

1. Secure Access to Resources with Microsoft Entra
Controlling who can access which resources and under what conditions is one of the most important tasks in cloud security. A misconfigured authentication policy, an account with excessive permissions that isn’t monitored, or an inadequately secured AI agent can each become the entry point an attacker needs to move laterally through your environment.
In this module, you'll learn the skills needed to close these gaps. You'll start by designing and deploying secure authentication in Microsoft Entra ID, including configuring multi-factor authentication. Next, you’ll configure policies for conditional access, passwordless options, and self-service password reset for hybrid environments. You’ll then focus on privileged access, where you’ll use Privileged Identity Management (PIM) to implement just-in-time access for Microsoft Entra roles and Azure resources. Just-in-time access eliminates permanent permissions that create unnecessary risks. Finally, you’ll apply these identity and access principles to a modern challenge: securing AI-powered applications and declarative agents that use API plugins to users on behalf of users .
By the end of this module, you will have a practical, multi-layered approach to access security that encompasses securing credentials, governing privileged access, and designing AI applications with identity in mind.
2. Securing Azure Key Vault with a multi-layered defense strategy for cloud and AI workloads
Implement a multi-layered security strategy for Azure Key Vault. In this module, you’ll apply a security-optimized vault configuration, enforce the principle of least privilege with just-in-time activation, manage the entire lifecycle of keys, secrets, and certificates, and use Microsoft Defender for Cloud to detect exposed credentials and malicious access patterns targeting your vaults.
3. Ensuring Security Governance and Regulatory Compliance
Enforce security governance and regulatory compliance across all Azure environments. Configure Azure Policy and resource locks to block non-compliant deployments. Then, manage security standards and implement recommendations in Defender for Cloud, assess your compliance status, manage RBAC role assignments at scale, protect backup data from ransomware and deletion, and integrate security controls into Bicep pipelines before resources go into production.
4. Implementing Security for Azure Storage for the Cloud and AI Security Engineer
Implement a multi-layered security strategy for Azure Storage. In this module, you’ll harden storage accounts against common attack vectors and control access using managed identities from Microsoft Entra ID and stored access policies. You’ll then configure network perimeter controls using firewall rules and private endpoints, and enable Microsoft Defender for Storage to detect threats such as malicious file uploads and compromised credentials from AI agents.
5. Implementing Security Measures for Azure SQL Databases
Implement end-to-end security measures for Azure SQL Database and SQL Managed Instance. Configure Entra ID authentication with managed identity access, deploy private endpoints, and apply encryption and access controls to protect sensitive financial data. Set up compliant audit trails and enable Microsoft Defender for Databases to detect SQL injection, anomalous access, and security vulnerabilities.
6. Implementing Network Security Controls in Azure
Implement multi-layered network security controls in Azure. Segment workloads and enforce least-privilege access using NSGs, ASGs, and Azure Virtual Network Manager. Monitor and control traffic centrally with Azure Firewall. Secure remote and hybrid connections and replace broad VPN access with zero-trust, application-level access using Microsoft Entra Private Access. Prevent public exposure of PaaS and AI services through private endpoints and Azure Private Link.
7. Implementing Security for AI
AI workloads introduce new attack surfaces across the identity, data, and runtime layers that are not fully covered by traditional security controls. In this module, you will implement multi-layered AI security controls across the entire Microsoft security platform.
First, you identify and assess AI data risks using Microsoft Purview Data Security Posture Management (DSPM). Next, you secure agent identities using Microsoft Entra Agent ID and Conditional Access, and analyze the identity blast radius and attack paths for AI in Microsoft Defender XDR. Next, you’ll configure real-time runtime protection for Copilot Studio agents using Microsoft Defender for Cloud Apps and secure AI model traffic using AI Gateway in Microsoft Foundry. Finally, you’ll configure protection measures in Microsoft Foundry, protect AI workloads with Microsoft Defender for Cloud, and manage deployed agents with Microsoft Agent 365.
