Let’s make it work for you 

Get in touch

Implement end-to-end security controls for cloud and AI workloads

From £2,499 + VAT
Accredited by
Details
Categories:
Infrastructure and Networking Artificial Intelligence
Level:
Intermediate
Tier type:
Premium
Code:
MSC500
Exam:
Yes - Available separately

Overview

Build the practical skills needed to implement and manage security controls across Microsoft Azure, Microsoft 365, and AI-enabled workloads.

This four-day course prepares security professionals to protect identities, data, infrastructure, applications, and AI solutions across cloud, hybrid, and multicloud environments. You will explore how Microsoft security technologies can help reduce unauthorised access, limit exposure, enforce secure configurations, and strengthen your organisation’s overall security posture.

Through instructor-led learning, hands-on labs, knowledge checks, demonstrations, and discussion, you will develop practical experience with Microsoft Entra ID, Azure Key Vault, Azure Policy, Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Purview, Microsoft Security Copilot, and other security capabilities.

As AI becomes increasingly embedded in modern cloud solutions, the course also explores how to secure AI agents, identities, data access paths, gateways, guardrails, and supporting infrastructure. You will leave with a broader understanding of how security controls work together across cloud and AI environments, and how to apply them to real-world engineering tasks.



Prerequisites

To get the most from this course, you should have:

  • Foundational knowledge of Microsoft Azure, including subscriptions, resource groups, virtual networks, storage accounts, virtual machines, and Azure role-based access control
  • A basic understanding of Microsoft Entra ID, authentication, authorisation, multifactor authentication, Conditional Access, and application or service identities
  • Knowledge of core security concepts, including least privilege, defence in depth, Zero Trust, encryption, auditing, threat protection, and secure configuration
  • Familiarity with cloud networking concepts, including virtual networks, subnets, private endpoints, firewalls, VPNs, and network security rules
  • Awareness of common Azure workloads, including storage, SQL databases, virtual machines, containers, App Services, and APIs
  • Familiarity with Microsoft security tools such as Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Defender XDR, Microsoft Purview, or Microsoft Security Copilot
  • Introductory awareness of AI concepts, including copilots, agents, prompts, models, and data grounding
  • Experience navigating the Azure portal and making basic configuration changes in a lab environment

Target audience

This course is designed for security engineers responsible for protecting organisational systems and data across cloud, hybrid, and AI-enabled environments.

It is particularly relevant for professionals who work with identity, infrastructure, networks, applications, data, security operations, DevOps, or AI solutions and need to implement security controls using Microsoft technologies.

You may work closely with architects, administrators, developers, analysts, database specialists, and network professionals. The course is also suitable for learners preparing for security responsibilities that span identity, access, governance, data, networking, compute, application platforms, AI workloads, and cloud security posture management.

What's included

Select your preferred way to learn:

What is Virtual?

Live, instructor-led training delivered online

Interactive online sessions led by subject matter experts. Learners join live classes, take part in discussions, and complete practical exercises from any location, making it easy to fit collaborative learning into busy schedules.

If you prefer to connect to a course that is taking place in a physical classroom, you can choose our Remote Access option. .

Best for: Teams and individuals who want expert guidance, real-time collaboration, and flexible access.

What's included?

4 Days instructor led course

Exam: Yes - Available separately

6 month free access to QA learning platform

Free 6-Month Access: Learning Platform Discovery plan

Included FREE with every instructor‑led course

Get free guided access to the QA Learning Platform. Assess your skills, explore in-demand topics, and understand which areas to focus on.

Learn AI, Cloud, Data, and Leadership skills at your own pace.

Put skills into practice with hands-on Labs and Simulabs.

Validate knowledge and highlight gaps with skills assessments.

What is bespoke training? 

Custom instructor-led training designed by QA to fit your needs

Tailored programmes built around your organisation’s goals, challenges, and skill levels. Delivered in the format that suits you to maximise relevance and impact.

Best for: Organisations and teams looking to target specific business priorities and capabilities with QA subject matter expertise.

 

Talk to us

Dates

Available ways to learn:

Outline

Securing access with Microsoft Entra ID

Explore how identity security provides a foundation for protecting cloud and AI workloads. You will examine authentication methods, Conditional Access, privileged access, application registration, and application identities.

Key topics include:

  • Managing and implementing authentication methods
  • Configuring privileged identity management
  • Enforcing multifactor authentication with Conditional Access
  • Securing application and service identities
  • Authenticating API plugins for declarative agents with secured APIs

Protecting secrets and keys with Azure Key Vault

Learn how to protect sensitive credentials and cryptographic assets used by cloud workloads. You will explore secure access, secrets management, certificates, managed identities, and workload protection.

Key topics include:

  • Configuring and securing Azure Key Vault
  • Managing keys and secrets
  • Managing certificates and monitoring key vault activity
  • Using managed identities to access protected resources
  • Protecting Azure Key Vault with Microsoft Defender for Cloud

Implementing governance and security controls

Discover how governance and least-privilege principles can help maintain secure and compliant cloud environments.

