AZ-500

1. Manage identity and access

  • Azure Active Directory
  • Review of Azure AD in Azure Portal
  • Lab – Working with users and groups
  • Azure AD Custom Domains
  • Azure Active Directory licences
  • Lab – Azure AD – Dynamic Groups
  • Permissions for Azure Active Directory users
  • The different permissions
  • Application Registration
  • Lab – Application Registration
  • Azure AD – User settings
  • Multi-Factor Authentication
  • Lab – Multi-Factor Authentication
  • Lab – Multi-Factor Authentication – Trusted Devices
  • Lab – Multi-Factor Authentication – Skip IPs
  • Lab – Conditional Access Policies
  • Lab – Conditional Access policies – Use case
  • Azure AD Identity Protection
  • Azure AD Identity Management – Use case scenario
  • Azure AD Privileged Identity Management – Azure AD Roles
  • Lab – Azure AD Privileged Identity Management – Azure AD Roles
  • Azure AD PIM – Azure Role settings
  • Lab – Azure Privileged Identity – Azure Resources
  • What are Access Reviews
  • Lab – Access Review – Security Groups
  • Lab – Access Review – Azure AD Roles
  • What is Azure AD Connect
  • Points on Azure AD Connect
  • Active Directory Implementation
  • Lab – Azure AD Connect – Installation
  • Going through the Azure AD Connect settings
  • Lab – Azure AD Connect – Pass-through Authentication
  • Azure AD Connect – Password writeback
  • Azure AD Connect – User properties
  • Lab – Azure AD – Passwordless sign-in
  • Transferring ownership of a subscription

2. Implement platform protection

  • Setting up Azure Cloud Shell
  • Azure virtual machine security overview
  • Network Security Groups
  • Lab – Network Security Groups
  • Lab – Network Security Groups – Subnet
  • Lab – Use case scenario – VM without a network security group
  • Allowing ICMP traffic
  • Application Security Groups – Implementation Overview
  • Lab – Application Security Groups – Setup – MySQL
  • Lab – Application Security Groups – Setup – Completion
  • Lab – Application Security Groups – Implementation
  • Azure Front Door Service
  • The Azure Application Gateway Service
  • Lab – Azure Application Gateway – Setup
  • Lab – Azure Application Gateway – URL Routing
  • Lab – Azure Application Gateway – Web Application Firewall
  • Virtual Network Peering
  • Lab – Virtual Network Peering
  • Point to Site VPN Connection
  • Lab – Point to Site VPN Connection
  • Site-to-Site VPN Connection
  • Site to Site VPN – What are we going to do
  • Lab – Site to Site VPN – Setup
  • Lab – Site to Site VPN – Implementation
  • Lab – Site to Site VPN – Transit Gateway
  • Site to Site VPN – Notes
  • User Defined Routes
  • Lab – User Defined Routes
  • Using a Jump server
  • Lab – Using a Jump server
  • Azure Bastion service
  • Lab – Azure Bastion service
  • Azure DDoS Protection
  • What is the Azure Firewall service
  • Azure Firewall – Our setup
  • Lab – Azure Firewall
  • Lab – Azure Firewall – NAT Rules
  • Lab – Azure Firewall – Application Rules
  • Azure Firewall – Hub and Spoke
  • Lab – Microsoft IaaS Antimalware extension
  • What is the Azure Monitor Service
  • Lab – Working with Azure Monitor
  • Lab – Alerts in Azure Monitor – Surpression
  • What is a Log Analytics Workspace
  • Lab – Log Analytics Workspace
  • Lab – Azure VM diagnostics log
  • Lab – Azure Log Analytics – Sending custom logs
  • Update Management for Azure Virtual Machines
  • Lab – Update Management for virtual machines
  • Creation of a storage account
  • Lab – Network Watcher – NSG Flow Logs
  • Role based access control
  • Lab – Role based access control
  • Lab – Custom roles
  • Lab – Azure resource locks
  • Lab – Azure resource locks – Use case scenario
  • Lab – Azure policies
  • Lab – Azure policies – Use case scenario
  • Azure Blueprints
  • Lab – Azure Blueprints – Definition
  • Lab – Azure Blueprints – Assignment
  • Lab – Azure Blueprints – Resource Locks
  • Quick overview on Containers
  • Lab – Deploying Docker on a Linux virtual machine
  • Lab – Deploying Docker on a Linux virtual machine – Commands
  • Lab – Azure Container Instances
  • Primer on Azure Kubernetes
  • Lab – Deploying Azure Kubernetes
  • Lab – Deploying Azure Kubernetes – Commands
  • Azure AD Authentication for Azure Kubernetes – Implementation Review
  • Lab – Azure Container registry
  • Lab – Azure Container registry – Practice commands

