This is an example of a simple banner

Training: Implement end-to-end security controls for cloud and AI workloads (SC-500)

Ref. SC-500T00
Duration:
4
 jours
Exam:
Optionnel
Level:
Intermédiaire

Implement end-to-end security controls for cloud and AI workloads Training (SC-500)

The SC-500 training teaches you to implement end-to-end security controls across the cloud and AI workloads running in Microsoft Azure. In four days you cover identity protection with Microsoft Entra ID and Privileged Identity Management, hardening for storage, databases, networks and virtual machines, governance with Azure Policy, and the protection of AI agents and services. This official Microsoft course succeeds AZ-500, retired on 31 August 2026, and extends the scope to AI workload security.

Secure Azure and AI with Defender for Cloud, Defender XDR and Security Copilot

Delivered in Geneva and Lausanne by MCT certified trainers, the course alternates demonstrations and hands-on labs. You enable Microsoft Defender for Cloud protection plans, analyse identity and AI agent risks in Microsoft Defender XDR, connect your data sources to Microsoft Sentinel and get started with Microsoft Security Copilot. The official outline holds 63 modules for four days: the pace is demanding and your trainer prioritises topics according to the environments and the challenges of the group. By the end of the course you are ready for the SC-500 exam and the Cloud and AI Security Engineer Associate certification.

Participant Profiles

  • Cloud security engineers
  • Microsoft Azure administrators and architects
  • SOC analysts extending their scope to cloud and AI environments
  • Infrastructure and IT governance managers
  • Cybersecurity consultants working on Azure
  • AZ-500 certified professionals who need to cover the AI scope

Objectives

  • Secure identities and privileged access with Microsoft Entra ID and PIM
  • Protect keys, secrets and certificates with Azure Key Vault
  • Enforce governance and compliance with Azure Policy and Defender for Cloud
  • Harden Azure storage, databases, networks and virtual machines
  • Secure containers, applications and APIs hosted on Azure
  • Protect AI workloads and agents with Defender for Cloud and Defender XDR
  • Deploy Microsoft Sentinel and operate Microsoft Security Copilot day to day

Prerequisites

  • Experience administering Microsoft Azure
  • Identity and networking notions: Microsoft Entra ID, addressing, filtering
  • Security basics: encryption, logging, vulnerabilities

Course Content

Module 1: Manage and implement authentication methods in Microsoft Entra ID

  • Explore Microsoft Entra ID authentication methods
  • Configure multifactor authentication in Microsoft Entra ID
  • Implement passwordless authentication in Microsoft Entra ID
  • Configure self-service password reset in Microsoft Entra ID

Module 2: Implement and configure Privileged Identity Management (PIM)

  • Why Privileged Identity Management and just-in-time access matter
  • Core capabilities of Privileged Identity Management (PIM)
  • Implement just-in-time access for Microsoft Entra roles
  • Implement just-in-time access for Azure roles and resources
  • Scaling with PIM for Groups
  • Applying JIT access to AI workloads, agents, and applications
  • JIT design patterns and best practices

Module 3: Authenticate your API plugin for declarative agents with secured APIs

  • Integrate an API plugin with an API secured with a key
  • Integrate an API plugin with an API secured with OAuth

Module 4: Configure and secure Azure Key Vault

  • Deploy Azure Key Vault with security controls
  • Configure access to Azure Key Vault
  • Configure Key Vault firewall and network settings

Module 5: Manage keys and secrets in Azure Key Vault

  • Manage cryptographic keys in Azure Key Vault
  • Manage secrets in Azure Key Vault

Module 6: Manage certificates and monitor Azure Key Vault

  • Manage certificates in Azure Key Vault
  • Enable Key Vault audit logging

Module 7: Protect Azure Key Vault with Microsoft Defender for Cloud

  • Scan for exposed secrets using Defender Cloud Security Posture Management (CSPM)
  • Enable Microsoft Defender for Key Vault
  • Investigate and respond to Defender for Key Vault alerts

Module 8: Enforce governance with Azure Policy and resource locks

  • Assign built-in Azure Policy definitions
  • Create and deploy custom policy definitions
  • Implement resource locks

