AZ-500T00: Microsoft Azure Security Technologies Training & Certification Course
AZ-500T00: Secure cloud resources with Microsoft security technologies equips Azure Security Engineers with skills to implement security controls, manage identity and access, secure networks, and monitor threats using Microsoft Defender for Cloud and Sentinel.
Course Overview
Students in the AZ-500T00 course gain hands-on experience with core Microsoft security technologies including Microsoft Entra ID, Azure Key Vault, Azure Security Center (now Microsoft Defender for Cloud), Microsoft Sentinel, Network Security Groups (NSGs), and Azure SQL Database. Through guided labs in the Azure Portal, learners configure role-based access control, implement conditional access policies, secure virtual networks, and deploy Always Encrypted in Azure SQL databases using keys stored in Azure Key Vault. A key real-world scenario involves building a secure data-driven application that integrates Microsoft Entra ID authentication and leverages Azure Key Vault to protect sensitive data, demonstrating end-to-end security implementation aligned with the Microsoft Cloud Security Benchmark.
This course directly prepares candidates for the Microsoft Certified: Azure Security Engineer Associate designation, a globally recognized certification that validates expertise in securing cloud and hybrid environments. Certified professionals report median salaries of $153,000 in the U.S., with senior roles such as Cloud Security Architect reaching up to $180,000 or more. Optiv Solutions enhances this learning path with Guaranteed-to-Run batches and access to official Microsoft courseware, ensuring structured, instructor-led preparation. Upon completion, graduates are positioned to advance into specialized security roles, lead compliance initiatives, and drive secure cloud adoption across enterprise organizations.
Skills You’ll Develop
Who Should Attend
WHO SHOULD ATTEND (TARGET AUDIENCE)
• Azure Administrators
• IT Security Specialists
• Cloud Architects
• Network Engineers
• DevOps Engineers
• Systems Administrators with a focus on cloud technologies
• Cybersecurity Analysts
• Compliance Managers
• Data Protection Officers
Pre-requisites
RECOMMENDED KNOWLEDGE BEFORE TAKING THIS COURSE
- ✓ Azure administrator certification such as AZ-104 or equivalent Azure cloud management experience
- ✓ Hands-on knowledge of Azure virtual networking components like VNets, subnets, and Network Security Groups (NSGs)
- ✓ Practical experience with identity and access management using Azure Active Directory and role-based access control (RBAC)
- ✓ Familiarity with security protocols including Virtual Private Networks (VPN), Internet Security Protocol (IPSec), and Secure Socket Layer (SSL)
- ✓ Experience managing Windows and Linux servers, including proficiency with PowerShell and command-line interfaces
- ✓ Understanding of disk encryption, data security methods, and security best practices like defense in depth and zero trust architecture
Certification Exam Details
Everything you need to know about the certification exam
Exam Details
Upcoming Batch Schedule
Enroll in upcoming batches and start your learning journey
Curriculum & Course Syllabus
Module 1: Manage identity and access
- Manage Microsoft Entra identities
- Secure Microsoft Entra users
- Secure Microsoft Entra groups
- Recommend when to use external identities
- Secure external identities
- Implement Microsoft Entra ID Protection
- Manage Microsoft Entra authentication
- Implement multi-factor authentication (MFA)
- Configure Microsoft Entra Verified ID
- Implement passwordless authentication
- Implement password protection
- Implement single sign-on (SSO)
- Integrate single sign on (SSO) and identity providers
- Recommend and enforce modern authentication methods
- Manage Microsoft Entra authorization
- Configure Azure role permissions for management groups, subscriptions, resource groups, and resources
- Assign Microsoft Entra built-in roles
- Assign Azure built-in roles
- Create and assign custom roles, including Azure roles and Microsoft Entra roles
- Implement and manage Microsoft Entra Permissions Management
- Configure Microsoft Entra Privileged Identity Management
- Configure role management and access reviews in Microsoft Entra
- Manage Microsoft Entra application access
- Manage access to enterprise applications in Microsoft Entra ID, including OAuth permission grants
- Manage Microsoft Entra app registrations
- Configure app registration permission scopes
- Manage app registration permission consent
- Manage and use service principals
- Manage managed identities for Azure resources
- Recommend when to use and configure a Microsoft Entra Application Proxy, including authentication
Module 2: Secure Networking
- Plan and implement security for virtual networks
- Plan and implement Network Security Groups (NSGs) and Application Security Groups (ASGs)
- Plan and implement user-defined routes (UDRs)
- Plan and implement Virtual Network peering or VPN gateway
- Plan and implement Virtual WAN, including secured virtual hub
- Secure VPN connectivity, including point-to-site and site-to-site
- Implement encryption over ExpressRoute
- Configure firewall settings on PaaS resources
- Monitor network security by using Network Watcher, including NSG flow logging
- Plan and implement security for private access to Azure resources
- Plan and implement virtual network Service Endpoints
- Plan and implement Private Endpoints
- Plan and implement Private Link services
- Plan and implement network integration for Azure App Service and Azure Functions
- Plan and implement network security configurations for an App Service Environment (ASE)
- Plan and implement network security configurations for an Azure SQL Managed Instance
- Plan and implement security for public access to Azure resources
- Plan and implement Transport Layer Security (TLS) to applications, including Azure App Service and API Management
