SC-500T00-A: Implement end‑to‑end security controls for cloud and AI workloads
Duration: 4 Days
This course prepares you to design, implement, and manage end-to-end security controls across Microsoft Azure and Microsoft 365 environments — including the emerging landscape of AI workloads and autonomous agents. Through a combination of instructor-led sessions and hands-on labs, you build practical skills in identity security, cloud infrastructure protection, threat detection, and posture management. This course is intended for security engineers who are responsible for planning and implementing security controls across cloud, hybrid, and multi-cloud environments using Microsoft security technologies.
As a candidate for this course, you’re a security engineer who protects organizational systems and data across cloud and hybrid environments by implementing comprehensive security controls that prevent unauthorized access and mitigate risks proactively. This role spans multiple security domains including identity, network, application, data, and compute. This role also ensures that platforms, data, identities, and infrastructure used by AI workloads are securely implemented and monitored. You work closely with architects, administrators, engineers, analysts, and developers responsible for Azure, Microsoft 365, identity and access, information protection, security operations, devops, application development, database platforms, and networks. You should have practical experience in administration of Microsoft Azure and hybrid environments, including compute, network, and storage. You should have strong familiarity with Microsoft Entra ID and familiarity with Microsoft 365 administration. Your responsibilities for this role include:
- Securing access to resources by using Microsoft Entra ID and Azure Key Vault
- Enforcing security and regulatory compliance
- Securing storage, databases, and networking
- Securing compute
- Securing AI solutions
- Managing and monitoring security posture
Manage and implement authentication methods in Microsoft Entra ID
Learn to plan, deploy, and manage secure authentication in Microsoft Entra ID. This module covers authentication methods, MFA with Conditional Access, passwordless options, and self-service password reset.
- Explore Microsoft Entra ID authentication methods
- Configure multifactor authentication in Microsoft Entra ID
- Implement passwordless authentication in Microsoft Entra ID
- Configure self-service password reset in Microsoft Entra ID
- Exercise - Configure authentication methods in Microsoft Entra ID
Implement and configure Privileged Identity Management (PIM)
Implement Just-in-Time privileged access using Privileged Identity Management (PIM) to reduce standing privilege across Microsoft Entra roles, Azure resources, and group-based access for cloud and AI environments.
- Why Privileged Identity Management and just-in-time access matter
- Core capabilities of Privileged Identity Management (PIM)
- Implement just-in-time access for Microsoft Entra roles
- Implement just-in-time access for Azure roles and resources
- Scaling with PIM for Groups
- Applying JIT access to AI workloads, agents, and applications
- JIT design patterns and best practices
Authenticate your API plugin for declarative agents with secured APIs
When building apps for work, you typically integrate with secured APIs. Learn about the two common ways of how APIs are secured – API key and OAuth2, and how to integrate with them when building an API plugin for declarative agents that run in Microsoft 365 Copilot.
- Integrate an API plugin with an API secured with a key
- Exercise - Integrate an API plugin with an API secured with a key
- Integrate an API plugin with an API secured with OAuth
- Exercise - Integrate an API plugin with an API secured with OAuth
Configure and secure Azure Key Vault
Configure a security-hardened Azure Key Vault for enterprise workloads. Apply soft delete and purge protection, enforce least-privilege RBAC access with just-in-time activation, and secure the network perimeter using firewall rules and private endpoints.
- Deploy Azure Key Vault with security controls
- Configure access to Azure Key Vault
- Configure Key Vault firewall and network settings
Manage keys and secrets in Azure Key Vault
Manage the security lifecycle of cryptographic keys and secrets in Azure Key Vault. Configure HSM-backed keys, implement Bring Your Own Key (BYOK) for regulatory scenarios, set up automated key rotation, and build zero-downtime secret rotation using dual-credential patterns.
- Manage cryptographic keys in Azure Key Vault
- Manage secrets in Azure Key Vault
- Knowledge check
Manage certificates and monitor Azure Key Vault
Manage certificate lifecycle in Azure Key Vault through integrated certificate authority issuance and autorenewal. Enable diagnostic logging to create an investigation-ready audit trail, configure log-based alert rules, and integrate Event Grid for real-time lifecycle automation.