Module 9: Configure security controls and remediate recommendations in Defender for Cloud

  • Configure Defender for Cloud and manage security standards
  • Deploy remediation controls at scale

Module 10: Evaluate regulatory compliance in Defender for Cloud

  • Understand compliance standards and controls in Defender for Cloud
  • Navigate the regulatory compliance dashboard and investigate control gaps
  • Assign standards and communicate compliance posture

Module 11: Manage and right-size RBAC role assignments for least privilege

  • Assign and manage Azure built-in roles
  • Create custom Azure roles and Microsoft Entra roles
  • Evaluate and remediate overprivileged access

Module 12: Protect backup data with Azure Backup security features

  • Enable soft delete and immutable vaults
  • Configure Multi-User Authorization and RBAC for backup

Module 13: Implement security controls in infrastructure as code

  • Scan IaC templates using Microsoft Defender for DevOps
  • Enforce policy compliance in IaC deployments

Module 14: Describe Azure storage services

  • Describe Azure storage accounts
  • Describe Azure storage redundancy
  • Describe Azure storage services
  • Identify Azure data migration options
  • Identify Azure file movement options

Module 15: Implement security and manage access for Azure Storage

  • Configure storage account security settings
  • Select an authorization model for Azure Storage
  • Manage access with stored access policies
  • Disable Shared Key authorization and enforce with Azure Policy

Module 16: Configure network security for Azure Storage

  • Describe Azure Storage network security controls
  • Configure virtual network and IP rules
  • Configure resource instance rules and trusted services
  • Implement private endpoints for storage accounts

Module 17: Implement Microsoft Defender for Storage

  • Explore Microsoft Defender for Storage capabilities
  • Enable and deploy Defender for Storage
  • Configure malware scanning and sensitive data detection
  • Configure alert routing and validate Defender coverage

Module 18: Configure platform-level security for Azure SQL

  • Configure authentication and managed identity access
  • Implement network isolation
  • Encrypt and protect data in transit and at rest
  • Apply data masking and row-level security

Module 19: Configure auditing for Azure SQL Database and SQL Managed Instance

  • Describe Azure SQL auditing capabilities
  • Configure audit destinations for Azure SQL Database
  • Configure auditing for SQL Managed Instance
  • Design a compliant audit strategy

Module 20: Implement Microsoft Defender for Databases

  • Explore Microsoft Defender for Databases capabilities
  • Enable Defender for Azure SQL Databases at subscription scope
  • Enable Defender for open-source relational databases
  • Configure vulnerability assessment
  • Configure alert routing and validate coverage

Module 21: Segment and isolate Azure workloads using network security controls

  • Assess network segmentation gaps
  • Control traffic with network security groups (NSGs)
  • Simplify rule management with application security groups
  • Enforce consistent policy with Azure Virtual Network Manager
  • Verify effective network security rules with Network Watcher

Module 22: Centralize and enforce traffic inspection using Azure Firewall

  • Determine when centralized traffic inspection is required
  • Configure Azure Firewall rules and policies
  • Secure a Virtual WAN hub with Azure Firewall

Module 23: Secure remote and hybrid connectivity using VPN gateways and Microsoft Entra Private Access

  • Assess security risks in hybrid connectivity
  • Harden VPN gateway security
  • Replace broad VPN access with Microsoft Entra Private Access

Module 24: Eliminate public network exposure of Azure PaaS services

  • Assess the risk of public PaaS endpoint exposure
  • Configure private endpoints to eliminate public PaaS exposure
  • Expose internal services securely using Azure Private Link service
  • Enforce and audit private endpoint adoption

Module 25: Secure access for Microsoft Entra Agent Identity

  • Map authentication flows and Conditional Access scope
  • Configure Conditional Access policies for agents
  • Control agent access and lifecycle

Module 26: Analyze AI identity risks using Microsoft Defender XDR

  • Discover AI agents in the Microsoft Defender portal
  • Assess blast radius and attack paths

