SC-500 : Microsoft Certified Cloud and AI Security Engineer Associate

  • Duration: 4 days
Categories:

SC-500 Microsoft Cloud & AI Security Engineer Practice TestsOverview

This course prepares participants to design, implement, and manage end-to-end security controls across Microsoft Azure and Microsoft 365 environments, including modern AI workloads and autonomous agents.

Through a combination of instructor-led training and hands-on practical exercises, participants will develop skills in identity security, cloud infrastructure protection, data and network security, threat detection, security posture management, and AI security.

The course is designed for security professionals responsible for implementing security controls across cloud, hybrid, and multi-cloud environments using Microsoft security technologies. Participants will also learn how to deploy and manage Microsoft Security Copilot and integrate AI capabilities into modern security operations.


What You’ll Learn

  • Design and implement end-to-end security controls across Microsoft Azure and Microsoft 365
  • Secure identities and access using Microsoft Entra ID, Conditional Access, PIM, and Zero Trust principles
  • Secure keys, secrets, and certificates using Azure Key Vault
  • Implement security governance and regulatory compliance using Azure Policy, RBAC, resource locks, and Microsoft Defender for Cloud
  • Secure Azure Storage and Azure SQL Database using encryption, identity-based access, and threat protection
  • Implement network security using NSGs, Azure Firewall, Private Link, Private Endpoints, and Microsoft Entra Private Access
  • Implement layered security controls for AI workloads, identities, data, and runtime environments
  • Secure Azure virtual machines and hybrid infrastructure using Trusted Launch, Azure Bastion, Just-in-Time VM access, and Microsoft Defender for Servers
  • Secure Azure application platform services including AKS, ACR, App Service, Functions, Logic Apps, API Management, and WAF
  • Manage cloud security posture using Microsoft Defender for Cloud, CSPM, CWPP, EASM, and Defender Vulnerability Management
  • Configure security monitoring, event collection, automated response, and compliance reporting using Microsoft Sentinel
  • Deploy and manage Microsoft Security Copilot for AI-powered security operations
  • Apply security best practices across cloud, hybrid, and multi-cloud environments
  • Detect threats, reduce security risks, and strengthen organizational security posture

Who Should Attend

This course is designed for:

  • Security Engineers
  • Cloud Security Engineers
  • Cybersecurity Professionals
  • Security Administrators
  • Security Architects
  • Cloud Engineers
  • Security Operations Professionals
  • Azure Administrators
  • Microsoft 365 Security Professionals
  • DevSecOps Professionals
  • AI Security Professionals

The course is particularly suitable for security engineers responsible for protecting organizational systems and data across cloud and hybrid environments.

Participants will benefit from practical experience with Azure compute, networking, storage, Microsoft Entra ID, Microsoft 365, security operations, and AI workloads.


Prerequisites

Before attending this course, participants should have:

  • Familiarity with Microsoft Entra ID concepts, including users, groups, and directory roles
  • Understanding of Azure Role-Based Access Control (RBAC)
  • Understanding of Azure scope hierarchy, including management groups, subscriptions, resource groups, and resources
  • Basic experience navigating the Azure portal and Microsoft Entra admin center
  • Familiarity with Zero Trust security principles
  • Understanding of least-privilege access and assume-breach principles
  • Awareness of Microsoft Entra ID P2 or Microsoft Entra ID Governance licensing requirements
  • Basic understanding of Azure networking, compute, and storage is recommended

Curriculum

Module 01: Secure Access to Resources by Using Microsoft Entra

Learn how to secure identities and control access to Azure and Microsoft resources using Microsoft Entra security capabilities.

Topics include:

  • Microsoft Entra ID
  • Identity and access management
  • Authentication and authorization
  • Conditional Access
  • Privileged Identity Management (PIM)
  • Role-based access
  • Least-privilege access
  • Identity security
  • Zero Trust principles
  • Securing identities used by AI agents and workloads

Module 02: Secure Azure Key Vault with Defense in Depth for Cloud and AI Workloads

Learn how to protect sensitive keys, secrets, and certificates using Azure Key Vault and layered security controls.

Topics include:

  • Azure Key Vault
  • Secure vault configuration
  • Least-privilege access
  • Just-in-time access
  • Key management
  • Secret management
  • Certificate management
  • Key and secret lifecycle management
  • Secret rotation
  • Microsoft Defender for Cloud
  • Detecting exposed credentials
  • Monitoring malicious access patterns
  • Securing AI workload credentials

Module 03: Enforce Security Governance and Regulatory Compliance

Learn how to implement security governance and compliance controls across Azure environments.

Topics include:

  • Azure Policy
  • Resource locks
  • Security standards
  • Microsoft Defender for Cloud recommendations
  • Regulatory compliance
  • RBAC governance
  • Role assignment management
  • Backup protection
  • Ransomware protection
  • Bicep security controls
  • Security validation before production deployment

Module 04: Implement Security for Azure Storage

Learn how to implement defense-in-depth security for Azure Storage and protect data used by cloud and AI workloads.

