1Manage identity, access, and governance
- 1.1Securing access with Microsoft Entra ID
Learn the identity foundations of SC-500: Privileged Identity Management (PIM), conditional access, multifactor authentication (MFA) and passwordless, application identities (enterprise apps / app registrations) and OAuth consent management, and managed identities for Azure resources—implemented through least privilege and Zero Trust.
- 1.2Protecting secrets and keys with Azure Key Vault
Learn Azure Key Vault for safely storing secrets, keys, and certificates: deployment, the access models (RBAC vs access policies), network restriction (firewall / private endpoint), managing keys/secrets/certificates, and threat detection via Defender CSPM secret scanning and Defender for Key Vault.
- 1.3Enforcing security and compliance through governance
Learn to enforce controls with Azure Policy (built-in/custom definitions), evaluate regulatory compliance and configure security standards/recommendations with Microsoft Defender for Cloud, apply resource locks, manage built-in/custom roles and remediate over-privileged access (RBAC), use Azure Backup security features, and implement security controls via infrastructure as code.

