All certifications / SC-500 / Lessons
SC-500 SC-500 lessons
Study SC-500 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-500 study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Manage identity, access, and governance
- Microsoft Entra built-in roles vs Azure RBAC roles, scopes (management group, subscription, resource group, resource) and least privilege
- Custom Azure RBAC roles: actions, notActions, dataActions and assignable scopes
- Privileged Identity Management: eligible vs active assignments, activation with MFA, approval and justification, access reviews
- Conditional Access: users and workload identities, cloud apps, conditions (sign-in risk, locations, device platform), grant and session controls, report-only mode
- MFA and authentication methods policy, phishing-resistant methods (FIDO2, passkeys, Windows Hello), authentication strengths
- Managed identities: system-assigned vs user-assigned, and replacing stored secrets with token-based access
- App registrations vs enterprise applications (service principals), API permissions, admin consent and user consent settings
- Azure Key Vault: RBAC vs access policies, soft delete and purge protection, key rotation, network restrictions, Defender for Key Vault
- Azure Policy: built-in vs custom definitions, initiatives, effects (Deny, Audit, Modify, DeployIfNotExists), remediation tasks, exemptions
- Resource locks (CanNotDelete, ReadOnly), management group hierarchy and governance at scale
- Finding and fixing over-privileged access with access reviews and Entra ID Protection risk policies
Domain 2: Secure storage, databases, and networking
- Storage authorization: Entra ID with data-plane RBAC, account keys, disabling Shared Key, key rotation
- Shared access signatures: user delegation vs service vs account SAS, stored access policies and revocation
- Storage encryption: Microsoft-managed vs customer-managed keys, infrastructure encryption, immutable blob storage
- Storage firewall, trusted services exceptions, and Defender for Storage (activity monitoring, malware scanning, sensitive data threat detection)
- Azure SQL security: Entra-only authentication, server and database firewall rules, TDE with CMK, Always Encrypted, dynamic data masking, auditing, Defender for SQL
- Network security groups and application security groups, service tags, rule priority and default rules
- Azure Virtual Network Manager security admin rules vs NSGs
- Private endpoints and Private Link vs service endpoints, private DNS zones
- Azure Firewall (Standard vs Premium: TLS inspection, IDPS, URL filtering), Firewall Manager and firewall policy, forced tunneling with user-defined routes
- Web Application Firewall on Application Gateway and Front Door, DDoS Protection
- Site-to-site and point-to-site VPN, Virtual WAN secured hubs, Microsoft Entra Private Access (ZTNA)
- Network Watcher: IP flow verify, effective security rules, VNet flow logs and traffic analytics
Domain 3: Secure compute
- Security for AI: Defender for AI services threat protection, prompt injection and jailbreak alerts, Azure AI Content Safety Prompt Shields
- Microsoft Purview DSPM for AI to find data overexposure to Microsoft 365 Copilot and AI apps
- AI Gateway in Azure API Management in front of Microsoft Foundry models: managed identity authentication, token limits, logging
- Microsoft Entra Agent ID: agent identities, Conditional Access and access management for AI agents
- VM disk protection: encryption at host, Azure Disk Encryption, server-side encryption with customer-managed keys
- Trusted launch: secure boot, vTPM and boot integrity monitoring
- Azure Bastion and just-in-time VM access instead of public RDP/SSH
- Defender for Servers (Plan 1 vs Plan 2), vulnerability assessment, Azure Arc for hybrid and multicloud servers, Azure Update Manager
- AKS security: Entra ID integration, Azure RBAC for Kubernetes, private clusters, network policies, Defender for Containers, Azure Policy for AKS
- Container registry security: disable the admin user, RBAC pull/push roles, private endpoints, image vulnerability scanning
- App Service, Functions and Logic Apps: managed identities, Key Vault references, access restrictions, HTTPS only and minimum TLS, authentication (Easy Auth)
Domain 4: Manage and monitor security posture
- Defender for Cloud: foundational CSPM vs Defender CSPM, secure score and recommendations
- Defender CSPM features: attack path analysis, cloud security explorer, agentless scanning, governance rules
- Regulatory compliance dashboard: Microsoft cloud security benchmark and adding standards
- Workload protection plans (Servers, Storage, SQL, Containers, Key Vault, App Service, AI) and alert handling
- Multicloud connectors for AWS and GCP, and workflow automation with Logic Apps
- Microsoft Sentinel workspace design, data connectors, Azure Monitor Agent with data collection rules, Syslog and CEF, Windows security events
- Sentinel analytics rules: scheduled, near-real-time, Microsoft security (incident creation) and anomaly rules; entity mapping
- Automation rules vs playbooks, incident management, workbooks, hunting queries, watchlists and threat intelligence
- Log tiers and retention (Analytics vs data lake/auxiliary), custom tables, KQL basics
- Microsoft Security Copilot: capacity in SCUs, roles, plugins, promptbooks, standalone vs embedded experiences and agents
- Microsoft Purview Audit for investigations