Implement end‑to‑end security controls for cloud and AI workloads| Microsoft M-SC500 Skip to main Content

Implement end-to-end security controls for cloud and AI workloads

  • Course Code M-SC500
  • Duration 4 days

Public Classroom Price

$1,510.00

Request Group Training Add to Cart

Course Delivery

This course is available in the following formats:

  • Company Event

    Event at company

  • Public Classroom

    Traditional Classroom Learning

  • Virtual Learning

    Learning that is virtual

Request this course in a different delivery format.

Course Overview

Top

Learn to secure cloud and AI workloads by implementing identity, compliance, threat protection, and governance controls across Microsoft security solutions.

 

This course prepares you to design, implement, and manage end-to-end security controls across Microsoft Azure and Microsoft 365 environments — including the emerging landscape of AI workloads and autonomous agents. Through a combination of instructor-led sessions and hands-on labs, you build practical skills in identity security, cloud infrastructure protection, threat detection, and posture management.

 

Updated August 2026

Course Schedule

Top
    • Delivery Format: Virtual Learning
    • Date: 18-21 October, 2026 | 9:00 AM to 5:00 PM
    • Location: Virtual (Arab Stand)
    • Language: English

    $1,510.00

    • Delivery Format: Public Classroom
    • Date: 18-21 October, 2026 | 9:00 AM to 5:00 PM
    • Location: Cairo-Sheraton (Egypt Stan)
    • Language: English
    • Delivery Format: Virtual Learning
    • Date: 16-19 November, 2026 | 8:00 AM to 4:00 PM
    • Location: Virtual (Arab Stand)
    • Language: English

    $1,510.00

    • Delivery Format: Virtual Learning
    • Date: 15-18 February, 2027 | 9:00 AM to 5:00 PM
    • Location: Virtual (Arab Stand)
    • Language: English

    $1,510.00

    • Delivery Format: Public Classroom
    • Date: 15-18 February, 2027 | 9:00 AM to 5:00 PM
    • Location: GK Riyadh (Arab Stand)
    • Language: English

Target Audience

Top

As a candidate for this course, you’re a security engineer who protects organizational systems and data across cloud and hybrid environments by implementing comprehensive security controls that prevent unauthorized access and mitigate risks proactively. This role spans multiple security domains including identity, network, application, data, and compute. This role also ensures that platforms, data, identities, and infrastructure used by AI workloads are securely implemented and monitored. You work closely with architects, administrators, engineers, analysts, and developers responsible for Azure, Microsoft 365, identity and access, information protection, security operations, devops, application development, database platforms, and networks. You should have practical experience in administration of Microsoft Azure and hybrid environments, including compute, network, and storage. You should have strong familiarity with Microsoft Entra ID and familiarity with Microsoft 365 administration.

 

Your responsibilities for this role include:

- Securing access to resources by using Microsoft Entra ID and Azure Key Vault

- Enforcing security and regulatory compliance

- Securing storage, databases, and networking

- Securing compute

- Securing AI solutions

- Managing and monitoring security posture

Course Objectives

Top

After this course participants should be able to:

  • Implement identity and access security controls using Microsoft Entra ID and Azure Key Vault.
  • Design and manage end-to-end security controls across Microsoft Azure and Microsoft 365 environments.
  • Enforce security governance and regulatory compliance requirements.
  • Secure networking, storage, databases, and compute resources in Azure.
  • Protect AI workloads, identities, data, and supporting infrastructure.
  • Implement threat detection and security monitoring solutions.
  • Manage and improve the security posture of cloud and hybrid environments.
  • Apply Microsoft security technologies to protect cloud, hybrid, and multi-cloud workloads.

