Microtek Logo
☎ Call Us
Microsoft Logo

SC-500T00: Implement End-to-End Security Controls for Cloud and AI Workloads Training

Learn to secure Azure, Microsoft 365, and AI workloads end to end with Microsoft security technologies and Zero Trust principles. 4-day official Microsoft course, aligned to Exam SC-500.

📘 Azure 👥 1958 Enrolled ⏱️ 4 Days 💼 Intermediate Level ⭐ 5 | 345 Reviews

Why Microtek Learning?

500+

Courses

10+ Years

Experience

95K+

Global Learners

Virtual Instructor-Led Training

$2195
|

Course Overview

Cloud security used to mean securing infrastructure. Now it also means securing the AI workloads and autonomous agents running on top of it, and that shift is exactly what this course was built for. SC-500T00 is Microsoft's successor to AZ-500T00, redesigned for security engineers who protect Azure and Microsoft 365 environments where AI is part of the attack surface.

Over four days of instructor-led sessions and hands-on labs, you will design, implement, and manage security controls across the full stack: identity and access with Microsoft Entra, secrets protection with Azure Key Vault, security for storage, databases, networks, virtual machines, and application platforms, and posture management with Microsoft Defender for Cloud. You will work with threat detection and response through Microsoft Sentinel and Defender XDR, bring Microsoft Security Copilot into your workflow, apply data security controls with Microsoft Purview, and run it all on Zero Trust principles. Throughout, the course treats AI workloads as first-class assets to secure, covering the platforms, data, identities, and infrastructure that AI services depend on.

The course prepares you for Exam SC-500 and the Microsoft Certified: Cloud and AI Security Engineer Associate credential, the certification replacing the retiring Azure Security Engineer Associate (AZ-500) path.

Mode of Training

🏫 Classroom 💻 Live Online 🧪 Blended 👨‍👩‍👧‍👦 Private Group

Upcoming Schedules

Start Date Time Duration Mode Price
Aug 04, 2026 9:00 am - 5:00 pm 4 Days online
$2195
Aug 18, 2026 9:00 am - 5:00 pm 4 Days online
$2195
Sep 01, 2026 9:00 am - 5:00 pm 4 Days online
$2195
Sep 15, 2026 9:00 am - 5:00 pm 4 Days online
$2195
Sep 29, 2026 9:00 am - 5:00 pm 4 Days online
$2195
+ View more schedules

What you will learn

  • Secure access to cloud resources using Microsoft Entra Protect secrets, keys, and certificates with Azure Key Vault, applied with defense in depth for cloud and AI workloads Enforce security governance and regulatory compliance across environments Implement security controls for Azure Storage, databases, networks, virtual machines, and application platforms Strengthen and monitor security posture with Microsoft Defender for Cloud Detect and respond to threats using Microsoft Sentinel and Defender XDR, assisted by Microsoft Security Copilot Protect the data, identities, and infrastructure behind AI workloads and autonomous agents Apply Zero Trust principles end to end across cloud, hybrid, and multi-cloud environments

Who Should Attend This Course?

Security engineers responsible for planning and implementing security controls across cloud, hybrid, and multi-cloud environments using Microsoft security technologies. In this role you prevent unauthorized access, mitigate risk proactively, and increasingly own the security of AI platforms and the data they touch. You work alongside architects, administrators, analysts, developers, and DevOps teams across Azure, Microsoft 365, identity, information protection, and security operations. The course also suits Azure administrators and infrastructure engineers moving into a dedicated security role, and current AZ-500 candidates transitioning to the new certification path.

Prerequisites

  • Practical experience administering Microsoft Azure and hybrid environments, including compute, networking, and storage
  • Strong familiarity with Microsoft Entra ID
  • Working knowledge of Microsoft 365 administration

If you are newer to Azure administration, consider building that foundation first through an Azure administrator course before taking on SC-500T00.

📞 Talk to a Learning Advisor

Please enter Name
Please enter a valid email address.
Please enter a valid phone number in international format (e.g., +14155552671).
Please enter Message
Please agree to I agree to Terms & Privacy Policy*.
Please agree to I authorize Microtek Learning to contact me via Phone/Email*.