8. Implementing Security Measures for Servers and Virtual Machines
Implement multi-layered security controls for Azure virtual machines and Arc-enabled hybrid servers. Configure disk encryption options, including host-based encryption with customer-managed keys and confidential disk encryption. Enable Trusted Launch security features—Secure Boot, vTPM, and integrity monitoring—to protect against boot-level threats. Eliminate public RDP and SSH exposure with Azure Bastion. Extend Azure security governance to on-premises and multi-cloud servers using Azure Arc. Deploy Microsoft Defender for Servers for vulnerability scanning, endpoint detection, agentless machine scanning, and file integrity monitoring. Enforce just-in-time access to VMs to eliminate permanently open management ports. Use Azure Machine Configuration to check and enforce operating system security baselines across your entire server infrastructure.
9. Secure Azure Application Platform Services for the Cloud and AI Security Engineer
Implement security controls across all Azure application platform services—from container workloads to the API level. Configure Microsoft Defender for Containers to detect risks in AKS and ACR, enforce AKS security baselines, and harden container registries and runtime environments. Then apply authentication, network access, and policy controls to Azure Function Apps, Logic Apps, App Services, Web Application Firewall, and Azure API Management.
10. Managing Security with Microsoft Defender for Cloud
Learn how to use Microsoft Defender for Cloud to establish and maintain a strong security posture across your entire hybrid and multi-cloud environment. First, connect on-premises, AWS, and GCP environments to create a unified view. Next, identify and prioritize security risks using Cloud Security Posture Management (CSPM)—including Secure Score, attack path analysis, and Cloud Security Explorer. Expand this security overview from the outside in with Microsoft Defender External Attack Surface Management (EASM) to detect unknown, internet-connected resources and uncover exploitable vulnerabilities. You’ll assess your organization’s compliance status against regulatory frameworks and generate audit-ready reports. Finally, you’ll activate Cloud Workload Protection Platform (CWPP) plans to protect servers, storage, databases, and AI workloads from active threats. You’ll then configure Microsoft Defender Vulnerability Management to scan for and remediate vulnerabilities on Azure VMs.
11. Implementing Activity and Event Logging in Microsoft Sentinel
Create a comprehensive architecture for event collection and response in Microsoft Sentinel. In this module, you’ll set up and secure a Microsoft Sentinel workspace, deploy Content Hub solutions, and connect Azure resource data. Next, you’ll collect Linux and Windows security events using data collection rules and implement automated response workflows with Logic Apps playbooks. In the final step, you’ll manage data retention and access to audit logs to meet compliance requirements.
12. Deploy and Operate Microsoft Security Copilot
In this final module, you’ll establish a solid foundation with Microsoft Security Copilot and move on to enterprise-wide deployment and day-to-day operations. First, you’ll explore the core concepts, how Security Copilot processes natural language prompts, the elements of an effective prompt, and the steps to enable the solution for your organization. Next, you’ll plan and configure workspaces with the appropriate Security Compute Units, data residency settings, and role assignments to meet enterprise segmentation requirements. Finally, you’ll manage access to plugins and oversee the entire lifecycle of both Microsoft and partner agents to ensure the smooth and secure operation of your deployment.
Requirements:
.
This course consists of antraining is led by an instructor who provides live guidance to participants. Theory and practice are taught through live demonstrations and hands-on exercises. The course uses the video conferencing software Zoom.
This intensive training course prepares you for the following certification:
"Microsoft Certified: Cloud and AI Security Engineer Associate (beta)"
Please note that the exam fee is not included in the seminar price. You must register for the exam yourself through an officially accredited Microsoft exam center.
As candidate this course, you are a security engineer who protects corporate systems and data in cloud and hybrid environments by implementing comprehensive security controls that prevent unauthorized access and proactively mitigate risks. This role spans multiple security domains, including identity, network, application, data, and computing environments.
You’ll also ensure that the platforms, data, identities, and infrastructure used by AI workloads are securely implemented and monitored. You developers closely with architects, administrators, engineers, analysts developers responsible for Azure, Microsoft 365, identity and access, information protection, security operations, DevOps, application development, database platforms, and networks.
You should have hands-on experience administering Microsoft Azure and hybrid environments, including compute, networking, and storage. You should be very familiar with Microsoft Entra ID and have knowledge of Microsoft 365 administration. Your responsibilities in this role will include:
Form of learning
Learning form
No filter results
The training is carried out in cooperation with an authorized training partner. This partner collects and processes data under its own responsibility. Please take note of the corresponding privacy policy.