Topics include:

  • Azure Storage security
  • Storage account protection
  • Microsoft Entra ID managed identities
  • Access control
  • Stored access policies
  • Storage firewall rules
  • Private endpoints
  • Network access controls
  • Microsoft Defender for Storage
  • Threat detection
  • Malicious file detection
  • Protecting AI agent credentials

Module 05: Implement Security for Azure SQL Databases

Learn how to secure Azure SQL Database and SQL Managed Instance using identity, network, encryption, and threat protection controls.

Topics include:

  • Azure SQL Database security
  • SQL Managed Instance security
  • Microsoft Entra authentication
  • Managed identities
  • Private endpoints
  • Data encryption
  • Access controls
  • Database auditing
  • Compliance logging
  • Microsoft Defender for Databases
  • SQL injection detection
  • Anomalous access detection
  • Vulnerability protection

Module 06: Implement Network Security Controls in Azure

Learn how to design and implement defense-in-depth network security controls across Azure environments.

Topics include:

  • Network Security Groups (NSGs)
  • Application Security Groups (ASGs)
  • Azure Virtual Network Manager
  • Network segmentation
  • Least-privilege network access
  • Azure Firewall
  • Centralized traffic inspection
  • Remote connectivity security
  • Hybrid connectivity
  • Microsoft Entra Private Access
  • Zero Trust application-level access
  • Azure Private Link
  • Private endpoints
  • Protecting PaaS and AI services from public exposure

Module 07: Implement Security for AI

Learn how to identify and address security risks introduced by modern AI workloads and autonomous agents.

Topics include:

  • AI security fundamentals
  • AI workload security
  • AI platform protection
  • AI identity security
  • AI data security
  • Runtime security
  • AI attack surfaces
  • Layered AI security controls
  • Microsoft security capabilities for AI workloads
  • Securing AI applications and agents

Module 08: Implement Security for Servers and Virtual Machines

Learn how to protect Azure virtual machines and hybrid servers using layered security controls.

Topics include:

  • Azure virtual machine security
  • Azure Arc-enabled servers
  • Disk encryption
  • Encryption at host
  • Customer-managed keys
  • Confidential disk encryption
  • Trusted Launch
  • Secure Boot
  • Virtual TPM (vTPM)
  • Integrity monitoring
  • Azure Bastion
  • Securing RDP and SSH access
  • Microsoft Defender for Servers
  • Vulnerability scanning
  • Endpoint detection
  • Agentless machine scanning
  • File Integrity Monitoring
  • Just-in-Time VM access
  • Azure Machine Configuration
  • OS security baselines

Module 09: Secure Azure Application Platform Services

Learn how to implement security controls across Azure application, container, API, and serverless platforms.

Topics include:

  • Azure Kubernetes Service (AKS)
  • Azure Container Registry (ACR)
  • Microsoft Defender for Containers
  • Container security
  • AKS security baselines
  • Container runtime protection
  • Azure App Service
  • Azure Functions
  • Azure Logic Apps
  • Azure API Management
  • Web Application Firewall (WAF)
  • Application authentication
  • Network access controls
  • Application security policies
  • AI application platform security

Module 10: Manage Security Posture Using Microsoft Defender for Cloud

Learn how to establish and maintain security posture management across hybrid and multi-cloud environments.

Topics include:

  • Microsoft Defender for Cloud
  • Cloud Security Posture Management (CSPM)
  • Cloud Workload Protection Platform (CWPP)
  • Secure Score
  • Attack Path Analysis
  • Cloud Security Explorer
  • Azure security posture management
  • Connecting on-premises environments
  • AWS and GCP integration
  • Microsoft Defender External Attack Surface Management (EASM)
  • Internet-facing asset discovery
  • Regulatory compliance assessment
  • Audit-ready compliance reporting
  • Defender plans for servers, storage, databases, and AI workloads
  • Microsoft Defender Vulnerability Management
  • Vulnerability scanning and remediation

Module 11: Implement Activity and Event Collection in Microsoft Sentinel

Learn how to implement security monitoring and automated response using Microsoft Sentinel.

Topics include:

  • Microsoft Sentinel fundamentals
  • Sentinel workspace configuration
  • Content Hub solutions
  • Azure resource data connectors
  • Windows security events
  • Linux security events
  • Data Collection Rules (DCRs)
  • Security event collection
  • Logic Apps playbooks
  • Automated response workflows
  • Security monitoring
  • Data retention
  • Audit log access
  • Compliance requirements

Module 12: Deploy and Operate Microsoft Security Copilot

Learn how to deploy, configure, govern, and operate Microsoft Security Copilot for AI-powered security operations.

Topics include:

  • Microsoft Security Copilot fundamentals
  • Natural language security prompts
  • Effective prompt design
  • Security Copilot deployment
  • Workspace planning
  • Security Compute Units
  • Data residency
  • Role assignments
  • Enterprise workspace segmentation
  • Plugin management
  • Microsoft-built plugins
  • Partner-built plugins
  • Agent management
  • Agent lifecycle management
  • Governance and operational management

Course Outcome

Upon successful completion of this course, participants will be able to design, implement, secure, monitor, and manage comprehensive security solutions across Microsoft Azure, Microsoft 365, hybrid, multi-cloud, and AI environments.

Participants will gain practical skills in identity security, cloud governance, data protection, network security, compute security, AI security, security posture management, threat detection, Microsoft Sentinel, and Microsoft Security Copilot, enabling them to implement modern, defense-in-depth security strategies for enterprise environments.