Module 27: Enable real-time protection for Copilot Studio agents

  • Explore Copilot Studio AI agent protection
  • Enable protection in Microsoft Defender
  • Review AI agent protection outputs

Module 28: Configure AI Gateway security in Microsoft Foundry

  • Examine AI Gateway architecture
  • Create and configure AI Gateway
  • Secure and monitor AI Gateway access

Module 29: Configure and manage guardrails in Microsoft Foundry

  • Understand guardrails and Microsoft Content Safety
  • Understand safety controls in Microsoft Foundry
  • Try out built-in guardrails
  • Create and manage blocklists in Microsoft Foundry
  • Configure and apply guardrails in Microsoft Foundry
  • Choose and refine the right guardrails for your AI workloads

Module 30: Protect AI workloads with Microsoft Defender for Cloud

  • Enable the AI workloads plan
  • Review insights in the Data & AI security dashboard
  • Assess and improve AI security posture with Cloud Security Posture Management (CSPM)
  • Detect AI threats at runtime with Cloud Workload Protection (CWP)
  • Investigate AI security alerts with prompt evidence in Microsoft Defender XDR

Module 31: Enable Defender for AI Services workload protection in Microsoft Defender for Cloud

  • Enable and configure the Defender for AI Services plan
  • Monitor AI security with the Data and AI dashboard

Module 32: Manage agents using Microsoft Agent 365

  • Enable and navigate Microsoft Agent 365
  • Register agents and apply access controls
  • Monitor agent activity and enforce governance

Module 33: Identify AI data risks using Microsoft Purview Data Security Posture Management

  • Configure Data Security Posture Management (DSPM) for AI
  • Assess SharePoint overexposure
  • Identify risks in Copilot and AI app interactions

Module 34: Implement disk encryption for Azure virtual machines

  • Choose the right disk encryption option for Azure VMs
  • Configure encryption at host with customer-managed keys
  • Apply confidential disk encryption to confidential virtual machines

Module 35: Configure trusted launch security features for Azure virtual machines

  • Identify Trusted Launch components and VM security types
  • Enable Trusted Launch on new and existing Gen2 VMs
  • Migrate Gen1 VMs and configure Trusted Launch components
  • Enforce Trusted Launch adoption with Azure Policy

Module 36: Plan and implement Azure Bastion

  • Plan Azure Bastion deployment
  • Deploy and configure Azure Bastion
  • Connect to VMs through Azure Bastion

Module 37: Manage security for Arc-enabled hybrid servers

  • Control access and extension security for Arc-enabled servers
  • Apply Azure Policy to Arc-enabled servers
  • Monitor Arc server security posture in Defender for Cloud

Module 38: Implement Microsoft Defender for Servers

  • Onboard servers to Defender for Servers
  • Configure vulnerability scanning with Defender Vulnerability Management
  • Configure Defender for Endpoint integration, agentless scanning, and File Integrity Monitoring

Module 39: Enable and enforce just-in-time VM access

  • Examine just-in-time VM access requirements and VM eligibility
  • Enable and configure JIT access policies
  • Request Just-in-time (JIT) access and audit access activity

Module 40: Enforce VM security configuration with Azure Machine Configuration

  • Explore Azure Machine Configuration extension capabilities and modes
  • Apply built-in security baseline policies
  • Author and assign custom machine configurations

Module 41: Detect container risks using Microsoft Defender for Containers

  • Explore Microsoft Defender for Containers
  • Enable and configure Defender for Containers
  • Assess container image vulnerabilities
  • Detect container runtime threats and misconfigurations

Module 42: Implement security controls for Azure Kubernetes Service

  • Control AKS cluster access with Microsoft Entra ID and RBAC
  • Secure AKS network access
  • Implement workload identity and secrets management for AKS
  • Enforce pod and container security

Module 43: Implement security controls for Azure Container Registry, Container Instances, and Container Apps

  • Secure Azure Container Registry
  • Implement security controls for Azure Container Instances
  • Implement security controls for Azure Container Apps

Module 44: Implement security controls for Azure Function apps and Logic apps

  • Configure authentication and authorization for Function apps
  • Secure network access for Function apps
  • Implement security controls for Logic apps