- Manage certificates in Azure Key Vault
- Enable Key Vault audit logging
Protect Azure Key Vault with Microsoft Defender for Cloud
Protect Azure Key Vault with Microsoft Defender for Cloud. Use Defender CSPM agentless secret scanning to discover exposed credentials across virtual machines (VMs) and cloud deployments, enable Microsoft Defender for Key Vault to detect malicious access patterns, and respond effectively to Key Vault security alerts.
- Scan for exposed secrets using Defender Cloud Security Posture Management (CSPM)
- Enable Microsoft Defender for Key Vault
- Investigate and respond to Defender for Key Vault alerts
Enforce governance with Azure Policy and resource locks
Enforce security standards before resources reach production using Azure Policy. Assign built-in policy definitions and initiatives at management group scope, author custom definitions with automated remediation tasks, and protect critical resources from deletion using Azure resource locks.
- Assign built-in Azure Policy definitions
- Create and deploy custom policy definitions
- Implement resource locks
Configure security controls and remediate recommendations in Defender for Cloud
Configure Defender for Cloud security standards at management group scope and systematically deploy security controls to remediate recommendations. Manage custom security standards, assign recommendation ownership using governance rules, and remediate at scale using Fix, Azure Policy remediation tasks, and structured exemptions.
- Configure Defender for Cloud and manage security standards
- Deploy remediation controls at scale
Evaluate regulatory compliance in Defender for Cloud
In this module, you use Microsoft Defender for Cloud to assess your organization's compliance posture against security frameworks. You explore the regulatory compliance dashboard, investigate control gaps, assign regulatory standards, and generate audit-ready reports that communicate compliance status to stakeholders.
- Understand compliance standards and controls in Defender for Cloud
- Navigate the regulatory compliance dashboard and investigate control gaps
- Assign standards and communicate compliance posture
Manage and right-size RBAC role assignments for least privilege
Implement least-privilege access governance across Azure and Microsoft Entra ID. Assign built-in roles at appropriate scope, create custom roles for Azure resources and Microsoft Entra directory operations. Then identify and remediate overprivileged access using Microsoft Entra access reviews and Defender for Cloud Security Posture Management (CSPM) identity insights.
- Assign and manage Azure built-in roles
- Create custom Azure roles and Microsoft Entra roles
- Evaluate and remediate overprivileged access
Protect backup data with Azure Backup security features
Protect Azure Backup data against ransomware, accidental deletion, and rogue administrators. Configure enhanced soft delete, vault immutability, Multi-User Authorization with Resource Guard, and RBAC controls to achieve an Excellent security posture rating across Recovery Services vaults.
- Enable soft delete and immutable vaults
- Configure Multi-User Authorization and RBAC for backup
Implement security controls in infrastructure as code
Embed security controls into infrastructure as code pipelines to prevent noncompliant Azure resources from reaching production. Integrate IaC security scanning using Microsoft Defender for DevOps and the Microsoft DevOps (MSDO) extension, and configure Azure Policy in a policy-as-code workflow to enforce security compliance at deployment time.
- Scan IaC templates using Microsoft Defender for DevOps
- Enforce policy compliance in IaC deployments
Describe Azure storage services
This module introduces you to storage in Azure, including things such as different types of storage and how a distributed infrastructure can make your data more resilient.
- Describe Azure storage accounts
- Describe Azure storage redundancy
- Describe Azure storage services
- Identify Azure data migration options
- Identify Azure file movement options
Implement security and manage access for Azure Storage
Implement account-level security controls and access governance for Azure Storage. Configure secure transfer settings, choose appropriate authorization models, apply stored access policies for SAS lifecycle management, and enforce Shared Key disable using Azure Policy to protect storage accounts used by AI agents and enterprise workloads.
- Configure storage account security settings
- Select an authorization model for Azure Storage
- Manage access with stored access policies
- Disable Shared Key authorization and enforce with Azure Policy
Configure network security for Azure Storage
Configure network-layer access controls for Azure Storage accounts. Apply firewall rules, define virtual network and IP-based access, configure resource instance rules for Azure AI services, manage trusted service exceptions, and implement private endpoints to eliminate public endpoint exposure.
