Become a Microsoft Certified: Identity and Access Administrator Associate (SC-300)
Organise digital access according to roles and actual needs. Connect identities, permissions and services to improve control of configurations. Develop the knowledge to administer access and prepare discussions with security teams.
- Duration
- 5 days 35 hours
- Code
- SC-300-BIS Code
- Certification
- Microsoft Certified: Identity and Access Administrator Associate Certification
Accredited training for the Microsoft Certified: Identity and Access Administrator Associate certification.
Presentation
An identity and access administrator manages the systems and processes used to identify users and control access to system or network resources. This role is crucial to an organisation's IT security.
This course teaches you to design, implement and manage identity and access management systems with Microsoft Azure AD. Your first day covers the fundamentals needed to understand security, identity and compliance concepts.
Over the following 4 days, you will examine identity and access management processes for enterprise applications in detail. You will explore methods for providing seamless experiences and self-service management capabilities to all users. Finally, you will learn to implement adaptive access and governance for identity and access management solutions, enabling you to troubleshoot, monitor and report on your environment.
By the end of this Microsoft Azure course, you will be ready to take the SC-300 exam included in our offer. Passing earns you Microsoft Certified: Identity and Access Administrator Associate certification.
Objectives
By the end of the Microsoft SC-300 course, you will achieve the following competency objectives:
- explain security, compliance and identity concepts;
- understand identity management capabilities in Microsoft Azure AD as part of Microsoft Entra;
- understand security capabilities in Microsoft solutions;
- understand compliance capabilities in Microsoft solutions;
- integrate identity management with Azure AD;
- integrate authentication and access management;
- integrate application access management;
- plan and introduce identity governance with Azure AD;
- pass SC-300 and earn Microsoft Certified: Identity and Access Administrator Associate certification.
Program
Security, compliance and identity fundamentals (SC-900|1 day)
Module 1: introducing security, compliance and identity concepts
- Understand security and compliance concepts:
- the shared responsibility model;
- defence in depth;
- the Zero Trust model;
- encryption and hashing;
- compliance concepts.
- Understand identity concepts:
- identity as the primary security perimeter;
- authentication;
- authorisation;
- identity providers;
- Active Directory.
Module 2: identity capabilities with Microsoft Azure AD as part of Microsoft Entra
- Understand core Azure AD services and identity types:
- what is Azure AD?
- Azure AD identities;
- hybrid identity;
- different external identity types.
- Understand Azure AD authentication capabilities:
- different authentication methods;
- multifactor authentication;
- self-service password reset;
- password protection and management capabilities.
- Understand Azure AD access management capabilities:
- Conditional Access;
- benefits of Azure AD roles;
- benefits of role-based access control.
- Understand Azure AD identity governance and protection capabilities:
- identity governance;
- user entitlement management and access reviews;
- Privileged Identity Management (PIM) capabilities;
- identity protection.
Module 3: security capabilities of Microsoft products
- Understand core Azure security capabilities:
- Azure DDoS Protection;
- Azure Firewall;
- what is a web application firewall?
- network segmentation with Azure virtual networks;
- Azure network security groups;
- Azure Bastion and virtual machine access;
- data encryption methods.
- Understand Azure security management capabilities:
- cloud security posture management;
- Microsoft Defender for Cloud;
- enhanced security capabilities of Microsoft Defender for Cloud;
- Azure security baselines.
- Understand Microsoft Sentinel security capabilities:
- SIEM and SOAR monitoring concepts;
- Microsoft Sentinel benefits for integrated threat management.
- Understand Microsoft 365 Defender threat protection:
- Microsoft 365 Defender services:
- Microsoft Defender for Office 365;
- Microsoft Defender for Endpoint;
- Microsoft Defender for Cloud Apps;
- Microsoft Defender for Identity;
- Microsoft 365 Defender services:
- the Microsoft 365 Defender portal.
Module 4: compliance capabilities of Microsoft products
- Understand the Microsoft Service Trust Portal and privacy principles:
- Service Trust Portal offerings;
- Microsoft privacy principles.
- Understand Microsoft Purview compliance management capabilities:
- the Microsoft Purview compliance portal;
- Compliance Manager;
- use and benefits of the compliance score.
- Understand Microsoft Purview information protection and data lifecycle management capabilities:
- data classification capabilities;
- benefits of Content Explorer and Activity Explorer;
- sensitivity labels and labelling policies;
- data loss prevention (DLP);
- records management;
- retention policies, retention labels and retention label policies.
- Understand Microsoft Purview insider risk capabilities:
- insider risk management;
- communication compliance;
- information barriers;
- Azure resource governance capabilities;
- using Azure Policy;
- using Azure Blueprints;
- unified data governance.
Identity and access administration with Azure AD (SC-300|4 days)
Module 1: implementing identities in Azure AD
- Configure and manage an Azure AD tenant:
- configuring and managing roles;
- configuring delegation through administrative units;
- analysing role permissions;
- configuring and managing custom domains;
- configuring tenant-level settings.
- Create, configure and manage Azure AD identities:
- creating, configuring and managing identities;
- creating, configuring and managing groups;
- configuring and managing device join and enrolment, including writeback;
- assigning, modifying and reporting on licences.
- Implement and manage external identities:
- managing external collaboration settings;
- inviting external users individually or in bulk;
- managing external user accounts in Azure AD;
- configuring identity providers, including SAML or WS-Fed.
