This study plan is designed to help you master Azure Security, from foundational concepts to advanced security engineering and operations. It aligns with Microsoft certifications like AZ-500 and SC series.
- Azure Fundamentals - 2 weeks
- Identity and Access Management - 2 weeks
- Platform Protection - 2 weeks
- Security Operations - 2 weeks
- Resources
Duration: 2 weeks
Start here if you are new to Azure.
- Core Concepts:
- Regions, Availability Zones, Subscriptions, Resource Groups.
- IaaS, PaaS, SaaS in Azure context.
- Core Services:
- Compute (VMs, App Service, AKS).
- Networking (VNet, NSG, Load Balancers).
- Storage (Blob, File, Disk).
- Basic Security:
- Shared Responsibility Model.
- Azure Policy & Blueprints basics.
- Microsoft Defender for Cloud (Free tier).
Duration: 2 weeks
Identity is the new perimeter.
- Core Identity:
- Users, Groups, Service Principals, Managed Identities.
- Hybrid Identity (Azure AD Connect).
- Access Control:
- RBAC: Built-in roles, Custom roles, Scope (Mgmt Group > Sub > RG > Resource).
- Conditional Access: Policies based on location, device state, risk.
- Identity Protection:
- PIM (Privileged Identity Management).
- MFA and Passwordless auth.
- Identity Protection (Risk detection).
Duration: 2 weeks
Securing the infrastructure and data.
- Network Security:
- NSGs vs ASGs.
- Azure Firewall & Azure Firewall Manager.
- DDoS Protection (Basic vs Standard).
- Private Link & Service Endpoints.
- Compute & Container Security:
- VM security (Bastion, JIT access, Disk Encryption).
- AKS Security (Network policies, private clusters).
- Data Security:
- Key Vault (Secrets, Keys, Certs).
- Storage Security (SAS tokens, Access Keys, Encryption).
- SQL Database Security (TDE, Firewall, Auditing).
Duration: 2 weeks
Monitoring and responding to threats.
- Microsoft Defender for Cloud:
- CSPM (Cloud Security Posture Management) - Secure Score.
- CWP (Cloud Workload Protection) - Alerts for VMs, Storage, SQL, Containers.
- Microsoft Sentinel (SIEM/SOAR):
- Connecting data sources.
- KQL (Kusto Query Language) basics for hunting.
- Creating Analytics Rules and Incidents.
- Automation with Playbooks (Logic Apps).
- AZ-500: Azure Security Technologies (Core certification).
- SC-900: Security, Compliance, and Identity Fundamentals.
- SC-200: Security Operations Analyst (Sentinel/Defender focus).
- SC-300: Identity and Access Administrator (Entra ID focus).
- Azure Citadel
- Microsoft GitHub Labs (Search for AZ-500)