CLS
Cybersecurity

SC-500T00-A: Implement end‑to‑end security controls for cloud and AI workloads

This Course is suitable for professionals responsible for securing cloud, hybrid environments, application environments, AI environments.

Total Duration
32 Hours
Level
Intermediate
Category
Cybersecurity
Partner
Microsoft
About this course

About this course

This course prepares you to design, implement, and manage end-to-end security controls across Microsoft Azure and Microsoft 365 environments — including the emerging landscape of AI workloads and autonomous agents. Through a combination of instructor-led sessions and hands-on labs, you build practical skills in identity security, cloud infrastructure protection, threat detection, and posture management. This course is intended for security engineers who are responsible for planning and implementing security controls across cloud, hybrid, and multi-cloud environments using Microsoft security technologies. 

Target Audience

Azure Security Administrators tasked with managing security controls, identities, networks, and protection of workloads
Cloud Administrators aiming to improve their knowledge of Azure security and governance.
Cybersecurity Specialists charged with securing cloud environment, applications, data, and AI workloads.
AI Security Specialists tasked with securing AI workloads, agents, APIs, and AI data.
IT Specialists who prepare to work with Microsoft cloud security and AI security technologies.

Prerequisites

Familiarity with Microsoft Entra ID concepts, including users, groups, and directory roles
Basic experience navigating the Azure portal and the Microsoft Entra admin center

Course Outline

  • Manage and Implement Authentication Methods in Microsoft Entra ID
  • Implement and Configure Privileged Identity Management (PIM)
  • Authenticate Your API Plugin for Declarative Agents with Secured APIs
  • Configure and Secure Azure Key Vault
  • Manage Keys and Secrets in Azure Key Vault
  • Manage Certificates and Monitor Azure Key Vault
  • Protect Azure Key Vault with Microsoft Defender for Cloud
  • Enforce Governance with Azure Policy and Resource Locks
  • Configure Security Controls and Remediate Recommendations in Defender for Cloud
  • Evaluate Regulatory Compliance in Defender for Cloud
  • Manage and Right-Size RBAC Role Assignments for Least Privilege
  • Protect Backup Data with Azure Backup Security Features
  • Implement Security Controls in Infrastructure as Code
  • Describe Azure Storage Services
  • Implement Security and Manage Access for Azure Storage
  • Configure Network Security for Azure Storage
  • Implement Microsoft Defender for Storage
  • Configure Platform-Level Security for Azure SQL
  • Configure Auditing for Azure SQL Database and SQL Managed Instance
  • Implement Microsoft Defender for Databases
  • Segment and Isolate Azure Workloads Using Network Security Controls
  • Centralize and Enforce Traffic Inspection Using Azure Firewall
  • Secure Remote and Hybrid Connectivity Using VPN Gateways and Microsoft Entra Private Access
  • Eliminate Public Network Exposure of Azure PaaS Services
  • Secure Access for Microsoft Entra Agent Identity
  • Analyze AI Identity Risks Using Microsoft Defender XDR
  • Enable Real-Time Protection for Copilot Studio Agents
  • Configure AI Gateway Security in Microsoft Foundry
  • Configure and Manage Guardrails in Microsoft Foundry
  • Protect AI Workloads with Microsoft Defender for Cloud
  • Enable Defender for AI Services Workload Protection in Microsoft Defender for Cloud
  • Manage Agents Using Microsoft Agent 365
  • Identify AI Data Risks Using Microsoft Purview Data Security Posture Management
  • Implement Disk Encryption for Azure Virtual Machines
  • Configure Trusted Launch Security Features for Azure Virtual Machines
  • Plan and Implement Azure Bastion
  • Manage Security for Arc-Enabled Hybrid Servers
  • Implement Microsoft Defender for Servers
  • Enable and Enforce Just-in-Time VM Access
  • Enforce VM Security Configuration with Azure Machine Configuration
  • Detect Container Risks Using Microsoft Defender for Containers
  • Implement Security Controls for Azure Kubernetes Service
  • Implement Security Controls for Azure Container Registry, Container Instances, and Container Apps
  • Implement Security Controls for Azure Function Apps and Logic Apps
  • Implement Security Controls for Azure App Services and Web Application Firewall
  • Implement API Backend Security Using Azure API Management
  • Connect Hybrid and Multi cloud Environments to Microsoft Defender for Cloud
  • Identify Security Risks by Using Cloud Security Posture Management
  • Discover Unprotected Assets and Vulnerabilities by Using Microsoft Defender External Attack Surface Management
  • Evaluate Regulatory Compliance in Defender for Cloud
  • Enable and Configure Workload Protection Plans in Microsoft Defender for Cloud
  • Configure Microsoft Defender Vulnerability Management Settings for Azure VMs
  • Create and Manage Microsoft Sentinel Workspaces
  • Manage Content in Microsoft Sentinel
  • Connect Microsoft Services to Microsoft Sentinel
  • Connect Syslog Data Sources to Microsoft Sentinel
  • Connect Common Event Format Logs to Microsoft Sentinel
  • Connect Windows Hosts to Microsoft Sentinel
  • Implement Automation Rules and Playbooks in Microsoft Sentinel
  • Manage Data Storage and Query Audit Logs in Microsoft Sentinel
  • Describe Microsoft Security Copilot
  • Configure Workspaces for Microsoft Security Copilot
  • Manage Plugins and Agents in Microsoft Security Copilot
Learning outcomes

What you'll learn

Configure multifactor authentication in Microsoft Entra ID
Implement password less authentication in Microsoft Entra ID
Integrate an API plugin with an API secured with a key
Implement just-in-time access for Azure roles and resources
Create and deploy custom policy definitions
Configure Defender for Cloud and manage security standards
Understand compliance standards and controls in Defender for Cloud
Configure Multi-User Authorization and RBAC for backup
Discover AI agents in the Microsoft Defender portal
Configure virtual network and IP rules
Explore Copilot Studio AI agent protection
Create and configure AI Gateway
Connect the Microsoft Entra connector
Connect the Microsoft Entra ID Protection connector
Assign workspaces for integrated agents
Acquire and configure partner agents from Security Store

Skills you'll learn

17 skills
Microsoft Entra Authentication
API and Agent Authentication
Azure Key Vault Security
Azure Policy
Least Privilege
Defender for Cloud
Azure Backup Security
Infrastructure as Code Security
Azure Storage Security
Azure Network Security

Certificate

  • Attendance Certificate from CLS Learning Solutions
  • This course enables you to pass the SC-500T00-A Certification Exam


SC-500T00-A: Implement end‑to‑end security controls for cloud and AI workloads

Potential Career Paths

Cloud Security Engineer
Azure Security Administrator
Cybersecurity Analyst
AI Security Engineer
Security & Compliance Engineer
IT Professional