Certification

This course aligns to Exam SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, which leads to the Microsoft Certified: Cloud and AI Security Engineer Associate credential. SC-500 is the successor to the retiring AZ-500 exam, and this certification is the forward path for professionals who would previously have pursued Azure Security Engineer Associate.

📘 SC-500T00: Implement End-to-End Security Controls for Cloud and AI Workloads Outline

Manage and Implement Authentication Methods in Microsoft Entra ID

  • Introduction
  • Explore Microsoft Entra ID Authentication Methods
  • Configure Multifactor Authentication in Microsoft Entra ID
  • Implement Passwordless Authentication in Microsoft Entra ID
  • Configure Self-Service Password Reset in Microsoft Entra ID
  • Exercise – Configure Authentication Methods in Microsoft Entra ID

Implement and Configure Privileged Identity Management (PIM)

  • Introduction
  • Why Privileged Identity Management and Just-in-Time Access Matter
  • Core Capabilities of Privileged Identity Management (PIM)
  • Implement Just-in-Time Access for Microsoft Entra Roles
  • Implement Just-in-Time Access for Azure Roles and Resources
  • Scaling with PIM for Groups
  • Applying JIT Access to AI Workloads, Agents, and Applications
  • JIT Design Patterns and Best Practices

Authenticate Your API Plugin for Declarative Agents with Secured APIs

  • Introduction
  • Integrate an API Plugin with an API Secured with a Key
  • Exercise – Integrate an API Plugin with an API Secured with a Key
  • Integrate an API Plugin with an API Secured with OAuth
  • Exercise – Integrate an API Plugin with an API Secured with OAuth

Configure and Secure Azure Key Vault

  • Introduction
  • Deploy Azure Key Vault with Security Controls
  • Configure Access to Azure Key Vault
  • Configure Key Vault Firewall and Network Settings

Manage Keys and Secrets in Azure Key Vault

  • Introduction
  • Manage Cryptographic Keys in Azure Key Vault
  • Manage Secrets in Azure Key Vault

Manage Certificates and Monitor Azure Key Vault

  • Introduction
  • Manage Certificates in Azure Key Vault
  • Enable Key Vault Audit Logging

Protect Azure Key Vault with Microsoft Defender for Cloud

  • Introduction
  • Scan for Exposed Secrets Using Defender Cloud Security Posture Management (CSPM)
  • Enable Microsoft Defender for Key Vault
  • Investigate and Respond to Defender for Key Vault Alerts

Enforce Governance with Azure Policy and Resource Locks

  • Introduction
  • Assign Built-In Azure Policy Definitions
  • Create and Deploy Custom Policy Definitions
  • Implement Resource Locks

Configure Security Controls and Remediate Recommendations in Defender for Cloud

  • Introduction
  • Configure Defender for Cloud and Manage Security Standards
  • Deploy Remediation Controls at Scale

Evaluate Regulatory Compliance in Defender for Cloud

  • Introduction
  • Understand Compliance Standards and Controls in Defender for Cloud
  • Navigate the Regulatory Compliance Dashboard and Investigate Control Gaps
  • Assign Standards and Communicate Compliance Posture

Manage and Right-Size RBAC Role Assignments for Least Privilege

  • Introduction
  • Assign and Manage Azure Built-In Roles
  • Create Custom Azure Roles and Microsoft Entra Roles
  • Evaluate and Remediate Overprivileged Access

Protect Backup Data with Azure Backup Security Features

  • Introduction
  • Enable Soft Delete and Immutable Vaults
  • Configure Multi-User Authorization and RBAC for Backup

Implement Security Controls in Infrastructure as Code

  • Introduction
  • Scan IaC Templates Using Microsoft Defender for DevOps
  • Enforce Policy Compliance in IaC Deployments

Describe Azure Storage Services

  • Introduction
  • Describe Azure Storage Accounts
  • Describe Azure Storage Redundancy
  • Describe Azure Storage Services
  • Identify Azure Data Migration Options
  • Identify Azure File Movement Options

Implement Security and Manage Access for Azure Storage

  • Introduction
  • Configure Storage Account Security Settings
  • Select an Authorization Model for Azure Storage
  • Manage Access with Stored Access Policies
  • Disable Shared Key Authorization and Enforce with Azure Policy