- Implement and manage hybrid identity:
- implementing and managing Azure AD Connect;
- implementing and managing Azure AD Connect cloud sync;
- implementing and managing password hash synchronisation (PHS);
- implementing and managing pass-through authentication (PTA);
- implementing and managing seamless single sign-on (SSO);
- implementing and managing federation, excluding manual AD FS deployments;
- implementing and managing Azure AD Connect Health;
- resolving synchronisation errors.
Module 2: implementing authentication and access management
- Implement Azure multifactor authentication (MFA):
- planning Azure MFA deployment, excluding MFA Server;
- configuring and deploying self-service password reset;
- managing Azure and per-user MFA settings;
- extending Azure AD MFA to third-party and on-premises devices;
- monitoring Azure AD MFA activity.
- Implement Azure AD user authentication:
- planning authentication;
- implementing and managing authentication methods;
- implementing and managing Windows Hello for Business;
- implementing and managing password protection and smart lockout;
- implementing certificate-based authentication;
- configuring Azure AD user authentication for Windows and Linux virtual machines in Azure.
- Implement Azure AD Conditional Access:
- planning Conditional Access policies;
- implementing Conditional Access policy assignments;
- implementing Conditional Access policy controls;
- testing and troubleshooting Conditional Access policies;
- implementing session management;
- implementing device restrictions;
- implementing continuous access evaluation;
- creating a Conditional Access policy from a template.
- Manage Azure AD Identity Protection:
- implementing and managing a user risk policy;
- implementing and managing a sign-in risk policy;
- implementing and managing an MFA registration policy;
- monitoring, investigating and remediating risky users;
- implementing security for workload identities.
- Implement access management for Azure resources:
- assigning Azure roles and configuring custom roles;
- creating and configuring managed identities;
- using managed identities to access Azure resources;
- analysing Azure role permissions;
- configuring Azure Key Vault policies and RBAC.
Module 3: implementing application access management
- Manage and monitor application access through Microsoft Defender for Cloud Apps:
- discovering and managing applications;
- configuring application connectors;
- implementing application restrictions;
- using Conditional Access App Control;
- creating access and session policies;
- implementing and managing policies for OAuth applications.
- Manage and monitor enterprise application integration:
- configuring and managing user and administrator consent;
- identifying applications through AD FS application activity reports;
- designing and implementing application access management;
- designing and implementing application management roles;
- monitoring and auditing enterprise application activity;
- designing and integrating on-premises applications through Azure AD Application Proxy;
- designing and integrating SaaS applications;
- provisioning and managing users, groups and roles in enterprise applications;
- creating and managing application collections.
- Plan and implement application registrations:
- planning application registrations;
- implementing application registrations;
- configuring application access permissions;
- planning and configuring multi-tier application permissions;
- managing and monitoring applications through app governance.
Module 4: planning and integrating identity governance in Azure AD
- Implement entitlement management:
- planning entitlements;
- creating and configuring catalogues;
- creating and configuring access packages;
- managing access requests;
- implementing and managing terms of use;
- managing the external user lifecycle in Azure AD identity governance settings;
- configuring and managing connected organisations;
- reviewing user entitlements through Azure AD entitlement management.
- Implement and manage access reviews:
- planning access reviews;
- creating and configuring access reviews for groups and applications;
- creating and configuring access review programmes;
- monitoring access review activity;
- responding to access review activities, including automated and manual responses.
- Implement privileged access:
- planning and managing Azure roles in Privileged Identity Management (PIM), including settings and assignments;
- planning and managing Azure resources in PIM, including settings and assignments;
- planning and configuring privileged access groups;
- managing PIM requests and the approval process;
- analysing PIM history and audit reports;
- creating and managing emergency access accounts.
- Monitor Azure AD:
- designing an Azure AD monitoring strategy;
- analysing sign-in, audit and provisioning logs through the Azure Active Directory admin centre;
- configuring diagnostic settings, including Log Analytics, storage accounts and Event Hub;
- monitoring Azure AD through Log Analytics, including KQL queries;
- analysing Azure AD through workbooks and Azure Active Directory admin centre reports;
- monitoring and improving security posture through Identity Secure Score.
Audience
This course is intended for:
- users of Microsoft products and services seeking advanced security, compliance and identity knowledge;
- administrators who carry out identity and access management tasks daily and those seeking certification;
- administrators and engineers seeking to specialise in designing identity solutions and access management systems with Azure.
Prerequisites
The Microsoft SC-900 course has the following prerequisites:
- knowledge of IT security best practices, including defence in depth, least-privilege access, shared responsibility and Zero Trust;
- knowledge of identity concepts including authentication, authorisation and Active Directory;
- experience deploying workloads on Azure;
- Windows and Linux systems administration and scripting skills are an advantage but are not mandatory.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
Course highlights
Training delivered by an expert Microsoft-certified trainer; an official French-language programme with computer labs and the SC-900 exam included in our offer.
- Certification guarantee: Microsoft Exam Replay is included, allowing a free exam retake if you do not pass the first time.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
Microsoft®, Microsoft Azure Active Directory®, Microsoft 365®, Microsoft Entra® and Power Platform® are registered trademarks or trademarks of Microsoft Corporation in the United States and other countries.
fr
en