Key topics include:

  • Enforcing governance with Azure Policy and resource locks
  • Managing role-based access control assignments
  • Using access reviews to support appropriate access
  • Configuring security controls and remediating recommendations
  • Evaluating regulatory compliance
  • Protecting backup data with Azure security features
  • Implementing security controls through infrastructure as code

Securing storage, databases, and networking

Learn how to protect data services and control network access to cloud resources.

Key topics include:

  • Managing access and network security for Azure Storage
  • Configuring firewalls, private endpoints, and shared access signatures
  • Using Microsoft Defender for Storage
  • Securing Azure SQL Database
  • Configuring SQL auditing and Microsoft Defender for SQL
  • Exploring data masking and ledger capabilities
  • Segmenting and isolating workloads
  • Centralising traffic inspection with Azure Firewall
  • Securing remote and hybrid connectivity
  • Reducing public network exposure for platform services

Securing servers, virtual machines, and hybrid infrastructure

Explore security controls for Azure virtual machines and hybrid servers.

Key topics include:

  • Implementing disk encryption
  • Configuring Trusted Launch security features
  • Using Azure Bastion for secure access
  • Managing security for Azure Arc-enabled hybrid servers
  • Implementing Microsoft Defender for Servers
  • Enforcing just-in-time virtual machine access
  • Applying virtual machine security configuration controls
  • Exploring agentless security capabilities

Implementing security for AI workloads

Examine the emerging security challenges associated with AI applications and autonomous agents. You will explore how identity, data protection, platform guardrails, gateways, and workload protection can work together to reduce AI security risks.

Key topics include:

  • Securing Microsoft Entra Agent Identity
  • Analysing AI identity risks with Microsoft Defender XDR
  • Protecting Copilot Studio agents
  • Configuring AI gateway security in Microsoft Foundry
  • Configuring and managing AI guardrails
  • Protecting AI workloads with Microsoft Defender for Cloud
  • Enabling workload protection for AI services
  • Managing agents with Microsoft Agent 365
  • Identifying AI data risks with Microsoft Purview Data Security Posture Management

Securing containers and application platforms

Learn how to apply security controls across modern application platforms, containers, APIs, and web services.

Key topics include:

  • Detecting container risks with Microsoft Defender for Containers
  • Securing Azure Kubernetes Service
  • Protecting Azure Container Registry, Container Instances, and Container Apps
  • Securing Azure Functions and Logic Apps
  • Implementing security controls for Azure App Services
  • Using web application firewall capabilities
  • Securing API back ends with Azure API Management

Managing cloud security posture

Develop the skills to identify risks, improve security posture, and manage protection across cloud, hybrid, and multicloud environments.

Key topics include:

  • Connecting hybrid and multicloud environments to Microsoft Defender for Cloud
  • Identifying risks using cloud security posture management
  • Discovering unprotected assets and vulnerabilities
  • Exploring external attack surface management
  • Evaluating regulatory compliance
  • Enabling and configuring workload protection plans
  • Managing vulnerability settings for Azure virtual machines
  • Using secure score, recommendations, secret scanning, and governance controls

Collecting and managing security events with Microsoft Sentinel

Explore foundational security operations capabilities using Microsoft Sentinel.

Key topics include:

  • Creating and managing Microsoft Sentinel workspaces
  • Managing security content
  • Connecting Microsoft and external data sources
  • Collecting syslog, Common Event Format, and Windows host data
  • Implementing automation rules and playbooks
  • Managing data storage
  • Querying and auditing collected logs

Implementing Microsoft Security Copilot

Discover how Microsoft Security Copilot can support security operations through configured workspaces, plugins, agents, and appropriate access controls.

Key topics include:

  • Understanding Microsoft Security Copilot capabilities
  • Configuring Security Copilot workspaces
  • Managing plugins and agents
  • Understanding the Security Compute Unit consumption model
  • Managing relevant roles and access

Exams and assessments

The course includes knowledge check questions throughout the learning experience to help reinforce understanding and identify areas that may need further review.

The course supports preparation for the SC-500 certification exam. The associated study areas cover managing identity, access, and governance; securing storage, databases, and networking; securing compute; and managing and monitoring security posture.

Knowledge checks, classroom discussion, practical labs, and instructor guidance provide opportunities to test and apply your understanding throughout the course.

Hands-on learning

This course combines instructor-led learning with practical exercises designed to help you apply security concepts in a lab environment.

