Course Duration
4 Days
Microsoft
Authorized Training
IT
Course cost:
was £2,499
£1,949
IT Certification Overview
Build the practical skills needed to implement and manage security controls across Microsoft Azure, Microsoft 365, and AI-enabled workloads.
This four-day course prepares security professionals to protect identities, data, infrastructure, applications, and AI solutions across cloud, hybrid, and multicloud environments. You will explore how Microsoft security technologies can help reduce unauthorised access, limit exposure, enforce secure configurations, and strengthen your organisation’s overall security posture.
Through instructor-led learning, hands-on labs, knowledge checks, demonstrations, and discussion, you will develop practical experience with Microsoft Entra ID, Azure Key Vault, Azure Policy, Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Purview, Microsoft Security Copilot, and other security capabilities.
As AI becomes increasingly embedded in modern cloud solutions, the course also explores how to secure AI agents, identities, data access paths, gateways, guardrails, and supporting infrastructure. You will leave with a broader understanding of how security controls work together across cloud and AI environments, and how to apply them to real-world engineering tasks.
Newto Training Reviews
What Our Happy Alumni Say About Us
Prerequisites
To get the most from this course, you should have:
- Foundational knowledge of Microsoft Azure, including subscriptions, resource groups, virtual networks, storage accounts, virtual machines, and Azure role-based access control
- A basic understanding of Microsoft Entra ID, authentication, authorisation, multifactor authentication, Conditional Access, and application or service identities
- Knowledge of core security concepts, including least privilege, defence in depth, Zero Trust, encryption, auditing, threat protection, and secure configuration
- Familiarity with cloud networking concepts, including virtual networks, subnets, private endpoints, firewalls, VPNs, and network security rules
- Awareness of common Azure workloads, including storage, SQL databases, virtual machines, containers, App Services, and APIs
- Familiarity with Microsoft security tools such as Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Defender XDR, Microsoft Purview, or Microsoft Security Copilot
- Introductory awareness of AI concepts, including copilots, agents, prompts, models, and data grounding
- Experience navigating the Azure portal and making basic configuration changes in a lab environment
Target audience
This course is designed for security engineers responsible for protecting organisational systems and data across cloud, hybrid, and AI-enabled environments.
It is particularly relevant for professionals who work with identity, infrastructure, networks, applications, data, security operations, DevOps, or AI solutions and need to implement security controls using Microsoft technologies.
You may work closely with architects, administrators, developers, analysts, database specialists, and network professionals. The course is also suitable for learners preparing for security responsibilities that span identity, access, governance, data, networking, compute, application platforms, AI workloads, and cloud security posture management.
Learning Objectives
By the end of this course, you will be able to:
- Secure identity and access across users, applications, and AI agents using Microsoft Entra ID, authentication controls, privileged access, and appropriate identity configurations
- Protect secrets, keys, certificates, storage, databases, and other sensitive resources using security controls designed to reduce exposure and strengthen access management
- Apply governance, policy, compliance, and least-privilege controls across Azure using Azure Policy, role-based access control, resource controls, and security recommendations
- Secure network access to Azure resources and services through segmentation, traffic inspection, private connectivity, firewalls, and other network security controls
- Assess and protect AI workloads, agents, identities, data access paths, gateways, guardrails, and supporting infrastructure
- Secure virtual machines, hybrid servers, containers, application platforms, APIs, and other cloud workloads
- Manage and monitor security posture across Azure, hybrid, and multicloud environments using Microsoft Defender for Cloud and related security capabilities
- Configure foundational security operations capabilities using Microsoft Sentinel and Microsoft Security Copilot
Implement end-to-end security controls for cloud and AI workloads Course Content
Securing access with Microsoft Entra ID
Explore how identity security provides a foundation for protecting cloud and AI workloads. You will examine authentication methods, Conditional Access, privileged access, application registration, and application identities.
Key topics include:
- Managing and implementing authentication methods
- Configuring privileged identity management
- Enforcing multifactor authentication with Conditional Access
- Securing application and service identities
- Authenticating API plugins for declarative agents with secured APIs
Protecting secrets and keys with Azure Key Vault
Learn how to protect sensitive credentials and cryptographic assets used by cloud workloads. You will explore secure access, secrets management, certificates, managed identities, and workload protection.
Key topics include:
- Configuring and securing Azure Key Vault
- Managing keys and secrets
- Managing certificates and monitoring key vault activity
- Using managed identities to access protected resources
- Protecting Azure Key Vault with Microsoft Defender for Cloud
Implementing governance and security controls
Discover how governance and least-privilege principles can help maintain secure and compliant cloud environments.
Key topics include:
- Enforcing governance with Azure Policy and resource locks
- Managing role-based access control assignments
- Using access reviews to support appropriate access
- Configuring security controls and remediating recommendations
- Evaluating regulatory compliance
- Protecting backup data with Azure security features
- Implementing security controls through infrastructure as code
Securing storage, databases, and networking
Learn how to protect data services and control network access to cloud resources.