- Describe Azure Storage network security controls
- Configure virtual network and IP rules
- Configure resource instance rules and trusted services
- Implement private endpoints for storage accounts
Implement Microsoft Defender for Storage
Enable and configure Microsoft Defender for Storage to detect threats against Azure Blob Storage, Azure Files, and Azure Data Lake Storage. Configure activity monitoring, malware scanning with cost controls, sensitive data threat detection, and alert routing to ensure Defender outputs reach the appropriate security team.
- Explore Microsoft Defender for Storage capabilities
- Enable and deploy Defender for Storage
- Configure malware scanning and sensitive data detection
- Configure alert routing and validate Defender coverage
Configure platform-level security for Azure SQL
Configure authentication, network isolation, encryption, and access controls for Azure SQL Database and SQL Managed Instance. Implement Microsoft Entra ID–only authentication with managed identity access for AI workloads, deploy private endpoints, and apply transparent data encryption, dynamic data masking, and row-level security to protect sensitive financial data.
- Configure authentication and managed identity access
- Implement network isolation
- Encrypt and protect data in transit and at rest
- Apply data masking and row-level security
Configure auditing for Azure SQL Database and SQL Managed Instance
Configure audit logging for Azure SQL Database and SQL Managed Instance to create tamper-resistant compliance records. Set audit action groups, route logs to Azure Monitor, Event Hubs, and immutable blob storage, and configure SQL Managed Instance–specific auditing to meet financial regulatory audit requirements.
- Describe Azure SQL auditing capabilities
- Configure audit destinations for Azure SQL Database
- Configure auditing for SQL Managed Instance
- Design a compliant audit strategy
Implement Microsoft Defender for Databases
Enable Microsoft Defender for Databases to detect SQL injection, anomalous query patterns, and vulnerability exposures across Azure SQL services. Enable protection at subscription scope using Azure Policy, configure vulnerability assessment baselines, and route security alerts to the security operations team.
- Explore Microsoft Defender for Databases capabilities
- Enable Defender for Azure SQL Databases at subscription scope
- Enable Defender for open-source relational databases
- Configure vulnerability assessment
- Configure alert routing and validate coverage
Segment and isolate Azure workloads using network security controls
Segment Azure workloads to control lateral movement and enforce least-privilege network access using NSGs, ASGs, Azure Virtual Network Manager, and Network Watcher verification.
- Assess network segmentation gaps
- Control traffic with network security groups (NSGs)
- Simplify rule management with application security groups
- Enforce consistent policy with Azure Virtual Network Manager
- Verify effective network security rules with Network Watcher
Centralize and enforce traffic inspection using Azure Firewall
Deploy Azure Firewall to centralize traffic inspection and enforce filtering policies across your Azure environment. Azure Firewall includes threat-intelligence-based blocking and Secured Virtual Hub deployment for hub-spoke and branch traffic.
- Determine when centralized traffic inspection is required
- Configure Azure Firewall rules and policies
- Secure a Virtual WAN hub with Azure Firewall
Secure remote and hybrid connectivity using VPN gateways and Microsoft Entra Private Access
Harden Azure VPN gateway security and deploy Microsoft Entra Private Access to replace broad VPN access with identity-aware, per-application access that enforces Zero Trust connectivity principles.
- Assess security risks in hybrid connectivity
- Harden VPN gateway security
- Replace broad VPN access with Microsoft Entra Private Access
Eliminate public network exposure of Azure PaaS services
Eliminate public network exposure of Azure PaaS and AI services using private endpoints and Azure Private Link, then enforce adoption at scale using Azure Policy and Defender for Cloud.
- Assess the risk of public PaaS endpoint exposure
- Configure private endpoints to eliminate public PaaS exposure
- Expose internal services securely using Azure Private Link service
- Enforce and audit private endpoint adoption
Secure access for Microsoft Entra Agent Identity
Apply Conditional Access controls to AI agent identities in Microsoft Entra Agent Identity. Map how agents authenticate, configure policies that enforce access conditions, and manage the agent identity lifecycle to reduce risk from compromised or over-privileged agents.
