using segmentation, least-privilege access, Azure Firewall, Zero Trust connectivity, and private endpoints to protect workloads and eliminate public exposure.
Modules
Learning Path 7: Implement security for AI
Implement Security for AI covers securing AI workloads across the Microsoft security platform. Learn how to identify AI data risks with Purview DSPM, secure agent identities with Entra Agent ID and Conditional Access, analyse threats in Defender XDR, protect AI agents and model traffic, apply AI guardrails, secure AI workloads with Defender for Cloud, and govern deployed agents using Agent 365.
Modules
Learning Path 8: Implement security for servers and virtual machines
Implement defence-in-depth security for Azure VMs and hybrid servers with encryption, Trusted Launch, Azure Bastion, Azure Arc, Microsoft Defender for Servers, Just-in-Time access, and Azure Machine Configuration to protect, monitor, and enforce security across the entire server estate.
Modules
Learning Path 9: Secure Azure application platform services for the cloud and AI security engineer
Implement security controls across Azure application services, from containers to APIs. Configure Microsoft Defender for Containers, enforce AKS security baselines, and secure container registries and runtimes. Apply authentication, network access, and policy controls across Azure Functions, Logic Apps, App Service, Web Application Firewall, and Azure API Management.
Modules
Learning Path 10: Manage security posture by using Microsoft Defender for Cloud
Learn to strengthen security posture across hybrid and multicloud environments using Microsoft Defender for Cloud. Connect Azure, on-premises, AWS, and GCP resources for unified visibility, identify and prioritise risks with CSPM tools, discover external exposures with Defender EASM, assess compliance, and generate audit-ready reports. Enable CWPP protections, then use Defender Vulnerability Management to detect and remediate vulnerabilities across workloads and Azure VMs.
Modules
Learning Path 11: Implement activity and event collection in Microsoft Sentinel
Build and manage a Microsoft Sentinel event collection and response solution by securing a workspace, connecting data sources, collecting Linux and Windows events, automating responses with playbooks, and managing retention and audit logs for compliance.
Modules
Learning Path 12: Deploy and operate Microsoft Security Copilot
This learning path introduces Microsoft Security Copilot, covering prompt fundamentals, deployment, and operational management. You'll learn how to configure workspaces, Security Compute Units, data residency, and roles for enterprise environments, then govern plugins and manage Microsoft and partner agents securely throughout their lifecycle.
Modules
Participants should have:
English
| Course Fee Payable | ||
|---|---|---|
| Original Fee | Before GST | With GST (9%) |
| Course Fee | $2,400.00 | $2,616.00 |