________________________________________________________________
Do you want to take this course in another training mode?
Contact us
Other modes: Telepresence - Classroom
________________________________________________________________
Microsoft is retiring AZ-500: Secure cloud resources with Microsoft security technologies on May 31, 2026. The replacement course will be: Cloud and AI Security Engineer (SC-500). Launching in July 2026.
AZ-500 Course: Secure cloud resources with Microsoft security technologies
This course provides IT security professionals with the knowledge and skills necessary to implement security controls, maintain an organization's security posture, and identify and remediate security vulnerabilities. This course includes security for identity and access, platform protection, data and applications, and security operations.
Virtual course with certification exam included as a gift. Don't miss this opportunity! The exam is valued at €126 + VAT and is included at no additional cost.
Promotion valid until December 31, 2026. One-attempt exam available only in Virtual - Teletraining mode. Not applicable to Self-Learning mode.
Level: Intermediate - Product: Azure - Role: Security Engineer
⏱️
Course duration:
100 hours
🔑
Access to classroom:
3 months
Azure Cloud Security - Microsoft Security Technologies - Cloud resource protection - Identity management - Access control Data encryption - Application security - Compliance and security
Course aimed at
This course is aimed at Azure security engineers who plan to take the associated certification exam or who perform security tasks in their daily work. This course would also be useful for an engineer who wants to specialize in providing security for Azure-based digital platforms and play an integral role in protecting an organization's data.
AZ-500 Course Objectives
-
Implement security controls: You will learn to configure and manage security controls to protect resources in Azure, including identity and access protection, platform security, data, and applications.
-
Maintain security posture: You will develop skills to maintain and improve your organization's security posture, ensuring that systems and data are protected against threats.
-
Identify and correct vulnerabilities: You will learn to identify and remediate security vulnerabilities using tools like Microsoft Defender for Cloud.
-
Implement threat protection: You will configure and manage threat protection solutions to detect and respond to security incidents in Azure, multi-cloud, and hybrid environments.
Elements of the Microsoft Learn AZ-500 training
- AZ-500: Protect identity and access (2 modules)
- AZ-500: Secure networks (3 modules)
- AZ-500: Secure compute, storage, and databases (3 modules)
- AZ-500: Protect Azure using Microsoft Defender for Cloud and Microsoft Sentinel (4 modules)
AZ-500 Course Content Protecting cloud resources with Microsoft security technologies
Module 1. Manage identity and access
Lessons
- Manage security controls for identity and access
- Manage application access in Microsoft Entra
Lab 01: Role-based access control
After completing this module, students will be able to:
- Effectively manage identities with Microsoft Entra ID to ensure secure access and identity governance.
- Effectively manage authentication processes with Microsoft Entra ID to protect user access and verify identities.
- Implement and manage authorization settings with Microsoft Entra ID to control access rights and permissions securely.
- Effectively manage and secure access to applications with Microsoft Entra ID to ensure proper user authorization and authentication.
Module 2. Protect networks
Lessons
- Plan and implement virtual network security
- Plan and implement private access security to Azure resources
- Plan and implement public access security to Azure resources
Lab 02: Network security groups and application security groups
Lab 03: Azure Firewall
After completing this module, students will be able to:
- Plan and implement security measures for virtual networks, covering NSGs, ASGs, UDRs, VNET peering, VPN Gateway instances, Virtual WAN, and network monitoring using Network Watcher.
- Establish private access to Azure resources using service endpoints, private endpoints, Private Link services, and secure configurations for App Service, Azure Functions, and Azure SQL Managed Instance.
- Implement security for public Azure access, including TLS application integration, Azure Firewall, Application Gateway, Front Door, WAF, and recommendations for Azure DDoS Protection.
Module 3. Protect compute, storage, and databases
Lessons
- Plan and implement advanced compute security
- Plan and implement storage security
- Plan and implement security for Azure SQL Database and Azure SQL Managed Instance
Lab 04: Configure and protect ACR and AKS
Lab 05: Protect Azure SQL Database
Lab 06: Service endpoints and secure storage
After completing this module, students will be able to:
- Strengthen compute security using Azure Bastion, AKS configurations, container monitoring, and advanced encryption techniques.
- Enhance storage security with custom access controls, threat protection measures, and various encryption strategies.
- Strengthen Azure SQL Database protection through authentication, auditing, data classification, and advanced encryption recommendations.
Module 4. Protect Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Lessons
- Implement and manage compliance with cloud governance policies
- Manage security posture with Microsoft Defender for Cloud
Configure and manage threat protection using Microsoft Defender for Cloud
- Configure and manage security monitoring and automation solutions
Lab 07: Key Vault
Lab 08: Creating a Log Analytics workspace, an Azure Storage account, and a data collection rule (DCR)
Lab 09: Configuring enhanced security features of Microsoft Defender for Cloud for servers
Lab 10: Enabling Just-In-Time access on virtual machines
Lab 11: Microsoft Sentinel
After completing this module, students will be able to:
- Implement security operations, establish governance, and deploy Azure policies and infrastructure, while protecting keys and certificates.
- Improve Defender's security posture, ensure compliance, and monitor external threats.
- Configure Defender for various threats, manage alerts, and leverage Sentinel for advanced security strategies.
Prerequisites
Students who pass the test will have prior knowledge and understanding of:
- Industry security best practices and requirements, such as defense in depth, least privileged access, role-based access control, multi-factor authentication, shared responsibility, and the zero-trust model.
- Security protocols, such as Virtual Private Networks (VPNs), Internet Protocol Security (IPSec), Secure Sockets Layer (SSL), and disk and data encryption methods.
- Some experience in deploying Azure workloads. This course does not cover the basics of Azure administration, but rather builds on that knowledge by adding security-specific information.
- Experience with Windows and Linux systems, as well as scripting languages.
- Course labs may use PowerShell and the CLI.
Language
Associated Microsoft Certification: Azure Security Engineer Associate
Microsoft Certified: Azure Security Engineer Associate
Microsoft is retiring the Azure Security Engineer Associate (AZ-500) certification on July 31, 2026. Its replacement will be the certification: Cloud and AI Security Engineer (SC-500). Beta launch May 2026.
Demonstrates the skills required to implement security controls, maintain an organization's security posture, and identify and remediate security vulnerabilities.
Level: Intermediate
Role: Security Engineer
Product: Azure
Subject: Security