Key topics include:
- Managing access and network security for Azure Storage
- Configuring firewalls, private endpoints, and shared access signatures
- Using Microsoft Defender for Storage
- Securing Azure SQL Database
- Configuring SQL auditing and Microsoft Defender for SQL
- Exploring data masking and ledger capabilities
- Segmenting and isolating workloads
- Centralising traffic inspection with Azure Firewall
- Securing remote and hybrid connectivity
- Reducing public network exposure for platform services
Securing servers, virtual machines, and hybrid infrastructure
Explore security controls for Azure virtual machines and hybrid servers.
Key topics include:
- Implementing disk encryption
- Configuring Trusted Launch security features
- Using Azure Bastion for secure access
- Managing security for Azure Arc-enabled hybrid servers
- Implementing Microsoft Defender for Servers
- Enforcing just-in-time virtual machine access
- Applying virtual machine security configuration controls
- Exploring agentless security capabilities
Implementing security for AI workloads
Examine the emerging security challenges associated with AI applications and autonomous agents. You will explore how identity, data protection, platform guardrails, gateways, and workload protection can work together to reduce AI security risks.
Key topics include:
- Securing Microsoft Entra Agent Identity
- Analysing AI identity risks with Microsoft Defender XDR
- Protecting Copilot Studio agents
- Configuring AI gateway security in Microsoft Foundry
- Configuring and managing AI guardrails
- Protecting AI workloads with Microsoft Defender for Cloud
- Enabling workload protection for AI services
- Managing agents with Microsoft Agent 365
- Identifying AI data risks with Microsoft Purview Data Security Posture Management
Securing containers and application platforms
Learn how to apply security controls across modern application platforms, containers, APIs, and web services.
Key topics include:
- Detecting container risks with Microsoft Defender for Containers
- Securing Azure Kubernetes Service
- Protecting Azure Container Registry, Container Instances, and Container Apps
- Securing Azure Functions and Logic Apps
- Implementing security controls for Azure App Services
- Using web application firewall capabilities
- Securing API back ends with Azure API Management
Managing cloud security posture
Develop the skills to identify risks, improve security posture, and manage protection across cloud, hybrid, and multicloud environments.
Key topics include:
- Connecting hybrid and multicloud environments to Microsoft Defender for Cloud
- Identifying risks using cloud security posture management
- Discovering unprotected assets and vulnerabilities
- Exploring external attack surface management
- Evaluating regulatory compliance
- Enabling and configuring workload protection plans
- Managing vulnerability settings for Azure virtual machines
- Using secure score, recommendations, secret scanning, and governance controls
Collecting and managing security events with Microsoft Sentinel
Explore foundational security operations capabilities using Microsoft Sentinel.
Key topics include:
- Creating and managing Microsoft Sentinel workspaces
- Managing security content
- Connecting Microsoft and external data sources
- Collecting syslog, Common Event Format, and Windows host data
- Implementing automation rules and playbooks
- Managing data storage
- Querying and auditing collected logs
Implementing Microsoft Security Copilot
Discover how Microsoft Security Copilot can support security operations through configured workspaces, plugins, agents, and appropriate access controls.
Key topics include:
- Understanding Microsoft Security Copilot capabilities
- Configuring Security Copilot workspaces
- Managing plugins and agents
- Understanding the Security Compute Unit consumption model
- Managing relevant roles and access
Exams and assessments
The course includes knowledge check questions throughout the learning experience to help reinforce understanding and identify areas that may need further review.
The course supports preparation for the SC-500 certification exam. The associated study areas cover managing identity, access, and governance; securing storage, databases, and networking; securing compute; and managing and monitoring security posture.
Knowledge checks, classroom discussion, practical labs, and instructor guidance provide opportunities to test and apply your understanding throughout the course.
Hands-on learning
This course combines instructor-led learning with practical exercises designed to help you apply security concepts in a lab environment.
Hands-on activities include opportunities to:
- Configure privileged identity management and Conditional Access
- Deploy and secure Azure Key Vault
- Configure Azure Policy and role-based access control
- Secure Azure Storage and Azure SQL Database
- Configure network security controls
- Secure Azure virtual machines and onboard them to Microsoft Defender for Servers
- Identify AI data risks and secure AI agent identities
- Configure AI gateway and Microsoft Foundry security controls
- Monitor AI security with Microsoft Defender for Cloud
- Secure container workloads, App Services, and API Management
- Explore cloud security posture management
- Configure Microsoft Sentinel data collection and automation
- Configure and use Microsoft Security Copilot
Implement end-to-end security controls for cloud and AI workloads Dates
Next 2 available training dates for this course
Advance Your Career with Implement end-to-end security controls for cloud and AI workloads
Gain the skills you need to succeed. Enrol in Implement end-to-end security controls for cloud and AI workloads with Newto Training today.