- Plan, implement, and manage an Azure Firewall, including Azure Firewall Manager and firewall policies
- Plan and implement an Azure Application Gateway
- Plan and implement an Azure Front Door, including Content Delivery Network (CDN)
- Plan and implement a Web Application Firewall (WAF)
- Recommend when to use Azure DDoS Protection Standard
Module 3: Secure compute, storage, and databases
- Configure Bring your own key (BYOK)
- Enable double encryption at the Azure Storage infrastructure level
- Plan and implement security for Azure SQL Database and Azure SQL Managed Instance
- Plan and implement advanced security for compute
- Plan and implement remote access to public endpoints, including Azure Bastion and just-in-time (JIT) virtual machine (VM) access
- Configure network isolation for Azure Kubernetes Service (AKS)
- Secure and monitor AKS
- Configure authentication for AKS
- Configure security monitoring for Azure Container Instances (ACIs)
- Configure security monitoring for Azure Container Apps (ACAs)
- Manage access to Azure Container Registry (ACR)
- Configure disk encryption, including Azure Disk Encryption (ADE), encryption at host, and confidential disk encryption
- Recommend security configurations for Azure API Management
- Plan and implement security for storage
- Configure access control for storage accounts
- Manage life cycle for storage account access keys
- Select and configure an appropriate method for access to Azure Files
- Select and configure an appropriate method for access to Azure Blob Storage
- Select and configure an appropriate method for access to Azure Tables
- Select and configure an appropriate method for access to Azure Queues
- Select and configure appropriate methods for protecting against data security threats, including soft delete, backups, versioning, and immutable storage
- Enable Microsoft Entra database authentication
- Enable database auditing
- Identify use cases for the Microsoft Purview governance portal
- Implement data classification of sensitive information by using the Microsoft Purview governance portal
- Plan and implement dynamic masking
- Implement Transparent Data Encryption (TDE)
- Recommend when to use Azure SQL Database Always Encrypted
Module 4: Manage security operations
- Plan, implement, and manage governance for security
- Create, assign, and interpret security policies and initiatives in Azure Policy
- Configure security settings by using Azure Blueprints
- Deploy secure infrastructures by using a landing zone
- Create and configure an Azure Key Vault
- Recommend when to use a dedicated Hardware Security Module (HSM)
- Configure access to Key Vault, including vault access policies and Azure Role Based Access Control
- Manage certificates, secrets, and keys
- Configure key rotation
- Configure backup and recovery of certificates, secrets, and keys
- Manage security posture by using Microsoft Defender for Cloud
- Identify and remediate security risks by using the Microsoft Defender for Cloud Secure Score and Inventory
- Assess compliance against security frameworks and Microsoft Defender for Cloud
- Add industry and regulatory standards to Microsoft Defender for Cloud
- Add custom initiatives to Microsoft Defender for Cloud
- Connect hybrid cloud and multi-cloud environments to Microsoft Defender for Cloud
- Identify and monitor external assets by using Microsoft Defender External Attack Surface Management
- Configure and manage threat protection by using Microsoft Defender for Cloud
- Enable workload protection services in Microsoft Defender for Cloud, including Storage, Databases, Containers, App Service, Key Vault, and Resource Manager
- Configure Microsoft Defender for Servers
- Configure Microsoft Defender for Azure SQL Database
- Manage and respond to security alerts in Microsoft Defender for Cloud
- Configure workflow automation by using Microsoft Defender for Cloud
- Evaluate vulnerability scans from Microsoft Defender for Server
Student Reviews & Testimonials
Real feedback from certified professionals and corporate teams
Frequently Asked Questions
Is the AZ-500 exam included in the AZ-500T00: Secure cloud resources with Microsoft security technologies course fee, and what is the cost if purchased separately?
The AZ-500 certification exam is not included in the AZ-500T00: Secure cloud resources with Microsoft security technologies course fee. You must purchase it separately for $165 USD, with pricing varying by your region. Pearson VUE proctors the exam; register using your personal Microsoft account to ensure your official certification records remain accessible.
How long is lab access provided for AZ-500T00: Secure cloud resources with Microsoft security technologies, and what environment is used?
You receive 30 days of lab access for AZ-500T00: Secure cloud resources with Microsoft security technologies using Microsoft Azure Cloud Slice. This sandbox environment requires no Azure Pass. This official Microsoft lab allows you to implement security controls in real-world scenarios. You gain 10 lab launches per session for hands-on practice.
What is the format, number of questions, passing score, and time limit for the AZ-500 exam?
The AZ-500 exam features 40-60 questions, including labs, case studies, and multiple-choice items. You have 100 minutes to complete the test. The passing score is 700 out of 1000. Pearson VUE proctors the exam, which validates your expertise in identity, networking, compute security, and security operations within the Microsoft Azure ecosystem.
How long is the Microsoft Certified: Azure Security Engineer Associate certification valid, and what is the renewal process?
Your Microsoft Certified: Azure Security Engineer Associate certification is valid for 12 months. Renew it by passing a free, online assessment on Microsoft Learn before it expires. The assessment takes 45 minutes and covers recent Azure security updates. If you fail, you can retake it immediately, with a 24-hour wait required after your second attempt.