Lesson 1: Build an overall security strategy and architecture
- Identify the integration points in an architecture by using Microsoft Cybersecurity Reference Architectures (MCRA)
- MCRA and Cloud Adoption Framework Secure Methodology.
- How to use the MCRA to identify integration points.
- Translate business goals into security requirements
- Translation process.
- Translate security requirements into technical capabilities, including security services, security products and security processes
- Requirement: Mitigate compromise of accounts using password spray and other credential compromise.
- Requirement: Shorten response times to attacks across resources in the environment.
- Requirement: Integrate network security into Infrastructure as a Code (IaC) automation.
- Requirement: Enable eDiscovery processes for Office 365 data.
- Design security for a resiliency strategy
- Reducing risk by reducing critical security events.
- Resilience requires shifting from a network-centric to an asset- and data-centric mindset.
- Integrate a hybrid or multi-tenant environment into a security strategy
- Develop a technical governance strategy for security
- Summary
- Case Study
- Quiz
Lesson 2: Design a security operations strategy
- Design a logging and auditing strategy to support security operations
- Centralizing log collection.
- Deciding which logs have security value.
- Designing security operations use cases.
- Determining log retention periods.
- Develop security operations to support a hybrid or multi-cloud environment
- Cross-platform log collection.
- Cloud security posture management (CSPM).
- Focus on identity.
- Internet of Things (IoT)/Operational Technology (OT) coverage.
- Design a strategy for SIEM and SOAR
- Microsoft Security Operations Reference Architecture.
- Ingest logs into your SIEM.
- Automate, automate, automate.
- Evaluate security workflows
- General incident response workflow.
- Automation, automation, automation (again).
- Evaluate a security operations strategy for the incident management lifecycle
- Microsoft’s approach to security incident management.
- Detection and analysis.
- Post-incident activity.
- Evaluate a security operations strategy for sharing technical threat intelligence
- Microsoft’s threat intelligence strategy.
- Sharing technical threat intelligence in your organization.
- Summary
- Case Study
- Quiz
Lesson 3: Design an identity security strategy
- Design a strategy for access to cloud resources
- Identity-related access controls.
- Network-related access controls.
- Coordinated identity and network access.
- Interconnection and cross-service collaboration.
- Assume-breach and explicitly verify.
- People, process, and technology approach.
- Recommend an identity store (tenants, B2B, B2C, and hybrid)
- Foundational implementations.
- External collaboration.
- Recommend an authentication strategy
- Enterprise accounts.
- Specialized accounts.
- Controlling authentication sessions.
- Key recommendations.
- Recommend an authorization strategy
- Configuring access to support authorization.
- Decentralized identities.
- Key recommendations.
- Design a strategy for conditional access
- Key recommendations.
- Design a strategy for role assignment and delegation
- Delegating to non-administrators.
- Delegating access to service providers.
- Design security strategy for privileged-role access to infrastructure, including identity-based firewall rules and Azure PIM
- Privileged Access Workstation (PAW).
- Privileged Identity Management (PIM).
- Microsoft Entra Permissions Management.
- Key recommendations.
- Design security strategy for privileged activities, including PAM, entitlement management, and cloud tenant administration
- Privileged Access Workstation (PAM).
- Privileged Identity Management (PIM).
- Microsoft Entra Permission Management.
- Summary
- Case Study
- Quiz
Lesson 4: Design a regulatory compliance strategy
- Interpret compliance requirements and translate specific technical capabilities (new or existing)
- Security compliance translation process.
- Resolving conflicts between compliance and security.
- Evaluate infrastructure compliance by using Microsoft Defender for Cloud
- Interpret compliance scores and recommend actions to resolve issues or improve security
- Design implementation of Azure Policy
- Design for data residency requirements
- Translate privacy requirements into requirements for security solutions
- Security and privacy.
- Summary
- Case Study
- Quiz
Lesson 5: Evaluate security posture and recommend technical strategies to manage risk
- Evaluate security posture by using benchmarks (including Azure Security benchmarks for Microsoft Cloud security benchmark, ISO 27001, etc.)
- Microsoft Cloud security benchmark.
- Monitoring your MCSB compliance.
- Industry standards.
- Evaluate security posture by using Microsoft Defender for Cloud
- Defender for Cloud.
- Security posture management.
- Considerations for multi-cloud.
- Considerations for vulnerability assessment.
- Evaluate security posture by using Secure Scores
- Secure Score in Defender for Cloud.
- Evaluate security posture of cloud workloads
- Workload security.
- Design security for an Azure Landing Zone
- Design principles.
- Enforcing guardrails.
- Single management plane.
- Application–centric.
- Security considerations.
- Interpret technical threat intelligence and recommend risk mitigations
- Threat intelligence in Defender for Cloud.
- Threat intelligence in Microsoft Sentinel.