3. Manage security operations

  • Azure Security Center
  • Lab – Azure Security Center – Just in time VM access
  • Azure Security Center – Data Collection for Azure virtual machines
  • Azure Security Center – Advanced Cloud Defense with Demo
  • Azure Security Center – Other features
  • Lab – Azure Security Center – Workflow Automation
  • What is Azure Sentinel
  • Lab – Azure Sentinel – Creating a workspace
  • Lab – Azure Sentinel – Collecting Azure Activity Logs
  • Lab – Azure Sentinel – Collecting Azure AD information
  • Lab – Azure Sentinel – Analytics , Alerts and Incidents
  • Lab – Azure Sentinel – Playbooks
  • Lab – Azure Sentinel – Collecting Security Events

4. Secure data and applications

  • The Azure Key vault service
  • Lab – Azure Key Vault
  • Service principal
  • Lab – Azure Key vault – Secrets
  • Lab – Managing Azure Key vault secrets
  • Lab – Managing Azure Key vault secrets – Commands
  • Lab – Azure Key vault – Encryption keys
  • Azure Key vault – Permissions vs RBAC
  • Azure Key vault – Soft Delete Feature
  • Lab – Azure Key Vault – Firewalls – IP Address
  • Lab – Azure Key Vault – Firewalls – Virtual Network
  • Lab – Azure Key Vault – Firewalls – Microsoft Trusted Service
  • Lab – Azure Key Vault – ARM Templates
  • Lab – Azure Key Vault – Backup
  • Managed Service Identity
  • Using Key vault with a Managed Service Identity
  • Setting up Visual Studio
  • Lab – Azure Web App – Custom domains
  • Lab – Azure Web App – SSL
  • Lab – Azure Web App – Getting the SSL certificate
  • Encryption at rest
  • Lab – Azure Disk Encryption
  • Lab – Azure Key Vault – ARM Templates
  • Lab – Creating an Azure SQL Database
  • Lab – Azure AD Authentication – Azure SQL Databases
  • Lab – Azure SQL Database Encryption
  • Azure SQL Server auditing
  • Lab – Azure SQL Database – Advanced Data Security
  • Azure SQL Database – Diagnostic setting
  • Lab – Firewalls and network – Network
  • Lab – Firewalls and network – Microsoft Services
  • Lab – Creating a storage account
  • Lab – Working with the Blob service
  • Lab – Immutable Blob storage
  • Lab – Azure Storage Explorer
  • Lab – Using Access Keys
  • Lab – Shared Access Signatures
  • Lab – Invalidating Shared Access Signatures
  • Lab – Azure AD Authentication – Azure Blob service
  • Azure AD Authentication for Azure Blobs – Follow up
  • Azure AD Authentication for Azure Files – Implementation Review
  • Azure AD Authentication for Azure Files – Follow up
  • Azure Storage Accounts Encryption
  • Service Endpoints
  • Lab – Service Endpoints
  • Lab – Network Security Groups – Storage accounts
  • Lab – Azure Storage Account – Rotating Account Keys
  • Lab – Cosmos DB – Using Account keys
  • Cosmos DB – Use case scenario
  • Azure Data Lake Storage Gen2 – Security Aspect
Menu