Configure Network Security for Azure Storage

  • Introduction
  • Describe Azure Storage Network Security Controls
  • Configure Virtual Network and IP Rules
  • Configure Resource Instance Rules and Trusted Services
  • Implement Private Endpoints for Storage Accounts

Implement Microsoft Defender for Storage

  • Introduction
  • Explore Microsoft Defender for Storage Capabilities
  • Enable and Deploy Defender for Storage
  • Configure Malware Scanning and Sensitive Data Detection
  • Configure Alert Routing and Validate Defender Coverage

Configure Platform-Level Security for Azure SQL

  • Introduction
  • Configure Authentication and Managed Identity Access
  • Implement Network Isolation
  • Encrypt and Protect Data in Transit and at Rest
  • Apply Data Masking and Row-Level Security

Configure Auditing for Azure SQL Database and SQL Managed Instance

  • Introduction
  • Describe Azure SQL Auditing Capabilities
  • Configure Audit Destinations for Azure SQL Database
  • Configure Auditing for SQL Managed Instance
  • Design a Compliant Audit Strategy

Implement Microsoft Defender for Databases

  • Introduction
  • Explore Microsoft Defender for Databases Capabilities
  • Enable Defender for Azure SQL Databases at Subscription Scope
  • Enable Defender for Open-Source Relational Databases
  • Configure Vulnerability Assessment
  • Configure Alert Routing and Validate Coverage

Segment and Isolate Azure Workloads Using Network Security Controls

  • Introduction
  • Assess Network Segmentation Gaps
  • Control Traffic with Network Security Groups (NSGs)
  • Simplify Rule Management with Application Security Groups
  • Enforce Consistent Policy with Azure Virtual Network Manager
  • Verify Effective Network Security Rules with Network Watcher

Centralize and Enforce Traffic Inspection Using Azure Firewall

  • Introduction
  • Determine When Centralized Traffic Inspection Is Required
  • Configure Azure Firewall Rules and Policies
  • Secure a Virtual WAN Hub with Azure Firewall

Secure Remote and Hybrid Connectivity Using VPN Gateways and Microsoft Entra Private Access

  • Introduction
  • Assess Security Risks in Hybrid Connectivity
  • Harden VPN Gateway Security
  • Replace Broad VPN Access with Microsoft Entra Private Access

Eliminate Public Network Exposure of Azure PaaS Services

  • Introduction
  • Assess the Risk of Public PaaS Endpoint Exposure
  • Configure Private Endpoints to Eliminate Public PaaS Exposure
  • Expose Internal Services Securely Using Azure Private Link Service
  • Enforce and Audit Private Endpoint Adoption

Secure Access for Microsoft Entra Agent Identity

  • Introduction
  • Map Authentication Flows and Conditional Access Scope
  • Configure Conditional Access Policies for Agents
  • Control Agent Access and Lifecycle

Analyze AI Identity Risks Using Microsoft Defender XDR

  • Introduction
  • Discover AI Agents in the Microsoft Defender Portal
  • Assess Blast Radius and Attack Paths

Enable Real-Time Protection for Copilot Studio Agents

  • Introduction
  • Explore Copilot Studio AI Agent Protection
  • Enable Protection in Microsoft Defender
  • Review AI Agent Protection Outputs

Configure AI Gateway Security in Microsoft Foundry

  • Introduction
  • Examine AI Gateway Architecture
  • Create and Configure AI Gateway
  • Secure and Monitor AI Gateway Access

Configure and Manage Guardrails in Microsoft Foundry

  • Introduction
  • Understand Guardrails and Microsoft Content Safety
  • Understand Safety Controls in Microsoft Foundry
  • Try Out Built-In Guardrails
  • Create and Manage Blocklists in Microsoft Foundry
  • Configure and Apply Guardrails in Microsoft Foundry
  • Choose and Refine the Right Guardrails for Your AI Workloads

Protect AI Workloads with Microsoft Defender for Cloud

  • Introduction
  • Enable the AI Workloads Plan
  • Review Insights in the Data & AI Security Dashboard
  • Assess and Improve AI Security Posture with Cloud Security Posture Management (CSPM)
  • Detect AI Threats at Runtime with Cloud Workload Protection (CWP)
  • Investigate AI Security Alerts with Prompt Evidence in Microsoft Defender XDR

