AZ-500: Secure cloud resources with Microsoft security technologies

€695.00
| /

________________________________________________________________

Do you want to take this course in another training mode?
Contact us

Other modes: Telepresence - Classroom

________________________________________________________________

⚠️ Course retired: Microsoft retired the AZ-500 material on August 31, 2026. The content remains available for reference. The replacement course is SC-500: Implement End-to-End Security Controls for Cloud and AI Workloads →

AZ-500 Course: Secure cloud resources with Microsoft security technologies

This course provides IT security professionals with the knowledge and skills necessary to implement security controls, maintain an organization's security posture, and identify and remediate security vulnerabilities. This course includes security for identity and access, platform protection, data and applications, and security operations.

Level: Intermediate - Product: Azure - Role: Security Engineer

⏱️

Course duration:
100 hours

🔑

Access to the classroom:
3 months

Azure Cloud Security - Microsoft Security Technologies - Cloud Resource Protection - Identity Management - Access Control - Data Encryption - Application Security - Compliance and Security


Course audience

This course is intended for Azure security engineers who plan to take the associated certification exam or who perform security tasks in their daily work. This course would also be useful for an engineer who wants to specialize in providing security for Azure-based digital platforms and play an integral role in protecting an organization's data.


AZ-500 Course Objectives

  • Implement security controls: You will learn to configure and manage security controls to protect resources in Azure, including identity and access protection, platform security, data, and applications.
  • Maintain security posture: You will develop skills to maintain and improve your organization's security posture, ensuring that systems and data are protected against threats.
  • Identify and correct vulnerabilities: You will learn to identify and remediate security vulnerabilities using tools like Microsoft Defender for Cloud.
  • Implement threat protection: You will configure and manage threat protection solutions to detect and respond to security incidents in Azure, multi-cloud, and hybrid environments.


Elements of the Microsoft Learn AZ-500 training

  • AZ-500: Identity and access protection (2 modules)
  • AZ-500: Secure networks (3 modules)
  • AZ-500: Secure compute, storage, and databases (3 modules)
  • AZ-500: Protect Azure using Microsoft Defender for Cloud and Microsoft Sentinel (4 modules)


AZ-500 Course Content: Protecting cloud resources with Microsoft security technologies

Module 1. Manage identity and access

Lessons

  • Managing security controls for identity and access
  • Managing application access in Microsoft Entra

Lab 01: Role-based access control

After completing this module, students will be able to:

  • Effectively manage identities with Microsoft Entra ID to ensure secure access and identity governance.
  • Effectively manage authentication processes with Microsoft Entra ID to protect user access and verify identities.
  • Implement and manage authorization settings with Microsoft Entra ID to control access rights and permissions securely.
  • Effectively manage and protect application access with Microsoft Entra ID to ensure proper user authorization and authentication.

Module 2. Protecting networks

Lessons

  • Planning and implementing virtual network security
  • Planning and implementing private access security to Azure resources
  • Planning and implementing public access security to Azure resources

Lab 02: Network Security Groups and Application Security Groups

Lab 03: Azure Firewall

After completing this module, students will be able to:

  • Plan and implement security measures for virtual networks, encompassing NSGs, ASGs, UDR, VNET peering, VPN Gateway instances, Virtual WAN, and network monitoring using Network Watcher.
  • Establish private access to Azure resources using service endpoints, private endpoints, Private Link services, and secure configurations for App Service, Azure Functions, and Azure SQL Managed Instance.
  • Implement security for public Azure access, including TLS application integration, Azure Firewall, Application Gateway, Front Door, WAF, and recommendations for Azure DDoS Protection.

Module 3. Protecting compute, storage, and databases

Lessons

  • Planning and implementing advanced compute security
  • Planning and implementing storage security
  • Planning and implementing Azure SQL Database and Azure SQL Managed Instance security

Lab 04: Configuring and protecting ACR and AKS

Lab 05: Protecting Azure SQL Database

Lab 06: Service endpoints and secure storage

After completing this module, students will be able to:

  • Enhance compute security using Azure Bastion, AKS configurations, container monitoring, and advanced encryption techniques.
  • Improve storage security with custom access controls, threat protection measures, and various encryption strategies.
  • Strengthen Azure SQL Database protection through authentication, auditing, data classification, and advanced encryption recommendations.

Module 4. Protecting Azure with Microsoft Defender for Cloud and Microsoft Sentinel

Lessons

  • Implementing and managing compliance with cloud governance policies
  • Managing security posture with Microsoft Defender for Cloud
  • Configuring and managing threat protection using Microsoft Defender for Cloud
  • Configuring and managing security monitoring and automation solutions

Lab 07: Key Vault

Lab 08: Creating a Log Analytics workspace, an Azure Storage account, and a Data Collection Rule (DCR)

Lab 09: Configuring Microsoft Defender for Cloud enhanced security features for servers

Lab 10: Enabling Just-In-Time access on virtual machines

Lab 11: Microsoft Sentinel

After completing this module, students will be able to:

  • Implement security operations, establish governance, and deploy Azure policies and infrastructures, while protecting keys and certificates.
  • Improve Defender's security posture, ensure compliance, and monitor external threats.
  • Configure Defender for various threats, manage alerts, and leverage Sentinel for advanced security strategies.


Prerequisites

Students passing the test will have prior knowledge and understanding of:

  • Industry security best practices and requirements, such as defense in depth, least privileged access, role-based access control, multifactor authentication, shared responsibility, and the zero-trust model.
  • Security protocols, such as Virtual Private Networks (VPNs), Internet Protocol Security (IPSec), Secure Sockets Layer (SSL), and disk and data encryption methods.
  • Some experience implementing Azure workloads. This course does not cover basic Azure administration concepts; instead, the content builds on that knowledge by adding security-specific information.
  • Experience with Windows and Linux systems, as well as scripting languages.
  • Course labs may use PowerShell and CLI.


Language

  • Course: English / Spanish
  • Labs: English / Spanish


Associated Microsoft Certification: Azure Security Engineer Associate

Microsoft Certified

Microsoft Certified: Azure Security Engineer Associate

Demonstrates the skills needed to implement security controls, maintain an organization's security posture, and identify and remediate security vulnerabilities.

Level: Intermediate
Role: Security Engineer
Product: Azure
Subject: Security


💡 Did you know this course is included in LaaS Cert?

Take this course and many more with our LaaS Cert annual license . Unlimited training for only €1,295!

✅ Microsoft, Linux-LPI, SCRUM, ITIL and Nanfor technical courses

✅ Personalized support always by your side

✅ 100% online, official and updated

Get your license now!

LaaS cert Formación ilimitada

Information related to training

Soporte siempre a tu lado

Training support

Always by your side

Modalidades Formativas

Training modalities

Self Learning - Virtual - In-person - Telepresence

bonificaciones

Bonuses

For companies