- Map authentication flows and Conditional Access scope
- Configure Conditional Access policies for agents
- Control agent access and lifecycle
Analyze AI identity risks using Microsoft Defender XDR
Use Microsoft Defender XDR to discover AI agents operating in your environment, assess the blast radius of each agent identity, and analyze attack paths that could lead to unauthorized data or resource access.
- Discover AI agents in the Microsoft Defender portal
- Assess blast radius and attack paths
Enable real-time protection for Copilot Studio agents
Configure Microsoft Defender for Cloud Apps to provide runtime protection for Copilot Studio agents. Enable protection in the Defender portal Settings for AI, coordinate with Power Platform admins for App ID configuration, and verify that agent inventory, alerts, and Advanced Hunting data appear in Microsoft Defender XDR.
- Explore Copilot Studio AI agent protection
- Enable protection in Microsoft Defender
- Review AI agent protection outputs
Configure AI Gateway security in Microsoft Foundry
Use AI Gateway in Microsoft Foundry to secure and govern AI model traffic. Examine the gateway architecture, create and configure a gateway instance with security controls, and apply access restrictions and monitoring to enforce policy and detect misuse.
- Examine AI Gateway architecture
- Create and configure AI Gateway
- Secure and monitor AI Gateway access
Configure and manage guardrails in Microsoft Foundry
Microsoft Foundry guardrails help secure AI workloads by applying configurable safety controls that evaluate both prompts and responses. You'll learn how to understand built-in safety models, test and refine guardrails, create blocklists, configure content filters, and validate that protections work as intended. These capabilities help organizations prevent unsafe or policy-violating interactions, protect sensitive data, and maintain trust in AI-assisted applications.
Implement disk encryption for Azure virtual machines
Select and configure the right disk encryption approach for Azure virtual machines. Compare managed disk encryption options, configure encryption at host with customer-managed keys using Disk Encryption Sets, apply confidential disk encryption to confidential virtual machines, and enforce disk encryption compliance using Azure Policy.
- Choose the right disk encryption option for Azure VMs
- Configure encryption at host with customer-managed keys
- Apply confidential disk encryption to confidential virtual machines
Configure trusted launch security features for Azure virtual machines
Configure Trusted Launch security features for Azure virtual machines. Enable Secure Boot, vTPM, and integrity monitoring to protect against boot-level malware and rootkits. Upgrade existing Gen1 and Gen2 VMs to the Trusted Launch security type and enforce adoption at scale using Azure Policy.
- Identify Trusted Launch components and VM security types
- Enable Trusted Launch on new and existing Gen2 VMs
- Migrate Gen1 VMs and configure Trusted Launch components
- Enforce Trusted Launch adoption with Azure Policy
Plan and implement Azure Bastion
Plan and deploy Azure Bastion to provide secure, browser-based RDP and SSH access to virtual machines without exposing public IP addresses or management ports. Select the appropriate SKU based on scale and feature requirements, deploy and configure Bastion in an Azure virtual network, and connect to VMs using both portal and native client methods.
- Plan Azure Bastion deployment
- Deploy and configure Azure Bastion
- Connect to VMs through Azure Bastion
Manage security for Arc-enabled hybrid servers
Manage security controls for Azure Arc-enabled hybrid servers. Configure RBAC and extension security to prevent unauthorized agent modifications. Then apply Azure Policy to enforce security baselines on Arc-enrolled machines. Finally, monitor hybrid server security posture in Microsoft Defender for Cloud.
- Control access and extension security for Arc-enabled servers
- Apply Azure Policy to Arc-enabled servers
- Monitor Arc server security posture in Defender for Cloud
Implement Microsoft Defender for Servers
Onboard Azure virtual machines and Arc-connected hybrid servers to Microsoft Defender for Servers. Select Plan 1 or Plan 2 based on capability requirements, configure vulnerability scanning using agentless and agent-based Defender Vulnerability Management. Then integrate Microsoft Defender for Endpoint, and manage agentless scanning capabilities for software inventory, secrets, malware detection, and File Integrity Monitoring.