Enable Defender for AI Services Workload Protection in Microsoft Defender for Cloud

  • Introduction
  • Enable and Configure the Defender for AI Services Plan
  • Monitor AI Security with the Data and AI Dashboard

Manage Agents Using Microsoft Agent 365

  • Introduction
  • Enable and Navigate Microsoft Agent 365
  • Register Agents and Apply Access Controls
  • Monitor Agent Activity and Enforce Governance

Identify AI Data Risks Using Microsoft Purview Data Security Posture Management

  • Introduction
  • Configure Data Security Posture Management (DSPM) for AI
  • Assess SharePoint Overexposure
  • Identify Risks in Copilot and AI App Interactions

Implement Disk Encryption for Azure Virtual Machines

  • Introduction
  • Choose the Right Disk Encryption Option for Azure VMs
  • Configure Encryption at Host with Customer-Managed Keys
  • Apply Confidential Disk Encryption to Confidential Virtual Machines

Configure Trusted Launch Security Features for Azure Virtual Machines

  • Introduction
  • Identify Trusted Launch Components and VM Security Types
  • Enable Trusted Launch on New and Existing Gen2 VMs
  • Migrate Gen1 VMs and Configure Trusted Launch Components
  • Enforce Trusted Launch Adoption with Azure Policy

Plan and Implement Azure Bastion

  • Introduction
  • Plan Azure Bastion Deployment
  • Deploy and Configure Azure Bastion
  • Connect to VMs Through Azure Bastion

Manage Security for Arc-Enabled Hybrid Servers

  • Introduction
  • Control Access and Extension Security for Arc-Enabled Servers
  • Apply Azure Policy to Arc-Enabled Servers
  • Monitor Arc Server Security Posture in Defender for Cloud

Implement Microsoft Defender for Servers

  • Introduction
  • Onboard Servers to Defender for Servers
  • Configure Vulnerability Scanning with Defender Vulnerability Management
  • Configure Defender for Endpoint Integration, Agentless Scanning, and File Integrity Monitoring

Enable and Enforce Just-in-Time VM Access

  • Introduction
  • Examine Just-in-Time VM Access Requirements and VM Eligibility
  • Enable and Configure JIT Access Policies
  • Request Just-in-Time (JIT) Access and Audit Access Activity

Enforce VM Security Configuration with Azure Machine Configuration

  • Introduction
  • Explore Azure Machine Configuration Extension Capabilities and Modes
  • Apply Built-In Security Baseline Policies
  • Author and Assign Custom Machine Configurations

Detect Container Risks Using Microsoft Defender for Containers

  • Introduction
  • Explore Microsoft Defender for Containers
  • Enable and Configure Defender for Containers
  • Assess Container Image Vulnerabilities
  • Detect Container Runtime Threats and Misconfigurations

Implement Security Controls for Azure Kubernetes Service

  • Introduction
  • Control AKS Cluster Access with Microsoft Entra ID and RBAC
  • Secure AKS Network Access
  • Implement Workload Identity and Secrets Management for AKS
  • Enforce Pod and Container Security

Implement Security Controls for Azure Container Registry, Container Instances, and Container Apps

  • Introduction
  • Secure Azure Container Registry
  • Implement Security Controls for Azure Container Instances
  • Implement Security Controls for Azure Container Apps

Implement Security Controls for Azure Function Apps and Logic Apps

  • Introduction
  • Configure Authentication and Authorization for Function Apps
  • Secure Network Access for Function Apps
  • Implement Security Controls for Logic Apps

Implement Security Controls for Azure App Services and Web Application Firewall

  • Introduction
  • Implement Security Controls for Azure App Service
  • Configure Web Application Firewall Policies
  • Protect App Service with Web Application Firewall

Implement API Backend Security Using Azure API Management

  • Introduction
  • Configure API Authentication and Authorization Policies
  • Implement API Network Security and Threat Protection
  • Secure API Management Backend Connections
  • Configure AI Gateway in API Management for Azure AI Foundry