Module 45: Implement security controls for Azure App Services and Web Application Firewall

  • Implement security controls for Azure App Service
  • Configure Web Application Firewall policies
  • Protect App Service with Web Application Firewall

Module 46: Implement API backend security using Azure API Management

  • Configure API authentication and authorization policies
  • Implement API network security and threat protection
  • Secure API Management backend connections
  • Configure AI Gateway in API Management for Azure AI Foundry

Module 47: Connect hybrid and multicloud environments to Microsoft Defender for Cloud

  • Explore the Defender for Cloud multicloud connectivity model
  • Plan a connector strategy for hybrid and multicloud environments
  • Connect on-premises machines using Azure Arc
  • Connect AWS accounts to Defender for Cloud
  • Connect GCP projects to Defender for Cloud
  • Verify multicloud coverage and validate protection

Module 48: Identify security risks by using Cloud Security Posture Management

  • Explore CSPM plans and posture visibility
  • Analyze security recommendations with risk prioritization
  • Identify attack paths and choke points
  • Hunt for risks with cloud security explorer

Module 49: Discover unprotected assets and vulnerabilities by using Microsoft Defender External Attack Surface Management

  • Explore EASM features and capabilities
  • Discover assets using recursive discovery
  • Analyze your attack surface with dashboards
  • Integrate EASM insights with Defender for Cloud

Module 50: Evaluate regulatory compliance in Defender for Cloud

  • Understand compliance standards and controls in Defender for Cloud
  • Navigate the regulatory compliance dashboard and investigate control gaps
  • Assign standards and communicate compliance posture

Module 51: Enable and configure workload protection plans in Microsoft Defender for Cloud

  • Understand the Defender for Cloud CWPP plan catalog
  • Enable workload protection plans in Environment Settings
  • Configure Defender for Storage and Defender for Databases
  • Deploy plans at scale and verify coverage

Module 52: Configure Microsoft Defender Vulnerability Management settings for Azure VMs

  • Explore Microsoft Defender Vulnerability Management (MDVM) integration with Defender for Servers
  • Configure vulnerability scanning for Azure VMs
  • Review and manage vulnerability findings
  • Apply Plan 2 premium MDVM capabilities

Module 53: Create and manage Microsoft Sentinel workspaces

  • Plan for the Microsoft Sentinel workspace
  • Create a Microsoft Sentinel workspace
  • Manage workspaces across tenants using Azure Lighthouse
  • Understand Microsoft Sentinel permissions and roles
  • Manage Microsoft Sentinel settings
  • Configure logs

Module 54: Manage content in Microsoft Sentinel

  • Use solutions from the content hub
  • Use repositories for deployment

Module 55: Connect Microsoft services to Microsoft Sentinel

  • Plan for Microsoft services connectors
  • Connect the Microsoft 365 connector
  • Connect the Microsoft Entra connector
  • Connect the Microsoft Entra ID Protection connector
  • Connect the Azure Activity connector

Module 56: Connect syslog data sources to Microsoft Sentinel

  • Plan for syslog data collection
  • Collect data from Linux-based sources using syslog
  • Configure the Data Collection Rule for Syslog Data Sources
  • Parse syslog data with KQL

Module 57: Connect Common Event Format logs to Microsoft Sentinel

  • Plan for Common Event Format connector
  • Connect your external solution using the Common Event Format connector

Module 58: Connect Windows hosts to Microsoft Sentinel

  • Plan for Windows hosts security events connector
  • Connect using the Windows Security Events via AMA Connector
  • Connect using the Security Events via Legacy Agent Connector
  • Collect Sysmon event logs

Module 59: Implement automation rules and playbooks in Microsoft Sentinel

  • Understand Microsoft Sentinel automation options
  • Create automation rules in Microsoft Sentinel
  • Configure and activate a Content Hub playbook
  • Author a custom playbook with Azure Logic Apps

Module 60: Manage data storage and query audit logs in Microsoft Sentinel

  • Create custom log tables in Microsoft Sentinel
  • Implement data retention in Microsoft Sentinel
  • Connect Microsoft Purview Audit to Microsoft Sentinel
  • Query Purview Audit logs in Microsoft Defender XDR