- Onboard servers to Defender for Servers
- Configure vulnerability scanning with Defender Vulnerability Management
- Configure Defender for Endpoint integration, agentless scanning, and File Integrity Monitoring
Enable and enforce just-in-time VM access
Enable and configure just-in-time VM access in Microsoft Defender for Cloud to eliminate permanently open RDP and SSH ports. Configure per-port access policies, request time-bound access to VMs, audit access activity, and enforce JIT adoption across your VM estate using Azure Policy.
- Examine just-in-time VM access requirements and VM eligibility
- Enable and configure JIT access policies
- Request Just-in-time (JIT) access and audit access activity
Enforce VM security configuration with Azure Machine Configuration
Audit and enforce OS security configuration on Azure virtual machines and Arc-enabled servers using Azure Machine Configuration. Apply built-in Windows and Linux security baseline policies, configure audit and enforce modes, and author custom machine configurations for organization-specific security requirements.
- Explore Azure Machine Configuration extension capabilities and modes
- Apply built-in security baseline policies
- Author and assign custom machine configurations
Detect container risks using Microsoft Defender for Containers
Detect misconfigurations and runtime risks across container workloads using Microsoft Defender for Containers. Enable and configure the Defender for Containers plan, and assess container image vulnerabilities in Azure Container Registry. Then respond to runtime threat alerts and security posture recommendations for Azure Kubernetes Service (AKS) clusters.
- Explore Microsoft Defender for Containers
- Enable and configure Defender for Containers
- Assess container image vulnerabilities
- Detect container runtime threats and misconfigurations
Implement security controls for Azure Kubernetes Service
Implement security controls for Azure Kubernetes Service. Configure Microsoft Entra integration and Kubernetes RBAC for API server authentication and authorization, enforce network policies and private cluster access. Then apply workload identity and pod security standards to harden containerized workloads in Azure Kubernetes Service (AKS).
- Control AKS cluster access with Microsoft Entra ID and RBAC
- Secure AKS network access
- Implement workload identity and secrets management for AKS
- Enforce pod and container security
Implement security controls for Azure Container Registry, Container Instances, and Container Apps
Implement security controls across Azure Container Registry, Azure Container Instances, and Azure Container Apps. Configure RBAC, private endpoints, and content trust for ACR; apply managed identities and virtual network integration for Container Instances; and enforce ingress controls, managed identities, and secrets management for Container Apps environments.
- Secure Azure Container Registry
- Implement security controls for Azure Container Instances
- Implement security controls for Azure Container Apps
Implement security controls for Azure Function apps and Logic apps
Implement security controls for Azure Function apps and Logic apps. Configure authentication and authorization, managed identities, virtual network integration, and private endpoints for Function apps, and apply managed identity, connector security, and network isolation for Logic apps.
- Configure authentication and authorization for Function apps
- Secure network access for Function apps
- Implement security controls for Logic apps
Implement security controls for Azure App Services and Web Application Firewall
Implement security controls for Azure App Services and Web Application Firewall. Configure authentication, managed identities, VNet integration, and private endpoints for App Service, and deploy WAF policies on Azure Application Gateway to protect web workloads at the network edge.
- Implement security controls for Azure App Service
- Configure Web Application Firewall policies
- Protect App Service with Web Application Firewall
Implement API backend security using Azure API Management
Implement security policies for backend API protection using Azure API Management. Configure subscription key management, JSON Web Token (JWT) validation, and OAuth 2.0 policies, and apply IP filtering and rate limiting. Then enforce mutual Transport Layer Security (mTLS) for secure backend API connections, and configure AI Gateway to secure and govern AI model endpoints.
- Configure API authentication and authorization policies
- Implement API network security and threat protection
- Secure API Management backend connections
- Configure AI Gateway in API Management for Azure AI Foundry
Connect hybrid and multicloud environments to Microsoft Defender for Cloud
In this module, you connect on-premises servers, AWS accounts, and GCP projects to Microsoft Defender for Cloud to extend unified security coverage across your entire hybrid and multicloud estate. You learn how federated authentication secures connector access without storing long-lived credentials. Then you plan the right connector scope for each environment type, and configure native connectors for AWS and GCP. The module covers both CSPM (agentless) and CWPP (Azure Arc–enabled) coverage extension, and closes by verifying that unified posture and workload protection is active across all connected environments.
