Build Layered Network Security in Azure! Learn to design, configure, and protect Azure network infrastructure from real-world threats.
The course teaches you how to protect cloud infrastructure by designing and implementing layered network defenses across Microsoft Azure environments. It opens with perimeter security fundamentals, where you'll apply defense-in-depth principles to build resilient network boundaries. You'll configure Azure Firewall and Azure DDoS Protection for centralized traffic inspection, use forced tunneling and user-defined routes to control traffic paths, and design hub-and-spoke topologies that centralize shared security services. From there, you'll move inside the network—configuring network security groups (NSGs) and application security groups (ASGs) to control workload traffic, then securing access to Azure services using service endpoints and Private Link. You'll also learn to protect internet-facing applications with Application Gateway, Web Application Firewall (WAF), and Azure Front Door, and connect on-premises infrastructure to Azure using VPN gateways and ExpressRoute. Throughout the course, guided demonstrations and scenario-based role-play activities give you hands-on practice applying network security controls to realistic cloud environments. Who this is for: Cloud administrators, network engineers, and security professionals who manage Azure environments and want to implement strong, practical network security controls.
















