Microsoft Cloud and AI Security Engineer (SC-500)

A free, self-paced 20 module training curriculum for Microsoft Cloud and AI Security Engineer (SC-500), built for security engineers protecting cloud and AI workloads end to end. Completing every module issues a printable 20.0 contact hour certificate from TECHLEAD 187 LLC.

Domains covered

Module syllabus

  1. 1.1 Entra Access Security
    Implementing Privileged Identity Management, Conditional Access policies, and authentication methods including MFA and passwordless.
  2. 1.2 Application Identity & Managed Identities
    Configuring identity for enterprise applications and app registrations, managing OAuth permission grants and consent settings, and managed identities for Azure resources.
  3. 1.3 Key Vault Security
    Deploying and configuring Key Vault settings, access, and firewall, managing keys, secrets, and certificates, secret scanning with Defender CSPM, and Defender for Key Vault.
  4. 1.4 Governance & RBAC Hygiene
    Enforcing security with Azure Policy and Defender for Cloud compliance standards, resource locks, built-in and custom roles, remediating overprivileged RBAC, backup protection, and IaC controls.
  5. 2.1 Storage Account Security
    Implementing storage account security, Storage firewall rules, Defender for Storage threat protection, and access policy management.
  6. 2.2 Database Security
    Implementing platform-level security in Azure SQL, database auditing for SQL Database and Managed Instance, and Defender for Databases across Azure database services.
  7. 2.3 Network Segmentation
    Managing NSGs and application security groups, network access policies with Azure Virtual Network Manager, and evaluating effective security rules with Network Watcher.
  8. 2.4 Hybrid & Remote Connectivity Security
    Securing Azure Virtual WAN, VPN connections, and implementing Microsoft Entra Private Access for identity-centric private connectivity.
  9. 2.5 Private Access to PaaS
    Configuring Azure private endpoints to secure access to PaaS resources and Private Link services to secure access to network resources.
  10. 2.6 Azure Firewall
    Implementing and configuring Azure Firewall: policies, rule collections, threat intelligence, and TLS inspection across SKU tiers.
  11. 3.1 AI Data Security & Agent Identity
    Finding SharePoint data overexposure and Copilot risks with Purview DSPM, protecting Copilot Studio agents, and governing Microsoft Entra Agent ID with Conditional Access and blast-radius analysis.
  12. 3.2 AI Platform Security
    Deploying AI Gateway in API Management for Microsoft Foundry, enabling Defender for AI Services, configuring Foundry agent guardrails, and the Data and AI security dashboard.
  13. 3.3 Server & VM Security
    Disk encryption, Bastion, JIT access, Azure Arc for hybrid servers, Defender for Servers with EDR and agentless scanning, VM security features, and Machine Configuration enforcement.
  14. 3.4 Container Security
    Detecting misconfigurations and runtime risks with Defender for Containers, and security controls for AKS, Container Registry, Container Instances, and Container Apps.
  15. 3.5 App Platform Security
    Security controls for Azure Functions, Logic Apps, and App Service, Web Application Firewall, and back-end API protection with API Management policies.
  16. 4.1 Defender CSPM & Compliance
    Identifying risks with Defender CSPM, evaluating compliance against security frameworks, and enabling workload protection plans in Defender for Cloud.
  17. 4.2 Multicloud & Exposure Management
    Connecting AWS and GCP environments to Defender for Cloud, Defender Vulnerability Management for Azure VMs, and Defender External Attack Surface Management.
  18. 4.3 Sentinel Data Collection
    Sentinel workspaces and roles, content hub solutions, data connectors, syslog and CEF collection, Windows Security events via DCRs and WEF, custom tables, retention, and Purview Audit.
  19. 4.4 Sentinel Automation
    Implementing automation rules and playbooks in Microsoft Sentinel for triage, enrichment, and response at scale.
  20. 4.5 Microsoft Security Copilot
    Configuring Security Copilot workspaces, permissions and roles, plugins, and Microsoft and Security Store agents.

What each module includes

An executive lesson briefing with five key concepts and official vendor documentation references, a scenario based knowledge check scored for mastery, an applied scenario evaluation, and supplemental verified videos plus official free hands on labs where available.

Start this curriculum

Other curricula

Published by TECHLEAD 187 LLC. Training certificates evidence completed instruction and contact hours; they are not vendor certifications and do not by themselves satisfy technical compliance requirements. Not affiliated with or endorsed by Google, Amazon Web Services, Microsoft, ISC2, Anthropic, or any U.S. government agency.