- Explore the Defender for Cloud multicloud connectivity model
- Plan a connector strategy for hybrid and multicloud environments
- Connect on-premises machines using Azure Arc
- Connect AWS accounts to Defender for Cloud
- Connect GCP projects to Defender for Cloud
- Verify multicloud coverage and validate protection
Identify security risks by using Cloud Security Posture Management
In this module, you use Cloud Security Posture Management (CSPM) in Microsoft Defender for Cloud to identify, prioritize, and trace security risks across Azure environments — including generative AI workloads. You compare Foundational and Defender CSPM plan capabilities, interpret the risk-based Cloud Secure Score, investigate attack paths targeting cloud and AI resources, and run graph-based queries in Cloud Security Explorer to proactively discover hidden risks.
- Explore CSPM plans and posture visibility
- Analyze security recommendations with risk prioritization
- Identify attack paths and choke points
- Hunt for risks with cloud security explorer
Discover unprotected assets and vulnerabilities by using Microsoft Defender External Attack Surface Management
In this module, you use Microsoft Defender External Attack Surface Management (EASM) to discover and secure your external attack surface. You learn how Microsoft Defender External Attack Surface Management (EASM) outside-in discovery complements other Defender tools. EASM uses recursive discovery to find unknown internet-facing assets across your organization, analyze dashboards to prioritize vulnerabilities and security hygiene risks, and integrate EASM findings with Defender CSPM for attack path analysis.
- Explore EASM features and capabilities
- Discover assets using recursive discovery
- Analyze your attack surface with dashboards
- Integrate EASM insights with Defender for Cloud
Evaluate regulatory compliance in Defender for Cloud
In this module, you use Microsoft Defender for Cloud to assess your organization's compliance posture against security frameworks. You explore the regulatory compliance dashboard, investigate control gaps, assign regulatory standards, and generate audit-ready reports that communicate compliance status to stakeholders.
- Understand compliance standards and controls in Defender for Cloud
- Navigate the regulatory compliance dashboard and investigate control gaps
- Assign standards and communicate compliance posture
Enable and configure workload protection plans in Microsoft Defender for Cloud
Enable Cloud Workload Protection Platform (CWPP) plans in Microsoft Defender for Cloud to defend servers, storage, databases, and AI workloads against active threats. You identify the right plan for each workload type — including Defender for AI Services and Defender for APIs — configure plan-specific settings such as the Defender for Servers P1/P2 tier distinction and Defender for Storage malware scanning, and deploy protection at subscription or management group scope. The module concludes by verifying coverage using the Coverage workbook.
- Understand the Defender for Cloud CWPP plan catalog
- Enable workload protection plans in Environment Settings
- Configure Defender for Storage and Defender for Databases
- Deploy plans at scale and verify coverage
Configure Microsoft Defender Vulnerability Management settings for Azure VMs
Configure Microsoft Defender Vulnerability Management for Azure VMs by selecting the appropriate scanning method for your Defender for Servers plan tier, enabling vulnerability assessment at subscription and machine scope, and reviewing findings in the Microsoft Defender portal. Apply Defender for Servers Plan 2 premium capabilities—security baselines assessment and vulnerable application blocking—to enforce ongoing compliance and reduce exploitation risk.
- Explore Microsoft Defender Vulnerability Management (MDVM) integration with Defender for Servers
- Configure vulnerability scanning for Azure VMs
- Review and manage vulnerability findings
- Apply Plan 2 premium MDVM capabilities
Create and manage Microsoft Sentinel workspaces
Learn about the architecture of Microsoft Sentinel workspaces to ensure you configure your system to meet your organization's security operations requirements.
- Plan for the Microsoft Sentinel workspace
- Create a Microsoft Sentinel workspace
- Manage workspaces across tenants using Azure Lighthouse
- Understand Microsoft Sentinel permissions and roles
- Manage Microsoft Sentinel settings
- Configure logs
- Module assessment
Manage content in Microsoft Sentinel
By the end of this module, you're able to manage content in Microsoft Sentinel.
