qSkills™ AI Agent
qS
Hello! Ask me about training courses, certifications, schedules or anything else on qskills.de—just in your own words.
0/800

CS500: Microsoft™ End-to-End Security Controls for Cloud and AI Workloads

Training: Cloud - AI - IAM - Microsoft™

In the course CS500 Implementing End-to-End Security Controls for Cloud and AI Workloads develops your ability to establish and administer security controls across Azure, hybrid infrastructure and AI applications. The training covers identity and access protection, security for data and network connections, and the settings needed to protect servers, containers and application platforms.

You use Microsoft™ Entra ID, Azure Key Vault and Microsoft™ Defender for Cloud to put security requirements into practice and identify vulnerabilities. AI security topics include Microsoft™ Purview, Microsoft™ Entra Agent ID, Microsoft™ Copilot Studio and Microsoft™ Foundry. Microsoft™ Sentinel and Microsoft™ Security Copilot extend the scope to event collection, automated workflows and the setup of supporting security tools.

Unfortunately there are currently no available appointments.
Would you like to request an appointment? Then click on 'No matching appointment?'

Request prefered appointment period:

* All fields marked with an asterisk are mandatory fields.

Agenda:

  • Identity controls, permissions and security governance

    • Sign-in and application access with Microsoft™ Entra ID

      • Combine multifactor authentication (MFA) and passwordless sign-in methods with Conditional Access to control authentication

      • Set up Privileged Identity Management (PIM) to administer privileged access

      • Establish application identities through enterprise applications and app registrations, with control over OAuth permission grants and consent settings

      • Identitäten für Enterprise Applications und App Registrations einrichten sowie OAuth-Berechtigungsfreigaben und Zustimmungseinstellungen verwalten

      • Equip Azure resources with managed identities for resource access

    • Keys and sensitive values in Azure Key Vault

      • Deploy Azure Key Vault and establish its configuration, access controls and firewall rules

      • Administer the keys, secrets and certificates held in Azure Key Vault

      • Use secret scanning in Defender Cloud Security Posture Management (Defender CSPM) and establish protection with Defender for Key Vault

    • Enforcing security policies and permission boundaries

      • Build security controls around built-in and custom Azure Policy definitions and configure controls through infrastructure as code

      • Apply security standards and recommendations in Microsoft™ Defender for Cloud when configuring controls, and assess regulatory compliance

      • Administer assignments of built-in Azure roles and maintain custom roles in Azure and Microsoft™ Entra

      • Review and reduce excessive Azure role-based access control (RBAC) permissions, and apply resource locks

      • Apply Azure Backup security settings to protect backups

  • Protection for storage, databases and network connections

    • Storage account protection

      • Set up Azure Storage security through account settings, firewall rules, access management and access policies

      • Establish threat protection for storage accounts with Defender for Storage

    • Azure database security

      • Set platform security options in Azure SQL and establish auditing for Azure SQL Database and Azure SQL Managed Instance

      • Apply Defender for Databases protection across Azure database services

    • Network access and private connectivity

      • Control network traffic through network security groups (NSGs) and application security groups (ASGs), with network access policies in Azure Virtual Network Manager

      • Apply security settings to Azure Virtual WAN and VPN connections

      • Set up Microsoft™ Entra Private Access for private connectivity

      • Establish private endpoint access to Azure PaaS resources and use Azure Private Link services to protect access to network resources

      • Deploy Azure Firewall and set its controls for network access

      • Use diagnostics in Azure Network Watcher to assess the security rules that take effect

  • Protection for compute resources

    • Security controls for AI applications and agents

      • Locate SharePoint data exposed too broadly and identify risks involving Microsoft™ Copilot and AI applications with Microsoft™ Purview Data Security Posture Management (DSPM)

      • Set up and activate real-time protection for agents built in Microsoft™ Copilot Studio

      • Administer access for Microsoft™ Entra Agent ID and apply Conditional Access to those identities

      • Examine the potential blast radius of Microsoft™ Entra Agent ID security risks in Defender XDR

      • Set up AI Gateway in Azure API Management for Microsoft™ Foundry and establish agent security guardrails in Microsoft™ Foundry

      • Activate Defender for AI Service within Cloud Workload Protection in Microsoft™ Defender for Cloud and track AI security in the Data and AI security dashboard

      • Use the Microsoft™ 365 admin center for agent administration

    • Server and virtual machine protection

      • Set up disk encryption for virtual machines

      • Plan and deploy Azure Bastion, then enable and enforce just-in-time (JIT) access to virtual machines

      • Extend security controls to hybrid and multicloud servers through Azure Arc and onboard servers to Defender for Servers in Microsoft™ Defender for Cloud

      • Set up vulnerability scanning, endpoint detection and response (EDR), and agentless VM scanning in Defender for Servers

      • Select and configure VM security features covering Secure Boot, virtual Trusted Platform Module (vTPM), integrity monitoring and security type

      • Use Azure Machine Configuration to enforce security settings on Azure-managed servers

    • Container and application platform protection

      • Find configuration weaknesses and runtime risks in container workloads through Defender for Containers

      • Establish security controls for Azure Kubernetes Service (AKS) and Azure Container Registry

      • Set the protection controls for Azure Container Instances and Azure Container Apps

      • Protect Azure Functions through authentication settings and network access controls

