1. Manage identity and access
- Azure Active Directory
- Review of Azure AD in Azure Portal
- Lab – Working with users and groups
- Azure AD Custom Domains
- Azure Active Directory licences
- Lab – Azure AD – Dynamic Groups
- Permissions for Azure Active Directory users
- The different permissions
- Application Registration
- Lab – Application Registration
- Azure AD – User settings
- Multi-Factor Authentication
- Lab – Multi-Factor Authentication
- Lab – Multi-Factor Authentication – Trusted Devices
- Lab – Multi-Factor Authentication – Skip IPs
- Lab – Conditional Access Policies
- Lab – Conditional Access policies – Use case
- Azure AD Identity Protection
- Azure AD Identity Management – Use case scenario
- Azure AD Privileged Identity Management – Azure AD Roles
- Lab – Azure AD Privileged Identity Management – Azure AD Roles
- Azure AD PIM – Azure Role settings
- Lab – Azure Privileged Identity – Azure Resources
- What are Access Reviews
- Lab – Access Review – Security Groups
- Lab – Access Review – Azure AD Roles
- What is Azure AD Connect
- Points on Azure AD Connect
- Active Directory Implementation
- Lab – Azure AD Connect – Installation
- Going through the Azure AD Connect settings
- Lab – Azure AD Connect – Pass-through Authentication
- Azure AD Connect – Password writeback
- Azure AD Connect – User properties
- Lab – Azure AD – Passwordless sign-in
- Transferring ownership of a subscription
2. Implement platform protection
- Setting up Azure Cloud Shell
- Azure virtual machine security overview
- Network Security Groups
- Lab – Network Security Groups
- Lab – Network Security Groups – Subnet
- Lab – Use case scenario – VM without a network security group
- Allowing ICMP traffic
- Application Security Groups – Implementation Overview
- Lab – Application Security Groups – Setup – MySQL
- Lab – Application Security Groups – Setup – Completion
- Lab – Application Security Groups – Implementation
- Azure Front Door Service
- The Azure Application Gateway Service
- Lab – Azure Application Gateway – Setup
- Lab – Azure Application Gateway – URL Routing
- Lab – Azure Application Gateway – Web Application Firewall
- Virtual Network Peering
- Lab – Virtual Network Peering
- Point to Site VPN Connection
- Lab – Point to Site VPN Connection
- Site-to-Site VPN Connection
- Site to Site VPN – What are we going to do
- Lab – Site to Site VPN – Setup
- Lab – Site to Site VPN – Implementation
- Lab – Site to Site VPN – Transit Gateway
- Site to Site VPN – Notes
- User Defined Routes
- Lab – User Defined Routes
- Using a Jump server
- Lab – Using a Jump server
- Azure Bastion service
- Lab – Azure Bastion service
- Azure DDoS Protection
- What is the Azure Firewall service
- Azure Firewall – Our setup
- Lab – Azure Firewall
- Lab – Azure Firewall – NAT Rules
- Lab – Azure Firewall – Application Rules
- Azure Firewall – Hub and Spoke
- Lab – Microsoft IaaS Antimalware extension
- What is the Azure Monitor Service
- Lab – Working with Azure Monitor
- Lab – Alerts in Azure Monitor – Surpression
- What is a Log Analytics Workspace
- Lab – Log Analytics Workspace
- Lab – Azure VM diagnostics log
- Lab – Azure Log Analytics – Sending custom logs
- Update Management for Azure Virtual Machines
- Lab – Update Management for virtual machines
- Creation of a storage account
- Lab – Network Watcher – NSG Flow Logs
- Role based access control
- Lab – Role based access control
- Lab – Custom roles
- Lab – Azure resource locks
- Lab – Azure resource locks – Use case scenario
- Lab – Azure policies
- Lab – Azure policies – Use case scenario
- Azure Blueprints
- Lab – Azure Blueprints – Definition
- Lab – Azure Blueprints – Assignment
- Lab – Azure Blueprints – Resource Locks
- Quick overview on Containers
- Lab – Deploying Docker on a Linux virtual machine
- Lab – Deploying Docker on a Linux virtual machine – Commands
- Lab – Azure Container Instances
- Primer on Azure Kubernetes
- Lab – Deploying Azure Kubernetes
- Lab – Deploying Azure Kubernetes – Commands
- Azure AD Authentication for Azure Kubernetes – Implementation Review
- Lab – Azure Container registry
- Lab – Azure Container registry – Practice commands
3. Manage security operations
- Azure Security Center
- Lab – Azure Security Center – Just in time VM access
- Azure Security Center – Data Collection for Azure virtual machines
- Azure Security Center – Advanced Cloud Defense with Demo
- Azure Security Center – Other features
- Lab – Azure Security Center – Workflow Automation
- What is Azure Sentinel
- Lab – Azure Sentinel – Creating a workspace
- Lab – Azure Sentinel – Collecting Azure Activity Logs
- Lab – Azure Sentinel – Collecting Azure AD information
- Lab – Azure Sentinel – Analytics , Alerts and Incidents
- Lab – Azure Sentinel – Playbooks
- Lab – Azure Sentinel – Collecting Security Events
4. Secure data and applications
- The Azure Key vault service
- Lab – Azure Key Vault
- Service principal
- Lab – Azure Key vault – Secrets
- Lab – Managing Azure Key vault secrets
- Lab – Managing Azure Key vault secrets – Commands
- Lab – Azure Key vault – Encryption keys
- Azure Key vault – Permissions vs RBAC
- Azure Key vault – Soft Delete Feature
- Lab – Azure Key Vault – Firewalls – IP Address
- Lab – Azure Key Vault – Firewalls – Virtual Network
- Lab – Azure Key Vault – Firewalls – Microsoft Trusted Service
- Lab – Azure Key Vault – ARM Templates
- Lab – Azure Key Vault – Backup
- Managed Service Identity
- Using Key vault with a Managed Service Identity
- Setting up Visual Studio
- Lab – Azure Web App – Custom domains
- Lab – Azure Web App – SSL
- Lab – Azure Web App – Getting the SSL certificate
- Encryption at rest
- Lab – Azure Disk Encryption
- Lab – Azure Key Vault – ARM Templates
- Lab – Creating an Azure SQL Database
- Lab – Azure AD Authentication – Azure SQL Databases
- Lab – Azure SQL Database Encryption
- Azure SQL Server auditing
- Lab – Azure SQL Database – Advanced Data Security
- Azure SQL Database – Diagnostic setting
- Lab – Firewalls and network – Network
- Lab – Firewalls and network – Microsoft Services
- Lab – Creating a storage account
- Lab – Working with the Blob service
- Lab – Immutable Blob storage
- Lab – Azure Storage Explorer
- Lab – Using Access Keys
- Lab – Shared Access Signatures
- Lab – Invalidating Shared Access Signatures
- Lab – Azure AD Authentication – Azure Blob service
- Azure AD Authentication for Azure Blobs – Follow up
- Azure AD Authentication for Azure Files – Implementation Review
- Azure AD Authentication for Azure Files – Follow up
- Azure Storage Accounts Encryption
- Service Endpoints
- Lab – Service Endpoints
- Lab – Network Security Groups – Storage accounts
- Lab – Azure Storage Account – Rotating Account Keys
- Lab – Cosmos DB – Using Account keys
- Cosmos DB – Use case scenario
- Azure Data Lake Storage Gen2 – Security Aspect