- Use solutions from the content hub
- Use repositories for deployment
- Module assessment
Connect Microsoft services to Microsoft Sentinel
Learn how to connect Microsoft 365 and Azure service logs to Microsoft Sentinel.
- Plan for Microsoft services connectors
- Connect the Microsoft 365 connector
- Connect the Microsoft Entra connector
- Connect the Microsoft Entra ID Protection connector
- Connect the Azure Activity connector
Connect syslog data sources to Microsoft Sentinel
Learn about the Azure Monitor Agent Linux Syslog Data Collection Rule configuration options, which enable you to parse Syslog data.
- Plan for syslog data collection
- Collect data from Linux-based sources using syslog
- Configure the Data Collection Rule for Syslog Data Sources
- Parse syslog data with KQL
Connect Common Event Format logs to Microsoft Sentinel
Most vendor-provided connectors utilize the CEF connector. Learn about the Common Event Format (CEF) connector's configuration options.
- Plan for Common Event Format connector
- Connect your external solution using the Common Event Format connector
Connect Windows hosts to Microsoft Sentinel
Two of the most common logs to collect are Windows security events and Sysmon. Learn how Microsoft Sentinel makes this easy with the Microsoft Windows Events data connectors.
- Plan for Windows hosts security events connector
- Connect using the Windows Security Events via AMA Connector
- Connect using the Security Events via Legacy Agent Connector
- Collect Sysmon event logs
Implement automation rules and playbooks in Microsoft Sentinel
Automate incident management in Microsoft Sentinel using automation rules and Logic Apps playbooks. Create automation rules to triage and route incidents, activate a prebuilt response playbook from Content Hub, and author a custom playbook. The process implements an automated notification and response workflow.
- Understand Microsoft Sentinel automation options
- Create automation rules in Microsoft Sentinel
- Configure and activate a Content Hub playbook
- Author a custom playbook with Azure Logic Apps
Manage data storage and query audit logs in Microsoft Sentinel
Manage data storage in Microsoft Sentinel by creating custom log tables, configuring retention tiers and archive policies, and integrating Microsoft Purview Audit. Create tables for nonstandard data sources, apply Analytics and Archive retention tiers to meet compliance requirements, and query Purview Audit logs in the Microsoft Defender XDR portal.
- Create custom log tables in Microsoft Sentinel
- Implement data retention in Microsoft Sentinel
- Connect Microsoft Purview Audit to Microsoft Sentinel
- Query Purview Audit logs in Microsoft Defender XDR
Describe Microsoft Security Copilot
Get acquainted with Microsoft Security Copilot. You're introduced to some basic terminology, how Microsoft Security Copilot processes prompts, the elements of an effective prompt, and how to enable the solution.
- Get acquainted with Microsoft Security Copilot
- Describe Microsoft Security Copilot terminology
- Describe how Microsoft Security Copilot processes prompt requests
- Describe the elements of an effective prompt
- Describe how to enable Microsoft Security Copilot
Configure workspaces for Microsoft Security Copilot
In this module, you plan and configure Security Copilot workspaces for enterprise segmentation. You learn how to set capacity with Security Compute Units (SCUs), select data storage locations for compliance. Then you assign workspace roles, configure workspace-level plugins and owner settings, assign workspaces for integrated Microsoft Security Copilot agents, and monitor capacity usage.
- Plan a workspace deployment
- Create a Security Copilot workspace
- Configure workspace access and settings
- Assign workspaces for integrated agents
- Monitor and manage workspace capacity
Manage plugins and agents in Microsoft Security Copilot
In this module, you configure plugin governance settings and manage the Security Copilot agent lifecycle. You learn how owner-level plugin settings control who can add and publish custom plugins. Then explore how to restrict preinstalled plugin access across workspaces, and how to discover, set up, and manage both Microsoft-built and Security Store partner agents.
- Configure plugin settings in Security Copilot
- Discover and set up Microsoft-built agents
- Acquire and configure partner agents from Security Store
- Manage Security Copilot agents