Connect Hybrid and Multicloud Environments to Microsoft Defender for Cloud

  • Introduction
  • Explore the Defender for Cloud Multicloud Connectivity Model
  • Plan a Connector Strategy for Hybrid and Multicloud Environments
  • Connect On-Premises Machines Using Azure Arc
  • Connect AWS Accounts to Defender for Cloud
  • Connect GCP Projects to Defender for Cloud
  • Verify Multicloud Coverage and Validate Protection

Identify Security Risks by Using Cloud Security Posture Management

  • Introduction
  • Explore CSPM Plans and Posture Visibility
  • Analyze Security Recommendations with Risk Prioritization
  • Identify Attack Paths and Choke Points
  • Hunt for Risks with Cloud Security Explorer

Discover Unprotected Assets and Vulnerabilities by Using Microsoft Defender External Attack Surface Management

  • Introduction
  • Explore EASM Features and Capabilities
  • Discover Assets Using Recursive Discovery
  • Analyze Your Attack Surface with Dashboards
  • Integrate EASM Insights with Defender for Cloud

Evaluate Regulatory Compliance in Defender for Cloud

  • Introduction
  • Understand Compliance Standards and Controls in Defender for Cloud
  • Navigate the Regulatory Compliance Dashboard and Investigate Control Gaps
  • Assign Standards and Communicate Compliance Posture

Enable and Configure Workload Protection Plans in Microsoft Defender for Cloud

  • Introduction
  • Understand the Defender for Cloud CWPP Plan Catalog
  • Enable Workload Protection Plans in Environment Settings
  • Configure Defender for Storage and Defender for Databases
  • Deploy Plans at Scale and Verify Coverage

Configure Microsoft Defender Vulnerability Management Settings for Azure VMs

  • Introduction
  • Explore Microsoft Defender Vulnerability Management (MDVM) Integration with Defender for Servers
  • Configure Vulnerability Scanning for Azure VMs
  • Review and Manage Vulnerability Findings
  • Apply Plan 2 Premium MDVM Capabilities

Create and Manage Microsoft Sentinel Workspaces

  • Introduction
  • Plan for the Microsoft Sentinel Workspace
  • Create a Microsoft Sentinel Workspace
  • Manage Workspaces Across Tenants Using Azure Lighthouse
  • Understand Microsoft Sentinel Permissions and Roles
  • Manage Microsoft Sentinel Settings
  • Configure Logs

Manage Content in Microsoft Sentinel

  • Introduction
  • Use Solutions from the Content Hub
  • Use Repositories for Deployment

Connect Microsoft Services to Microsoft Sentinel

  • Introduction
  • Plan for Microsoft Services Connectors
  • Connect the Microsoft 365 Connector
  • Connect the Microsoft Entra Connector
  • Connect the Microsoft Entra ID Protection Connector
  • Connect the Azure Activity Connector

Connect Syslog Data Sources to Microsoft Sentinel

  • Introduction
  • Plan for Syslog Data Collection
  • Collect Data from Linux-Based Sources Using Syslog
  • Configure the Data Collection Rule for Syslog Data Sources
  • Parse Syslog Data with KQL
  • Module Assessment
  • Summary and Resources

Connect Common Event Format Logs to Microsoft Sentinel

  • Introduction
  • Plan for Common Event Format Connector
  • Connect Your External Solution Using the Common Event Format Connector

Connect Windows Hosts to Microsoft Sentinel

  • Introduction
  • Plan for Windows Hosts Security Events Connector
  • Connect Using the Windows Security Events via AMA Connector
  • Connect Using the Security Events via Legacy Agent Connector
  • Collect Sysmon Event Logs

Implement Automation Rules and Playbooks in Microsoft Sentinel

  • Introduction
  • Understand Microsoft Sentinel Automation Options
  • Create Automation Rules in Microsoft Sentinel
  • Configure and Activate a Content Hub Playbook
  • Author a Custom Playbook with Azure Logic Apps

Manage Data Storage and Query Audit Logs in Microsoft Sentinel

  • Introduction
  • Create Custom Log Tables in Microsoft Sentinel
  • Implement Data Retention in Microsoft Sentinel
  • Connect Microsoft Purview Audit to Microsoft Sentinel
  • Query Microsoft Purview Audit Logs in Microsoft Defender XDR

