
Azure Security Course
Master enterprise-grade security across every layer of Microsoft Azure, from identity and network controls to threat detection and compliance. This course equips cloud professionals with the technical depth and strategic thinking needed to protect real-world Azure environments. Whether you are hardening workloads or advising leadership, you will leave with skills that matter.
What you will learn:
This course covers the full spectrum of Azure security, including identity and access management, network segmentation, data encryption, and regulatory compliance. You will configure Microsoft Defender for Cloud, build detection rules in Microsoft Sentinel, and automate incident response with SOAR playbooks. You will also learn to secure CI/CD pipelines, harden Kubernetes workloads, and implement zero-trust architecture at enterprise scale. Practical topics include Key Vault operations, penetration testing scoping, and executive risk reporting. Every chapter is built around the controls and tools Azure security professionals use every day.
How you study in practice Azure Security Course
How you practise Azure Security Course
For businesses looking to train their team
With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.
Course content
8 Chapters • 41 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsAzure Security Foundations and Cloud Risk
Azure Security Foundations and Cloud Risk
Lesson 1 • Shared Responsibility Model
Defines security duties split between Microsoft and the customer across IaaS, PaaS, and SaaS. Prevents misconfigured ownership assumptions.
Lesson 2 • Azure Security Benchmark Introduction
Presents the Azure Security Benchmark as a prescriptive control baseline. Students learn to use it as a gap-analysis tool for their environments.
Lesson 3 • Azure Global Infrastructure Overview
Maps Azure regions, availability zones, and data residency concepts. Provides the physical and logical context for security boundary decisions.
Lesson 4 • Cloud Security Fundamentals
Covers CIA triad, threat actors, and cloud-specific attack surfaces. Anchors all subsequent Azure security decisions in foundational risk thinking.
Lesson 5 • Azure Compliance and Governance Basics
Introduces compliance frameworks, Azure Policy, and regulatory alignment concepts. Sets governance context before technical controls are introduced.
Chapter 2HideHide detailsSee detailsIdentity and Access Management in Azure
Identity and Access Management in Azure
Lesson 1 • Azure Active Directory Core Concepts
Covers tenants, users, groups, and directory roles in Azure AD. Establishes the identity plane that all access control chapters build upon.
Lesson 2 • Authentication Methods and MFA
Examines password policies, MFA options, and passwordless authentication. Reduces credential-based attack risk across all Azure workloads.
Lesson 3 • Role-Based Access Control Design
Covers built-in and custom RBAC roles, scope hierarchy, and least-privilege design. Prevents over-permissioned identities from expanding blast radius.
Lesson 4 • Privileged Identity Management
Implements just-in-time privileged access, approval workflows, and access reviews. Minimises standing privileged access exposure in production environments.
Lesson 5 • Managed Identities and Service Principals
Eliminates credential storage by using managed identities for Azure service authentication. Secures application-to-service communication without secrets in code.
Lesson 6 • Conditional Access Policies
Teaches signal-based access decisions using location, device, and risk signals. Enables adaptive enforcement without blocking legitimate productivity.
Chapter 3HideHide detailsSee detailsNetwork Security in Azure
Network Security in Azure
Lesson 1 • Azure Firewall and Forced Tunneling
Deploys Azure Firewall for centralised traffic inspection and FQDN-based filtering. Forced tunnelling routes internet-bound traffic through security inspection points.
Lesson 2 • Private Endpoints and Service Endpoints
Eliminates public internet exposure for PaaS services using private connectivity. Reduces data exfiltration risk by keeping traffic within the Azure backbone.
Lesson 3 • Network Security Groups and Application Security Groups
Teaches inbound and outbound rule creation, priority logic, and ASG-based grouping. Enforces micro-segmentation at the subnet and NIC level.
Lesson 4 • Virtual Network Architecture and Segmentation
Covers VNet design, subnets, and address space planning for security isolation. Provides the network foundation for all subsequent perimeter controls.
Lesson 5 • DDoS Protection and Web Application Firewall
Configures DDoS Protection plans and WAF policies for public-facing workloads. Defends against volumetric and application-layer attacks at scale.
Chapter 4HideHide detailsSee detailsData Security and Encryption in Azure
Data Security and Encryption in Azure
Lesson 1 • Data Classification and Sensitivity Labeling
Applies sensitivity labels and classification schemes to Azure data assets. Drives encryption and access decisions based on data sensitivity tiers.
Lesson 2 • Encryption in Transit and TLS Enforcement
Enforces TLS 1.2+ across Azure services and configures secure transfer requirements. Prevents interception of data moving between clients and Azure endpoints.
Lesson 3 • Azure Key Vault Design and Operations
Manages secrets, keys, and certificates using Key Vault with access policies and RBAC. Centralises cryptographic material management and rotation.
Lesson 4 • Azure Storage Security Controls
Secures Blob, File, Queue, and Table storage with SAS tokens, firewall rules, and immutability. Prevents unauthorised access and accidental data deletion.