- Recommend security capabilities or controls to mitigate identified risks
- Identifying and mitigating risks.
- Summary
- Case Study
- Quiz
Lesson 6: Design a strategy for securing server and client endpoints
- Specify security baselines for server and client endpoints
- Group Policy Objects (GPO).
- Security Compliance Toolkit (SCT).
- Azure Security Benchmark (ASB).
- Microsoft Endpoint Manager (MEM).
- PowerShell DSC.
- Azure Automation.
- Azure Policy.
- Azure Resource Manager (ARM) templates.
- Microsoft Defender for Cloud (MDC).
- Microsoft Defender for IoT (MDIoT).
- Baseline configuration.
- Key Recommendations.
- Specify security requirements for servers, including multiple platforms and operating systems
- Shared responsibility in the cloud.
- Legacy insecure protocols.
- Threat protection.
- Local Administrator Password Management (LAPS).
- User rights assignments.
- Network-based controls.
- Specify security requirements for mobile devices and clients, including endpoint protection, hardening, and configurations
- Local Administrator Password Management.
- Basic Mobility and Security.
- Threat protection.
- Conditional access.
- Microsoft Intune.
- User rights assignments.
- Micro-segmentation.
- Other security controls.
- Specify requirements to secure Active Directory Domain Services
- Secure the control plane.
- Privileged Access Management.
- Key recommendations.
- Microsoft Defender for Identity.
- Active Directory Federation Services (AD FS).
- Design a strategy to manage secrets, keys, and certificates
- Access control.
- Configuration control.
- Key management.
- Key recommendations.
- Design a strategy for secure remote access
- Key configurations to enable secure remote access.
- Remote access to desktop, applications, and data.
- Remote access to on-premises web applications.
- RDP/SSH connectivity.
- Remotely provisioning new devices.
- B2B collaboration.
- Key recommendations.
- Summary
- Case Study
- Quiz
Lesson 7: Design a strategy for securing SaaS, PaaS, and IaaS services
- Specify security baselines for SaaS, PaaS, and IaaS services
- Specify security baselines for SaaS services.
- Specify security requirements for IoT workloads
- Security requirements.
- Security posture and threat detection.
- Specify security requirements for data workloads, including SQL, Azure SQL Database, Azure Synapse, and Azure Cosmos DB
- Security considerations for Azure Cosmos DB.
- Specify security requirements for web workloads, including Azure App Service
- Network communication.
- Authentication and authorization.
- Security posture and threat protection.
- Specify security requirements for storage workloads, including Azure Storage
- Data protection.
- Identity and access management.
- Logging and monitoring.
- Specify security requirements for containers
- Hardening access to Azure Container Registry.
- Specify security requirements for container orchestration
- Threat detection.
- Summary
- Case Study
- Quiz
Lesson 8: Specify security requirements for applications
- Specify priorities for mitigating threats to applications
- Classifying applications.
- Application threat modeling.
- Microsoft Security Development Lifecycle (SDL).
- Specify a security standard for onboarding a new application
- Old versus new.
- Security standards for onboarding applications.
- Specify a security strategy for applications and APIs
- Waterfall to Agile/DevOps.
- Security in DevOps (DevSecOps).
- Summary
- Case Study
- Quiz
Lesson 9: Design a strategy for securing data
- Specify priorities for mitigating threats to data
- Common threats.
- Design a strategy to identify and protect sensitive data
- Know your data.
- Protect your data.
- Prevent data loss.
- Govern your data.
- Specify an encryption standard for data at rest and in motion
- Encrypt at rest.
- Encryption in motion.
- Summary
- Case Study
- Quiz
Lesson 10: Microsoft Cybersecurity Reference Architectures and Microsoft cloud security benchmark best practices
- Recommend best practices for cybersecurity capabilities and controls
- Recommend best practices for protecting from insider and external attacks
- Recommend best practices for Zero Trust security
- Recommend best practices for the Zero Trust Rapid Modernization Plan
- Summary
- Case Study
- Quiz
Lesson 11: Recommend a secure methodology by using the Cloud Adoption Framework (CAF)
- Recommend a DevSecOps process
- DevSecOps Control.
- Plan and develop.
- Commit the code.
- Build and test.
- Go to production and operate.
- Recommend a methodology for asset protection
- Getting secure.
- Staying secure.
- Key recommendations for an asse protection program
- Recommend strategies for managing and minimizing risk
- Measuring risk.
- Managing security risk.
- Summary
- Case Study
- Quiz
Lesson 12: Recommend a ransomware strategy by using Microsoft Security Best Practices
- Plan for ransomware protection and extortion-based attacks
- Security hygiene and damage control.
- Protect assets from ransomware attacks
- Enter environment.
- Traverse and spread.
- Execute objective.
- Recommend Microsoft ransomware best practices
- Best practices.
- Summary
- Case Study
- Quiz