Describe Microsoft Security Copilot

  • Introduction
  • Get Acquainted with Microsoft Security Copilot
  • Describe Microsoft Security Copilot Terminology
  • Describe How Microsoft Security Copilot Processes Prompt Requests
  • Describe the Elements of an Effective Prompt
  • Describe How to Enable Microsoft Security Copilot

Configure Workspaces for Microsoft Security Copilot

  • Introduction
  • Plan a Workspace Deployment
  • Create a Security Copilot Workspace
  • Configure Workspace Access and Settings
  • Assign Workspaces for Integrated Agents
  • Monitor and Manage Workspace Capacity

Manage Plugins and Agents in Microsoft Security Copilot

  • Introduction
  • Configure Plugin Settings in Security Copilot
  • Discover and Set Up Microsoft-Built Agents
  • Acquire and Configure Partner Agents from Security Store
  • Manage Security Copilot Agents

❓ Frequently Asked Questions

Should I still take it? Microsoft is retiring the AZ-500 exam, and SC-500 is its replacement. If you are starting your security certification journey now, SC-500 is the exam to target: it covers the AZ-500 security domains and extends them into AI workload security, which is where the role is heading. If you already hold the Azure Security Engineer Associate certification, check Microsoft's transition guidance for how your credential carries forward.

The core Azure security engineering skills remain: identity, networking, compute, data, and posture management. What's new is the AI layer. SC-500T00 treats AI workloads and autonomous agents as assets you must secure, and it folds in Microsoft Security Copilot, Purview data security for AI, and the newer Defender and Sentinel capabilities. It also frames everything explicitly around Zero Trust across cloud, hybrid, and multi-cloud environments.

Yes. The course combines instructor-led sessions with hands-on labs, so you implement the controls yourself rather than just seeing them demonstrated.

No. You need the Azure, Entra ID, and Microsoft 365 experience listed in the prerequisites. The AI security content is taught from the ground up; what the course assumes is that you can already administer the cloud environment those AI workloads run in.

Still have questions?

Reach out to our learning advisors for personalized guidance on choosing the right course, group training, or enterprise packages.

📞 Talk to an Advisor

What You Get with Microtek Learning

Instructor-Led Excellence

  • Certified Instructor-led Training
  • Top Industry Trainers
  • Official Student Handbooks

Measurable Learning Outcomes

  • Pre- & Post-Training Assessments
  • Practice Tests
  • Exam-Oriented Curriculum

Real-World Skill Building

  • Hands-on Activities & Scenarios
  • Interactive Online Courses
  • Peer Collaboration (Not in self-paced)

Full Support & Perks

  • Exam Scheduling Support *
  • Learn & Earn Program *
  • Support from Certified Experts
  • Gov. & Private Pricing *

Our Clients

For over 10 years, Microtek Learning has helped organizations, leaders, students and professionals to reach their maximum potential. We have led the path by addressing their challenges and advancing their performances.

Actemium
US Dept of Defense
Education Advisory Board
GE Digital
Department of Homeland Security
Pacific Life
MetLife
AIG
Chase
DC Gov
Johnson & Johnson
William Osler Health System
Google

Our Awards

Microsoft Award

Microsoft Learning
Partner of the Year

Inc 5000

5000 List of the Fastest-Growing Private Companies in America

Top IT Training

Top IT Training Companies
(Multiple Years)

Why We Are Best To Choose?

Team Support

Professional Team Support

Our expert counseling team provides round-the-clock assistance with the best value offers.

Experienced Trainers

Experienced Trainers

Certified trainers with 5–15 years of real-world industry experience guide your learning.

Satisfaction Guarantee

100% Satisfaction Guarantee

We guarantee satisfaction with top-quality content and instructor delivery.

Real-World Experience

Real-World Experience

Train with industry projects and curricula aligned to current standards.

Best Price Guarantee

Best Price Guarantee

We promise the lowest pricing and best offers in the market.

Guaranteed to Run

Guaranteed to Run

All courses are assured to run on scheduled dates via all delivery methods.

Azure Learning Resources

Explore our collection of free resources to boost your Azure learning journey

Blogs

Azure Expert Blogs

Explore insights from industry experts to stay ahead in tech—dive into our Expert Blogs now!

Read Blogs
Talk to Advisor