Course Content

Top

Module 1: Secure access to resources by using Microsoft Entra

  • Manage and implement authentication methods in Microsoft Entra ID
  • Implement and configure Privileged Identity Management (PIM)
  • Authenticate your API plugin for declarative agents with secured APIs

Module 2: Secure Azure Key Vault with defense in depth for the cloud and AI workloads

  • Configure and secure Azure Key Vault
  • Manage keys and secrets in Azure Key Vault
  • Manage certificates and monitor Azure Key Vault
  • Protect Azure Key Vault with Microsoft Defender for Cloud

Module 3: Enforce security governance and regulatory compliance

  • Enforce governance with Azure Policy and resource locks
  • Configure security controls and remediate recommendations in Defender for Cloud
  • Evaluate regulatory compliance in Defender for Cloud
  • Manage and right-size RBAC role assignments for least privilege
  • Protect backup data with Azure Backup security features
  • Implement security controls in infrastructure as code

Module 4: Implement security for Azure Storage for the cloud and AI security engineer

  • Describe Azure storage services
  • Implement security and manage access for Azure Storage
  • Configure network security for Azure Storage
  • Implement Microsoft Defender for Storage

Module 5: Implement security for Azure SQL databases

  • Configure platform-level security for Azure SQL
  • Configure auditing for Azure SQL Database and SQL Managed Instance
  • Implement Microsoft Defender for Databases

Module 6: Implement network security controls in Azure

  • Segment and isolate Azure workloads using network security controls
  • Centralize and enforce traffic inspection using Azure Firewall
  • Secure remote and hybrid connectivity using VPN gateways and Microsoft Entra Private Access
  • Eliminate public network exposure of Azure PaaS services

Module 7: Implement security for AI

  • Secure access for Microsoft Entra Agent Identity
  • Analyze AI identity risks using Microsoft Defender XDR
  • Enable real-time protection for Copilot Studio agents
  • Configure AI Gateway security in Microsoft Foundry
  • Configure and manage guardrails in Microsoft Foundry
  • Protect AI workloads with Microsoft Defender for Cloud
  • Enable Defender for AI Services workload protection in Microsoft Defender for Cloud
  • Manage agents using Microsoft Agent 365
  • Identify AI data risks using Microsoft Purview Data Security Posture Management

Module 8: Implement security for servers and virtual machines

  • Implement disk encryption for Azure virtual machines
  • Configure trusted launch security features for Azure virtual machines
  • Plan and implement Azure Bastion
  • Manage security for Arc-enabled hybrid servers
  • Implement Microsoft Defender for Servers
  • Enable and enforce just-in-time VM access
  • Enforce VM security configuration with Azure Machine Configuration

Module 9: Secure Azure application platform services for the cloud and AI security engineer

  • Detect container risks using Microsoft Defender for Containers
  • Implement security controls for Azure Kubernetes Service
  • Implement security controls for Azure Container Registry, Container Instances, and Container Apps
  • Implement security controls for Azure Function apps and Logic apps
  • Implement security controls for Azure App Services and Web Application Firewall
  • Implement API backend security using Azure API Management

Module 10: Manage security posture by using Microsoft Defender for Cloud

  • Connect hybrid and multicloud environments to Microsoft Defender for Cloud
  • Identify security risks by using Cloud Security Posture Management
  • Discover unprotected assets and vulnerabilities by using Microsoft Defender External Attack Surface Management
  • Evaluate regulatory compliance in Defender for Cloud
  • Enable and configure workload protection plans in Microsoft Defender for Cloud
  • Configure Microsoft Defender Vulnerability Management settings for Azure VMs

Module 11: Implement activity and event collection in Microsoft Sentinel

  • Create and manage Microsoft Sentinel workspaces
  • Manage content in Microsoft Sentinel
  • Connect Microsoft services to Microsoft Sentinel
  • Connect syslog data sources to Microsoft Sentinel
  • Connect Common Event Format logs to Microsoft Sentinel
  • Connect Windows hosts to Microsoft Sentinel
  • Implement automation rules and playbooks in Microsoft Sentinel
  • Manage data storage and query audit logs in Microsoft Sentinel

Module 12: Deploy and operate Microsoft Security Copilot

  • Describe Microsoft Security Copilot
  • Configure workspaces for Microsoft Security Copilot
  • Manage plugins and agents in Microsoft Security Copilot

Course Prerequisites

Top

Participants should have:

  • a basic understanding of cloud security concepts, identity and access management, networking, and Microsoft Azure administration.
  • practical experience in administration of Microsoft Azure and hybrid environments, including compute, network, and storage.
  • strong familiarity with Microsoft Entra ID and familiarity with Microsoft 365 administration.
  • familiarity with Microsoft security technologies.

Test Certification

Top
  • SC-500 - Implement end‑to‑end security controls for cloud and AI workloads

Follow on Courses

Top

 

The following are recommended for further study:

Further Information

Top