Hands-on activities include opportunities to:

  • Configure privileged identity management and Conditional Access
  • Deploy and secure Azure Key Vault
  • Configure Azure Policy and role-based access control
  • Secure Azure Storage and Azure SQL Database
  • Configure network security controls
  • Secure Azure virtual machines and onboard them to Microsoft Defender for Servers
  • Identify AI data risks and secure AI agent identities
  • Configure AI gateway and Microsoft Foundry security controls
  • Monitor AI security with Microsoft Defender for Cloud
  • Secure container workloads, App Services, and API Management
  • Explore cloud security posture management
  • Configure Microsoft Sentinel data collection and automation
  • Configure and use Microsoft Security Copilot

Learning outcomes

By the end of this course, you will be able to:

  • Secure identity and access across users, applications, and AI agents using Microsoft Entra ID, authentication controls, privileged access, and appropriate identity configurations
  • Protect secrets, keys, certificates, storage, databases, and other sensitive resources using security controls designed to reduce exposure and strengthen access management
  • Apply governance, policy, compliance, and least-privilege controls across Azure using Azure Policy, role-based access control, resource controls, and security recommendations
  • Secure network access to Azure resources and services through segmentation, traffic inspection, private connectivity, firewalls, and other network security controls
  • Assess and protect AI workloads, agents, identities, data access paths, gateways, guardrails, and supporting infrastructure
  • Secure virtual machines, hybrid servers, containers, application platforms, APIs, and other cloud workloads
  • Manage and monitor security posture across Azure, hybrid, and multicloud environments using Microsoft Defender for Cloud and related security capabilities
  • Configure foundational security operations capabilities using Microsoft Sentinel and Microsoft Security Copilot

Good to know

Why choose QA

Get in touch for team bookings and exclusive discounts

Ready to book? Complete the form and a member of our team will be in touch shortly to discuss your options.

Let’s make it work for you. Speak to one of our learning experts today.

By submitting this form, you agree to QA processing your data in accordance with our Privacy Policy and Terms & Conditions. You can unsubscribe at any time by clicking the link in our emails or contacting us directly.

What our customers are saying

“As the administrator, it’s critical for me to be able to demonstrate where their skills started and where they’ve increased, and that’s all proven by the assessments. It’s been really valuable to us because it checks all the boxes for what all my stakeholders care about, including me.”

Jennifer Zaborowski

Director of IT Learning & Development, Regeneron  

“I participated in an IT Project Management Workshop, and I have to say it was by some way, the most well organised, best presented, engaging, informative and inspiring workshop or training course I have been on with QA. The trainer’s willingness to spend his time and share his experience and resources with me were second to none, and I truly feel better prepared going forward in my career.”

James

QA learner

Portfolio Director

Rob Blincoe

Portfolio Director – Cloud & Infrastructure

Rob leads the strategic direction of the cloud and Infrastructure training portfolios, empowering organisations and individuals to build practical, scalable skills across Cloud, Hybrid, On-Premise and other platforms. He designs learning experiences that make cloud and Infrastructure adoption more accessible, efficient, and aligned to real-world business goals. Visit my page
Yellow
Need to know

Frequently asked questions

How can I create an account on myQA.com?

There are a number of ways to create an account. If you are a self-funder, simply select the "Create account" option on the login page.

If you have been booked onto a course by your company, you will receive a confirmation email. From this email, select "Sign into myQA" and you will be taken to the "Create account" page. Complete all of the details and select "Create account".

If you have the booking number you can also go here and select the "I have a booking number" option. Enter the booking reference and your surname. If the details match, you will be taken to the "Create account" page from where you can enter your details and confirm your account.

Find more answers to frequently asked questions in our FAQs: Bookings & Cancellations page.

How do QA’s virtual classroom courses work?

Our virtual classroom courses allow you to access award-winning classroom training, without leaving your home or office. Our learning professionals are specially trained on how to interact with remote attendees and our remote labs ensure all participants can take part in hands-on exercises wherever they are.

We use the WebEx video conferencing platform by Cisco. Before you book, check that you meet the WebEx system requirements and run a test meeting to ensure the software is compatible with your firewall settings. If it doesn’t work, try adjusting your settings or contact your IT department about permitting the website.

How do QA’s online courses work?

QA online courses, also commonly known as distance learning courses or elearning courses, take the form of interactive software designed for individual learning, but you will also have access to full support from our subject-matter experts for the duration of your course.

Once you have purchased the Online course and have completed your registration, you will receive the necessary details to enable you to immediately access it through our e-learning platform and you can start to learn straight away, from any compatible device. Access to the online learning platform is valid for one year from the booking date.

All courses are built around case studies and presented in an engaging format, which includes storytelling elements, video, audio and humour. Every case study is supported by sample documents and a collection of Knowledge Nuggets that provide more in-depth detail on the wider processes.

When will I receive my joining instructions?

Joining instructions for QA courses are sent two weeks prior to the course start date, or immediately if the booking is confirmed within this timeframe. For course bookings made via QA but delivered by a third-party supplier, joining instructions are sent to attendees prior to the training course, but timescales vary depending on each supplier’s terms. Read more FAQs.

When will I receive my certificate?

Certificates of Achievement are issued at the end the course, either as a hard copy or via email. Read more here.