      • Apply security controls within Azure Logic Apps and Azure App Service

      • Set up Azure Web Application Firewall and protect back-end APIs through security policies in Azure API Management

  • Security posture assessment and monitoring

    • Cloud risk and protection coverage

      • Identify risks through Defender CSPM and assess adherence to security frameworks in Microsoft™ Defender for Cloud

      • Activate and configure workload protection plans in Microsoft™ Defender for Cloud and connect hybrid and multicloud environments, including Amazon Web Services (AWS™) and Google™ Cloud Platform (GCP)

      • Set Microsoft™ Defender Vulnerability Management options for Azure virtual machines

      • Discover assets lacking protection and associated vulnerabilities with Microsoft™ Defender External Attack Surface Management (EASM)

    • Event data and automated workflows with Microsoft™ Sentinel

      • Establish and connect Microsoft™ Sentinel workspaces and assign access roles

      • Deploy Content Hub solutions for use in Microsoft™ Sentinel

      • Connect Azure resources through Microsoft™ data connectors and bring in events through syslog and Common Event Format (CEF)

      • Collect Windows Security events through data collection rules, including Windows Event Forwarding (WEF)

      • Create custom log tables for ingested records and set retention in Microsoft™ Sentinel data stores

      • Build automated workflows in Microsoft™ Sentinel with automation rules and playbooks

      • Retrieve Microsoft™ Purview Audit records through queries in Defender XDR

    • Setting up Microsoft™ Security Copilot

      • Establish workspaces in Microsoft™ Security Copilot and administer their roles and permissions

      • Set up and activate plugins, Microsoft™ agents and Security Store agents

Objectives:

In the workshop CS500 Implementing End-to-End Security Controls for Cloud and AI Workloads will gain in-depth knowledge in the following areas:

  • Configure authentication methods, application identities and privileged access in Microsoft™ Entra ID, and correct excessive permissions

  • Administer keys, secrets and certificates in Azure Key Vault and implement security requirements through Azure Policy, roles, resource locks and infrastructure as code

  • Protect storage, databases and network connections with appropriate access and security configurations

  • Identify risks affecting AI applications and agents, and establish their access controls, protection features and security monitoring

  • Configure security controls for servers, virtual machines, containers and Azure application platforms, extending protection to hybrid environments

  • Use Microsoft™ Defender for Cloud to assess risks, vulnerabilities and adherence to security requirements, and administer protection plans

  • Bring event data into Microsoft™ Sentinel, manage retention and implement workflows with automation rules and playbooks

  • Set up Microsoft™ Security Copilot with workspaces, permissions, plugins and agents


This training prepares you for the CS500 Implementing End-to-End Security Controls for Cloud and AI Workloads exam. The exam must always be taken separately at a Pearson VUE test center or online.

Target audience:

The training CS500 Implementing End-to-End Security Controls for Cloud and AI Workloads is ideal for:

  • Security Engineers responsible for implementing and maintaining security controls across Azure, hybrid infrastructure and AI environments

  • Administrators and technical specialists whose responsibilities include protecting identities, networks, databases, storage or application platforms in these environments

  • Participants with relevant administration knowledge who want to prepare for the Microsoft™ SC-500 exam

Prerequisites:

To be able to follow the course content and learning pace in the workshop CS500 Implementing End-to-End Security Controls for Cloud and AI Workloads, you should have the following prior knowledge:

  • Practical experience administering Azure and hybrid environments, particularly compute resources, networks and storage

  • A strong working knowledge of Microsoft™ Entra ID

  • Familiarity with Microsoft™ 365 administration

We recommend taking the course: AZ104 MS Azure Administration in advance.

Description:

In the course CS500 Implementing End-to-End Security Controls for Cloud and AI Workloads develops your ability to establish and administer security controls across Azure, hybrid infrastructure and AI applications. The training covers identity and access protection, security for data and network connections, and the settings needed to protect servers, containers and application platforms.

You use Microsoft™ Entra ID, Azure Key Vault and Microsoft™ Defender for Cloud to put security requirements into practice and identify vulnerabilities. AI security topics include Microsoft™ Purview, Microsoft™ Entra Agent ID, Microsoft™ Copilot Studio and Microsoft™ Foundry. Microsoft™ Sentinel and Microsoft™ Security Copilot extend the scope to event collection, automated workflows and the setup of supporting security tools.

Check Icon

Guaranteed implementation:

from 2 Attendees

Booking information:

Duration:

4 Days

Price:

2.490,00 € plus VAT.

For in-person attendance, lunch and beverages are included in the price.

Impressions:

Authorized training partner

NetApp Partner Authorized Learning
Commvault Training Partner
CQI | IRCA Approved Training Partner
Veeam Authorized Education Center
DEKRA Certification GmbH
AWS Partner Select Tier Training
ISACA Accredited Partner
iSAQB
CompTIA Authorized Partner
EC-Council Accredited Training Center

Memberships

Allianz für Cyber-Sicherheit
TeleTrust Pioneers in IT security
Bundesverband der IT-Sachverständigen und Gutachter e.V.
Bundesverband mittelständische Wirtschaft (BVMW)
Allianz für Sicherheit in der Wirtschaft
NIK - Netzwerk der Digitalwirtschaft
BVSW
Bayern Innovativ
KH-iT
CAST
IHK Nürnberg für Mittelfranken
eato e.V.
Sicherheitsnetzwerk München e.V.