Module 61: Describe Microsoft Security Copilot

  • Get acquainted with Microsoft Security Copilot
  • Describe Microsoft Security Copilot terminology
  • Describe how Microsoft Security Copilot processes prompt requests
  • Describe the elements of an effective prompt
  • Describe how to enable Microsoft Security Copilot

Module 62: Configure workspaces for Microsoft Security Copilot

  • Plan a workspace deployment
  • Create a Security Copilot workspace
  • Configure workspace access and settings
  • Assign workspaces for integrated agents
  • Monitor and manage workspace capacity

Module 63: Manage plugins and agents in Microsoft Security Copilot

  • Configure plugin settings in Security Copilot
  • Discover and set up Microsoft-built agents
  • Acquire and configure partner agents from Security Store
  • Manage Security Copilot agents

Documentation

  • Access to Microsoft Learn, Microsoft’s online learning platform, offering interactive resources and educational content to deepen your knowledge and develop your technical skills.

Lab / Exercises

  • This course provides you with exclusive access to the official Microsoft lab, enabling you to practice your skills in a professional environment.

Exam

  • This course prepares you to the SC-500: Cloud and AI Security Engineer Associate exam.

Complementary Courses

Eligible Funding

ITTA is a partner of a continuing education fund dedicated to temporary workers. This fund can subsidize your training, provided that you are subject to the “Service Provision” collective labor agreement (CCT) and meet certain conditions, including having worked at least 88 hours in the past 12 months.

Additional Information

SC-500 Training: Secure Cloud and AI Workloads

Cloud security no longer stops at virtual machines and virtual networks. Organisations now run copilots, conversational agents and language models that handle sensitive business data, call internal APIs and act on behalf of users. Every agent becomes an identity to govern, every prompt a potential path for data leakage. The SC-500 training answers that reality by covering Azure platform security and AI workload security in a single journey.

The course runs over four days in Geneva or Lausanne, in the classroom or in a virtual class. It targets professionals who already operate an Azure environment and now have to guarantee its security posture, from identity control through to the monitoring of AI models deployed in Microsoft Foundry.

What SC-500 changes compared with AZ-500

SC-500 succeeds AZ-500, retired by Microsoft on 31 August 2026. The foundation remains: identity and privileged access management, storage and database protection, network security, policy driven governance and monitoring with Microsoft Sentinel. That foundation is completed by a brand new AI scope: agent identities in Microsoft Entra, guardrails and blocklists in Microsoft Foundry, AI gateway security, real time protection for Copilot Studio agents, agent governance with Microsoft Agent 365 and data risk assessment with Microsoft Purview Data Security Posture Management.

The related certification changes name as well. Microsoft Certified: Azure Security Engineer Associate gives way to Microsoft Certified: Cloud and AI Security Engineer Associate, earned by passing the SC-500 exam. For an engineer already holding AZ-500, SC-500 is the natural route to stay aligned with the current Microsoft catalogue.

A hardened Azure foundation, from network to applications

The first part of the outline revisits Azure security fundamentals and treats them at an operational level of detail. You configure multifactor and passwordless authentication, deploy just in time access with Privileged Identity Management, and right size RBAC role assignments to enforce least privilege. Azure Key Vault is covered in depth: deployment, firewall rules, key rotation, certificate management and audit logging.

Storage and database protection follow, then network isolation with security groups, Azure Firewall, Azure Virtual Network Manager and private endpoints, then the hardening of virtual machines, containers, Azure Kubernetes Service, web applications and APIs. Every building block is tied back to the overall posture measured in Microsoft Defender for Cloud, including resources hosted on AWS, GCP or on premises through Azure Arc.

AI workload security and security operations with Sentinel

The AI section carries significant weight. You discover the agents deployed in your tenant from the Microsoft Defender portal, assess their blast radius and attack paths, enable real time protection for Copilot Studio agents and configure Microsoft Foundry guardrails. The Defender for Cloud AI workloads plan provides the alerts, the prompt evidence and the Data and AI dashboard needed to investigate an incident involving a model.