Lesson 5 • Encryption at Rest in Azure Services
Covers platform-managed and customer-managed key encryption for storage and databases. Ensures data remains protected even if physical media is compromised
Chapter 5HideHide detailsSee detailsSecurity Posture Management and Defender for Cloud
Security Posture Management and Defender for Cloud
Lesson 1 • Secure Score and Recommendations
Interprets Secure Score metrics and prioritises actionable hardening recommendations. Drives measurable posture improvement through structured remediation.
Lesson 2 • Workflow Automation and Remediation
Automates alert response and recommendation remediation using Logic Apps and playbooks. Reduces mean time to remediate by eliminating manual triage steps.
Lesson 3 • Defender Plans for Azure Workloads
Enables workload-specific Defender plans for VMs, SQL, storage, and containers. Extends threat detection to each resource type with tailored analytics.
Lesson 4 • Microsoft Defender for Cloud Overview
Introduces Defender for Cloud's CSPM and CWP capabilities across Azure workloads. Establishes the central console for posture visibility and threat detection.
Lesson 5 • Security Alerts and Threat Detection
Analyses Defender for Cloud alerts, maps them to MITRE ATT&CK, and triages incidents. Builds analyst skills for distinguishing true positives from noise.
Chapter 6HideHide detailsSee detailsThreat Detection, SIEM, and Incident Response
Threat Detection, SIEM, and Incident Response
Lesson 1 • Analytics Rules and Detection Engineering
Builds scheduled, NRT, and fusion analytics rules to surface malicious patterns. Teaches KQL-based detection logic tuned to reduce false positives.
Lesson 2 • Microsoft Sentinel Architecture and Onboarding
Configures Sentinel workspaces, data connectors, and log ingestion from Azure sources. Establishes the detection platform for all subsequent analytics work.
Lesson 3 • Incident Investigation and Hunting
Uses Sentinel's investigation graph, bookmarks, and hunting queries to trace attack paths. Develops analyst skills for proactive threat discovery beyond alert queues.
Lesson 4 • SOAR Playbooks and Incident Response
Automates containment and notification actions using Sentinel playbooks and Logic Apps. Standardises incident response to reduce human error under pressure.
Lesson 5 • Threat Intelligence Integration
Ingests threat intelligence feeds and applies indicators to Sentinel analytics. Enriches detections with external context to improve alert fidelity.
Chapter 7HideHide detailsSee detailsApplication and DevSecOps Security in Azure
Application and DevSecOps Security in Azure
Lesson 1 • Secrets Management in Application Code
Eliminates hardcoded credentials by integrating Key Vault references and managed identities. Prevents secret leakage in source control and deployment artefacts.
Lesson 2 • Container and Kubernetes Security
Secures Azure Kubernetes Service clusters, container images, and runtime environments. Addresses container-specific threats including image vulnerabilities and privilege escalation.
Lesson 3 • Secure CI/CD Pipeline Integration
Integrates SAST, DAST, dependency scanning, and IaC security checks into Azure DevOps. Enforces security gates that block vulnerable code from reaching production.
Lesson 4 • API Security and Azure API Management
Secures APIs with OAuth 2.0, rate limiting, and threat protection policies in APIM. Prevents API abuse, data leakage, and unauthorised access at the gateway layer.
Lesson 5 • Secure Application Design Principles
Applies threat modelling, secure design patterns, and zero-trust principles to Azure apps. Prevents architectural vulnerabilities before code is written.
Chapter 8HideHide detailsSee detailsAdvanced Security Architecture and Strategy
Advanced Security Architecture and Strategy
Lesson 1 • Security Metrics and Executive Reporting
Defines KPIs, KRIs, and security dashboards for communicating risk to leadership. Translates technical findings into business-impact language for decision-makers.
Lesson 2 • Security Architecture Review Process
Conducts structured architecture reviews using threat modelling and control validation. Embeds security review gates into project delivery and change management.
Lesson 3 • Multi-Cloud and Hybrid Security Considerations
Extends Azure security controls to on-premises and multi-cloud environments via Arc and Defender. Maintains consistent posture across heterogeneous infrastructure.
Lesson 4 • Landing Zone Security Design
Applies Azure Landing Zone security controls including policy-driven governance and segmentation. Ensures security is built into the platform before workloads are deployed.
Lesson 5 • Zero-Trust Architecture in Azure
Implements verify-explicitly, least-privilege, and assume-breach principles across Azure. Translates zero-trust theory into concrete Azure control configurations.
Your valid completion certificate
This course is for you:
Cloud engineer: wants to take ownership of Azure security beyond basic configurations.
IT administrator: transitioning from on-premises infrastructure into cloud security responsibilities.
Security analyst: expanding skills from general cybersecurity into Azure-specific threat detection.
DevOps engineer: looking to embed security practices directly into pipelines and deployments.
Compliance officer: needs technical fluency to evaluate and enforce Azure regulatory controls.
Career changer: moving from a non-security IT role into a dedicated cloud security position.
What our students say
Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast and simple to use. The diversity of content and complementary videos really help with learning.

Top qualifications
FAQ
Who is Dedika?
Is the certificate valid in the United Kingdom?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















