When you enroll in this course, you'll also be enrolled in this Professional Certificate.
Learn new concepts from industry experts
Gain a foundational understanding of a subject or tool
Develop job-relevant skills with hands-on projects
Earn a shareable career certificate from Microsoft
There are 4 modules in this course
Microsoft Azure provides a comprehensive suite of security tools and services to help you safeguard your organization's data and applications. Identity Protection and governance is the right course for you if you want to become an Azure security engineer.
In this course, you will learn how to protect identities in Azure AD, the core principles of enterprise governance, and Azure role-based access control (RBAC).
You will get acquainted with Conditional Access, multifactor authentication (MFA), and other capabilities. You will learn how to plan and configure privilege identity management (PIM). You will also learn how to manage, assign, activate, and approve requests for a privileged access group. You will explore how to investigate and remediate risks.
This course will give you an in-depth understanding of the shared responsibility model. You will learn to create policies and configure and deploy access to services using RBAC. You will see how to configure the built-in roles in Azure to control access to Azure resources. Finally, you will learn to monitor, maintain, and protect resources.
This is the second course in a series of seven courses that will prepare you to succeed in the AZ-500 exam.
In this module, you will learn how to protect identities in Azure AD using Conditional Access, multifactor authentication (MFA), access reviews, and other capabilities. You will learn how to plan and configure privilege identity management (PIM) for roles and resources. You will also learn how to manage, assign, activate, and approve requests for a privileged access group. You will also learn how to investigate and remediate risks detected by Azure AD Identity Protection.
Assign eligibility for a privileged access group•5 minutes
Exercise: Configure Azure Active Directory Privileged Identity Management for groups•15 minutes
Solution: Configure Azure Active Directory Privileged Identity Management for groups•5 minutes
Additional resources: Bring groups into Privileged Identity Management•3 minutes
4 assignments•Total 75 minutes
Knowledge check: Deploy Azure Active Directory identity protection•15 minutes
Knowledge check: Azure Active Directory Privileged Identity Management•15 minutes
Knowledge check: Working with Azure Active Directory groups and guests in Azure Privileged Identity Management•15 minutes
Module quiz: Identity protection and governance•30 minutes
1 discussion prompt•Total 5 minutes
Meet & greet•5 minutes
Policies, initiatives and recommendations
Module 2•3 hours to complete
Module details
In this module, you will learn about the core principles of enterprise governance. You will gain an in-depth understanding of the shared responsibility model and how it impacts security configuration. You will explore the Azure cloud security advantages. You will learn how to create policies to protect your solutions and configure and deploy access to services using role-based access control (RBAC). You will also learn about the Azure hierarchy of systems.
What's included
7 videos9 readings3 assignments
Show info about module content
7 videos•Total 37 minutes
Overview of the shared responsibility model•5 minutes
Explore the Azure cloud security advantages•5 minutes
Review Azure hierarchy of systems•6 minutes
Overview of Azure policies•5 minutes
Azure policy effects•7 minutes
Group policies into initiatives•4 minutes
Module summary•6 minutes
9 readings•Total 107 minutes
The shared responsibility model in depth•14 minutes
Policies, initiatives, and recommendations•9 minutes
Additional resources: Core principles of enterprise governance•3 minutes
Azure built-in policies•13 minutes
Azure policy definition structure•13 minutes
Get compliance data of Azure resources•10 minutes
Built-in initiatives•10 minutes
Exercise: Implement Azure Policy•30 minutes
Solution: Implement Azure Policy•5 minutes
3 assignments•Total 60 minutes
Knowledge check: Core principles of enterprise governance•15 minutes
Knowledge check: Policies•15 minutes
Module quiz: Policies, initiatives and recommendations•30 minutes
Role-based access control
Module 3•4 hours to complete
Module details
In this module, you will learn about Azure role-based access control (RBAC) and how to enable and assign RBAC roles, including the key differences between Azure Policy and RBAC. You will learn how to configure the built-in roles in Azure to control access to Azure resources, the structure of role definitions for access control, how to define custom role permissions, and create and assign a custom role to a user. You will also learn how to monitor, maintain, and protect resources. You will learn how to deploy Azure blueprints and design an Azure subscription management plan.
What's included
10 videos7 readings3 assignments
Show info about module content
10 videos•Total 62 minutes
What is Azure role-based access control?•7 minutes
Enable Azure role-based access control•8 minutes
Compare and contrast Azure role-based access control vs Azure policies•4 minutes
Azure built-in roles•5 minutes
An overview of custom roles in Azure•7 minutes
An overview of resource locks•6 minutes
Demo: Manage resource locks•4 minutes
Deploy Azure blueprints•8 minutes
Design an Azure subscription management plan•8 minutes
Module summary•6 minutes
7 readings•Total 99 minutes
Exercise: Azure role-based access control Role assignments•30 minutes
Solution: Azure role-based access control Role assignments•5 minutes
Create custom roles in Azure•10 minutes
Additional resources – Role-based access control (RBAC)•4 minutes
Exercise: Enable users to manage resource locks•15 minutes
Solution: Enable users to manage resource locks•5 minutes
Course 2 Glossary: Identity Protection and Governance •30 minutes
Our goal at Microsoft is to empower every individual and organization on the planet to achieve more.
In this next revolution of digital transformation, growth is being driven by technology. Our integrated cloud approach creates an unmatched platform for digital transformation. We address the real-world needs of customers by seamlessly integrating Microsoft 365, Dynamics 365, LinkedIn, GitHub, Microsoft Power Platform, and Azure to unlock business value for every organization—from large enterprises to family-run businesses. The backbone and foundation of this is Azure.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I subscribe to this Certificate?
When you enroll in the course, you get access to all of the courses in the Certificate, and you earn a certificate when you complete the work. Your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.