The operations section covers Microsoft Sentinel workspace creation, Microsoft 365, Entra, Syslog, CEF and Windows connectors, automation rules and Logic Apps playbooks, data retention and audit log queries. The course closes with Microsoft Security Copilot: workspaces, plugins, embedded agents and effective prompt writing.

Why a guided course beats self study

The official outline holds 63 modules for four days. That is a lot of ground, and it is exactly where a guided course pays off: the trainer sets priorities, drills into the topics that matter for your context and leaves aside what belongs to personal reading. Self study is possible, but Microsoft documentation is scattered and the AI portion evolves too quickly to follow without a clear thread. In class you gain a structured view in four days, official labs and the chance to test your real scenarios with a certified trainer.

To cover the whole Microsoft security domain, two ITTA courses complement SC-500 naturally: SC-200, focused on security operations, threat hunting and incident response, and SC-300, dedicated to identity governance in Microsoft Entra. After the course, book the SC-500 exam within four to six weeks, replay the labs on a test subscription and apply two or three Defender for Cloud recommendations to your production environment as soon as possible.

FAQ

Does SC-500 really replace AZ-500?

Yes. Microsoft retired AZ-500 on 31 August 2026 and SC-500 becomes the reference course for cloud workload security. The Azure content is kept and extended with AI security.

Do I need the AZ-500 certification before attending SC-500?

No. Practical Azure administration experience along with identity, networking and encryption concepts is enough. AZ-500 certified attendees will mainly gain the new material on AI agents and models.

How does it differ from SC-200?

SC-500 is about designing and configuring security controls, so about prevention. SC-200 is about detection, investigation and response inside a security operations centre. The two paths complement each other.

Are all 63 modules covered in four days?

The official outline is deliberately broad. The trainer covers every exam domain and goes deeper on the modules that matter most to the group, while the remaining ones are outlined and pointed to the official material for personal study.

Is the course available as a virtual class?

Yes. It is offered in the classroom in Geneva and Lausanne and as an interactive virtual class, with the same outline, the same official Microsoft labs and the same certified trainer.

Does SC-500 help with Swiss data protection requirements?

The controls covered (encryption, access management, classification, logging, regulatory compliance in Defender for Cloud) map directly onto nFADP and GDPR expectations, including for generative AI use cases.

Prix de l'inscription
CHF 3'000.-
Inclus dans ce cours
  • Training provided by a certified trainer
  • 180 days of access to Official Microsoft Labs
  • Official documentation in digital format
  • Official Microsoft achievement badge

 

Mois actuel

lun12Oct(Oct 12)09:00jeu15(Oct 15)17:00VirtuelVirtual Etiquettes de sessionSC-500T00

lun12Oct(Oct 12)09:00jeu15(Oct 15)17:00Genève, Route des Jeunes 35, 1227 Genève Etiquettes de sessionSC-500T00

lun16Nov(Nov 16)09:00jeu19(Nov 19)17:00VirtuelVirtual Etiquettes de sessionSC-500T00

lun16Nov(Nov 16)09:00jeu19(Nov 19)17:00Lausanne, Av. Mon-Repos 24, 1005 Lausanne Etiquettes de sessionSC-500T00

lun07Déc(Déc 7)09:00jeu10(Déc 10)17:00VirtuelVirtual Etiquettes de sessionSC-500T00

lun07Déc(Déc 7)09:00jeu10(Déc 10)17:00Genève, Route des Jeunes 35, 1227 Genève Etiquettes de sessionSC-500T00

Contact

ITTA
Route des jeunes 35
1227 Carouge, Suisse

Opening hours

Monday to Friday
8:30 AM to 6:00 PM
Tel. 058 307 73 00

Contact-us

ITTA
Route des jeunes 35
1227 Carouge, Suisse

Make a request

Contact

ITTA
Route des jeunes 35
1227 Carouge, Suisse

Opening hours

Monday to Friday, from 8:30 am to 06:00 pm.

Contact us

Your request