Microsoft Azure Security Technologies (AZ-500)

A free, self-paced 16 module training curriculum for Microsoft Azure Security Technologies (AZ-500), built for security engineers implementing identity, network, and workload controls on Azure. Completing every module issues a printable 16.0 contact hour certificate from TECHLEAD 187 LLC.

Domains covered

Module syllabus

  1. 1.1 Entra Roles & Privileged Identity Management
    Managing Azure built-in role assignments, custom Azure and Microsoft Entra roles, and Privileged Identity Management settings and assignments for just-in-time elevation.
  2. 1.2 MFA & Conditional Access
    Implementing multi-factor authentication for access to Azure resources and designing Conditional Access policies for cloud resources, including break-glass strategy.
  3. 1.3 Application Access & Managed Identities
    Managing enterprise application access, OAuth permission grants, app registrations, permission scopes and consent, service principals, and managed identities.
  4. 2.1 Virtual Network Security
    Planning and implementing NSGs, ASGs, Azure Virtual Network Manager, user-defined routes, peering and VPN gateways, Virtual WAN secured hubs, ExpressRoute encryption, and Network Watcher monitoring.
  5. 2.2 Private Access to Azure Resources
    Planning and implementing Service Endpoints, Private Endpoints, Private Link services, App Service and Functions network integration, App Service Environments, and SQL Managed Instance network security.
  6. 2.3 TLS & Azure Firewall
    Planning and implementing TLS for applications including App Service and API Management, and managing Azure Firewall, Azure Firewall Manager, and firewall policies.
  7. 2.4 Edge Protection: App Gateway, Front Door, WAF & DDoS
    Planning and implementing Azure Application Gateway, Azure Front Door with CDN, Web Application Firewall, and recommending when to use Azure DDoS Protection.
  8. 3.1 Secure Compute Access & Encryption
    Planning remote VM access with Azure Bastion and just-in-time access, configuring disk encryption (ADE, encryption at host, confidential disk encryption), and securing API Management.
  9. 3.2 Container & Kubernetes Security
    Configuring network isolation, authentication, and monitoring for AKS, security monitoring for Container Instances and Container Apps, and access control for Azure Container Registry.
  10. 3.3 Storage Security
    Configuring storage account access control and key management, Azure Files and Blob access methods, data threat protection (soft delete, versioning, immutable storage), BYOK, and infrastructure double encryption.
  11. 3.4 Azure SQL Security
    Enabling Microsoft Entra database authentication and auditing, planning dynamic data masking, implementing Transparent Data Encryption, and recommending Always Encrypted.
  12. 4.1 Governance with Azure Policy
    Creating, assigning, and interpreting policies and initiatives in Azure Policy, and implementing security controls for backup protection and asset management.
  13. 4.2 Key Vault Security
    Configuring Key Vault network settings and access (vault access policies and Azure RBAC), managing certificates, secrets, and keys, key rotation, and backup and recovery.
  14. 4.3 Security Posture with Defender for Cloud
    Managing Secure Score, Inventory, compliance standards, and custom standards in Microsoft Defender for Cloud, connecting AWS and GCP environments, and using Defender EASM.
  15. 4.4 Workload Protection with Defender for Cloud
    Enabling cloud workload protection plans, configuring Defender for Servers, Databases, and Storage, agentless VM scanning, Defender Vulnerability Management, and DevOps security.
  16. 4.5 Monitoring & Automation with Sentinel
    Managing Defender for Cloud alerts and workflow automation, configuring data collection rules in Azure Monitor, and Microsoft Sentinel data connectors, analytics rules, and automation.

What each module includes

An executive lesson briefing with five key concepts and official vendor documentation references, a scenario based knowledge check scored for mastery, an applied scenario evaluation, and supplemental verified videos plus official free hands on labs where available.

Start this curriculum

Other curricula

Published by TECHLEAD 187 LLC. Training certificates evidence completed instruction and contact hours; they are not vendor certifications and do not by themselves satisfy technical compliance requirements. Not affiliated with or endorsed by Google, Amazon Web Services, Microsoft, ISC2, Anthropic, or any U.S. government agency.