Microsoft Cloud and AI Security Engineer (SC-500)
A free, self-paced 20 module training curriculum for Microsoft Cloud and AI Security Engineer (SC-500), built for security engineers protecting cloud and AI workloads end to end. Completing every module issues a printable 20.0 contact hour certificate from TECHLEAD 187 LLC.
- 20 modules
- 20.0 contact hours
- 4 domains
- Self-paced
- Free to use
Domains covered
- Identity & Governance: 4 modules
- Data & Networking: 6 modules
- Compute & AI: 5 modules
- Posture & Monitoring: 5 modules
Module syllabus
- 1.1 Entra Access Security
Implementing Privileged Identity Management, Conditional Access policies, and authentication methods including MFA and passwordless. - 1.2 Application Identity & Managed Identities
Configuring identity for enterprise applications and app registrations, managing OAuth permission grants and consent settings, and managed identities for Azure resources. - 1.3 Key Vault Security
Deploying and configuring Key Vault settings, access, and firewall, managing keys, secrets, and certificates, secret scanning with Defender CSPM, and Defender for Key Vault. - 1.4 Governance & RBAC Hygiene
Enforcing security with Azure Policy and Defender for Cloud compliance standards, resource locks, built-in and custom roles, remediating overprivileged RBAC, backup protection, and IaC controls. - 2.1 Storage Account Security
Implementing storage account security, Storage firewall rules, Defender for Storage threat protection, and access policy management. - 2.2 Database Security
Implementing platform-level security in Azure SQL, database auditing for SQL Database and Managed Instance, and Defender for Databases across Azure database services. - 2.3 Network Segmentation
Managing NSGs and application security groups, network access policies with Azure Virtual Network Manager, and evaluating effective security rules with Network Watcher. - 2.4 Hybrid & Remote Connectivity Security
Securing Azure Virtual WAN, VPN connections, and implementing Microsoft Entra Private Access for identity-centric private connectivity. - 2.5 Private Access to PaaS
Configuring Azure private endpoints to secure access to PaaS resources and Private Link services to secure access to network resources. - 2.6 Azure Firewall
Implementing and configuring Azure Firewall: policies, rule collections, threat intelligence, and TLS inspection across SKU tiers. - 3.1 AI Data Security & Agent Identity
Finding SharePoint data overexposure and Copilot risks with Purview DSPM, protecting Copilot Studio agents, and governing Microsoft Entra Agent ID with Conditional Access and blast-radius analysis. - 3.2 AI Platform Security
Deploying AI Gateway in API Management for Microsoft Foundry, enabling Defender for AI Services, configuring Foundry agent guardrails, and the Data and AI security dashboard. - 3.3 Server & VM Security
Disk encryption, Bastion, JIT access, Azure Arc for hybrid servers, Defender for Servers with EDR and agentless scanning, VM security features, and Machine Configuration enforcement. - 3.4 Container Security
Detecting misconfigurations and runtime risks with Defender for Containers, and security controls for AKS, Container Registry, Container Instances, and Container Apps. - 3.5 App Platform Security
Security controls for Azure Functions, Logic Apps, and App Service, Web Application Firewall, and back-end API protection with API Management policies. - 4.1 Defender CSPM & Compliance
Identifying risks with Defender CSPM, evaluating compliance against security frameworks, and enabling workload protection plans in Defender for Cloud. - 4.2 Multicloud & Exposure Management
Connecting AWS and GCP environments to Defender for Cloud, Defender Vulnerability Management for Azure VMs, and Defender External Attack Surface Management. - 4.3 Sentinel Data Collection
Sentinel workspaces and roles, content hub solutions, data connectors, syslog and CEF collection, Windows Security events via DCRs and WEF, custom tables, retention, and Purview Audit. - 4.4 Sentinel Automation
Implementing automation rules and playbooks in Microsoft Sentinel for triage, enrichment, and response at scale. - 4.5 Microsoft Security Copilot
Configuring Security Copilot workspaces, permissions and roles, plugins, and Microsoft and Security Store agents.
What each module includes
An executive lesson briefing with five key concepts and official vendor documentation references, a scenario based knowledge check scored for mastery, an applied scenario evaluation, and supplemental verified videos plus official free hands on labs where available.
Start this curriculumOther curricula
Published by TECHLEAD 187 LLC. Training certificates evidence completed instruction and contact hours; they are not vendor certifications and do not by themselves satisfy technical compliance requirements. Not affiliated with or endorsed by Google, Amazon Web Services, Microsoft, ISC2, Anthropic, or any U.S. government agency.