Secure Cloud and AI Environments End to End (SC-500)
The cloud redistributes responsibilities without eliminating risks. Connect architecture, identities and data protection to structure security decisions. Strengthen your ability to analyse cloud environments and coordinate protective measures with the teams involved.
- Duration
- 4 days 28 hours
- Code
- SC500T00 Code
- Certification
- Microsoft Certified : Cloud and AI Security Engineer Associate Certification
Accredited training for the Microsoft Certified : Cloud and AI Security Engineer Associate certification.
Presentation
Demand for cloud security and AI experts has never been greater than in 2026. Microsoft is evolving its security certification pathway with this new qualification, which progressively succeeds AZ-500 and covers protection for AI agents and Copilot solutions for the first time, alongside identity, networking, storage and computing.
During this course, you will develop practical command of Azure security controls over four intensive days, combining methodological instruction with hands-on workshops. The programme covers identity management, storage and network security, secure computing and security posture monitoring with Microsoft Defender and Microsoft Sentinel.
By the end of the course, you will master the skills expected of a security engineer working across cloud and hybrid environments. You will be prepared to take SC-500 and earn the Microsoft Certified: Cloud and AI Security Engineer Associate certification.
Objectives
By the end of this Microsoft SC-500 course, you will be able to:
- secure resource access with Microsoft Entra ID and Azure Key Vault;
- apply security and regulatory compliance across Azure environments;
- secure storage, databases and networking;
- secure computing, servers and application platform services;
- secure AI solutions, including Copilot agents and Microsoft Foundry;
- manage and monitor security posture with Microsoft Defender for Cloud and Microsoft Sentinel;
- prepare for and pass SC-500 to earn the Microsoft Certified: Cloud and AI Security Engineer Associate credential.
Program
Module 1: Secure identity, access and governance
- Conditional access policies and authentication methods, including MFA and passwordless authentication.
- Manage privileged identities with Privileged Identity Management and managed identities for Azure resources.
- Secure secrets, keys and certificates with Azure Key Vault.
- Governance controls with Azure Policy, RBAC roles and resource locks for regulatory compliance.
Labs
- Configure a conditional access policy and deploy a firewall-protected Azure Key Vault.
Module 2: Secure storage, databases and networking
- Firewall rules and access policies for Azure storage accounts.
- Security configurations and auditing for Azure SQL Database and Azure SQL Managed Instance.
- Network security groups, application security groups and Azure Virtual Network Manager.
- Azure Firewall, private endpoints and secure VPN connections.
Labs
- Deploy a segmented network environment with security groups, private endpoints and Azure Firewall.
Module 3: Secure computing and AI workloads
- Disk encryption, just-in-time access and Azure Bastion for virtual machines.
- Security controls for Azure Kubernetes Service, Azure Container Registry and Azure App Service.
- Detect Copilot and AI agent risks with Microsoft Purview and Defender for Cloud.
- Conditional access and real-time protection for Microsoft Copilot Studio and Microsoft Foundry agents.
Labs
- Configure a secure AI gateway in Azure API Management and enable Defender for the AI service.
Module 4: Manage and monitor security posture
- Compliance assessment and vulnerability management with Microsoft Defender for Cloud.
- Connect AWS and GCP multicloud environments to Defender for Cloud.
- Create Microsoft Sentinel workspaces and configure data connectors.
- Automation rules, playbooks and use of Microsoft Security Copilot.
Labs
- Create a Microsoft Sentinel workspace and configure an automated incident response playbook.
Audience
This course is intended for IT security professionals, including:
- security engineers responsible for protecting cloud and hybrid environments;
- Azure administrators seeking to expand their security skills;
- security architects developing towards cybersecurity expertise;
- SOC analysts involved in securing identities, data and AI.
Prerequisites
The following prerequisites apply:
- Technical skills: practical experience administering Azure and hybrid environments, including computing, networking and storage.
- Theoretical foundations: good knowledge of Microsoft Entra ID and Microsoft 365 administration.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
Course highlights
- SC-500-aligned programme: cover all four skills domains assessed in the official Microsoft examination.
- Practical Azure workshops: work with real cloud environments to configure Defender, Sentinel and Key Vault under realistic conditions.
- Next-generation certification: earn a credential that succeeds AZ-500 and incorporates AI security for the first time.
- Enhanced employability: develop an in-demand professional profile in a market where cloud and AI security is becoming a priority.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
Microsoft® is a registered trademark or trademark of Microsoft Corporation in the United States and other countries. Its mention for educational purposes does not constitute an endorsement or partnership.
fr
en