Choose your language
Azure Compute, Storage, and Database Security Course
More than 2 million students worldwide

Azure Compute, Storage, and Database Security Course

Lock down every layer of your Azure environment — from virtual machines and containers to blob storage and SQL databases. This course delivers hands-on security skills across compute, storage, and database services, grounded in real-world Azure architecture. Master RBAC, threat detection, encryption, and compliance automation to protect cloud workloads at enterprise scale.

Dedika for businesses

What you will learn:

  • Configure role-based access control and least-privilege policies across Azure subscriptions and resources.

  • Secure Azure virtual machines using OS hardening, just-in-time access, and endpoint protection tools.

  • Protect blob, file, and queue storage with encryption, immutability policies, and network restrictions.

  • Implement Azure SQL and Cosmos DB defenses including auditing, data masking, and threat detection.

  • Deploy Microsoft Sentinel with analytics rules and Logic App playbooks for automated incident response.

  • Apply Zero Trust principles and DevSecOps practices to harden CI/CD pipelines and cloud architectures.

How you study in practice Azure Compute, Storage, and Database Security Course

How you practice Azure Compute, Storage, and Database Security Course

For companies looking to train their teams

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course Content

8 Chapters • 41 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Azure Security Foundations and Architecture

  • Lesson 1 • Azure Security Center and Defender Overview

    Introduces Microsoft Defender for Cloud as the unified security posture management tool. Students understand how to read secure scores and prioritize recommendations.

  • Lesson 2 • Regulatory and Compliance Frameworks in Azure

    Maps common industry compliance requirements to Azure built-in policy initiatives and compliance dashboards. Prepares students to align technical controls with audit expectations.

  • Lesson 3 • Cloud Security Shared Responsibility Model

    Defines which security obligations belong to Microsoft versus the customer across service tiers. Anchors all subsequent chapters by clarifying accountability boundaries.

  • Lesson 4 • Azure Global Infrastructure Overview

    Covers regions, availability zones, and data residency concepts that affect security design. Connects physical infrastructure choices to compliance and resilience outcomes.

  • Lesson 5 • Azure Identity and Access Fundamentals

    Introduces Azure Active Directory, tenants, and identity-based access as the security perimeter. Provides the identity foundation required for all resource-level security chapters.

Chapter 2See details

Azure Role-Based Access Control and Policies

  • Lesson 1 • Designing Least-Privilege Access Models

    Applies RBAC principles to minimize standing permissions and reduce attack surface. Students practice scoping roles to specific resource groups and service types.

  • Lesson 2 • Management Groups and Subscription Governance

    Organizes subscriptions into hierarchies to apply policies and RBAC at enterprise scale. Students design governance structures that enforce security baselines across business units.

  • Lesson 3 • RBAC Core Concepts and Roles

    Explains role definitions, assignments, and scope hierarchy across management groups, subscriptions, and resources. Establishes the permission model used throughout all service-specific chapters.

  • Lesson 4 • Azure Policy for Governance and Compliance

    Covers policy definitions, initiatives, and enforcement modes to prevent non-compliant resource configurations. Enables automated guardrails that complement RBAC permissions.

  • Lesson 5 • Custom Role Definitions and Assignments

    Guides creation of custom roles when built-in roles are too permissive or too restrictive. Connects to real-world scenarios where fine-grained control is required.

Chapter 3See details

Azure Virtual Machine and Compute Security

  • Lesson 1 • Disk Encryption and Secure Boot

    Applies Azure Disk Encryption and Trusted Launch to protect data at rest and firmware integrity. Covers key management integration with Azure Key Vault for encryption keys.

  • Lesson 2 • Endpoint Protection and Antimalware

    Deploys Microsoft Antimalware and Defender for Endpoint on Azure VMs to detect and respond to threats. Integrates endpoint telemetry with Defender for Cloud alerts.

  • Lesson 3 • VM Network Isolation and Security Groups

    Uses network security groups, application security groups, and Azure Bastion to isolate VMs. Prevents lateral movement by enforcing traffic rules at the NIC and subnet levels.

  • Lesson 4 • Just-in-Time VM Access

    Configures JIT access to lock management ports and grant time-limited access on demand. Eliminates persistent exposure of RDP and SSH to the internet.

  • Lesson 5 • VM Security Baselines and OS Hardening

    Applies security baselines to Windows and Linux VMs using Azure Policy and guest configuration. Reduces attack surface by disabling unnecessary services and enforcing secure settings.

  • Lesson 6 • Patch Management and Update Automation

    Implements Azure Update Manager to schedule and enforce OS and application patches. Ensures VMs remain compliant with vulnerability remediation timelines.

Chapter 4See details

Container and Serverless Compute Security

  • Lesson 1 • Runtime Threat Detection for Containers

    Enables Defender for Containers runtime protection to detect anomalous behavior inside running pods. Connects runtime alerts to incident response workflows.

  • Lesson 2 • Azure Functions Security Controls

    Applies authentication, managed identities, and network restrictions to Azure Functions. Eliminates credential exposure and limits function invocation to authorized callers.

  • Lesson 3 • Container Image Security and Scanning

    Uses Microsoft Defender for Containers and Azure Container Registry to scan images for vulnerabilities. Prevents deployment of images with known critical vulnerabilities.

  • Lesson 4 • Supply Chain Security for Compute Workloads

    Addresses software supply chain risks through signed artifacts, dependency scanning, and CI/CD pipeline controls. Ensures only verified code reaches production compute environments.

  • Lesson 5 • AKS Cluster Security Configuration

    Hardens AKS clusters through RBAC, network policies, and private cluster configuration. Reduces the blast radius of compromised workloads within the cluster.

Chapter 5See details

Azure Network Security for Compute Workloads

  • Lesson 1 • DDoS Protection and Traffic Filtering

    Configures Azure DDoS Protection plans and rate-limiting policies to absorb volumetric attacks. Ensures compute availability during large-scale network-layer attacks.

  • Lesson 2 • Private Endpoints and Service Isolation

    Removes public internet exposure from Azure services by routing traffic through private endpoints. Applies to storage, databases, and compute management planes covered in later chapters.

  • Lesson 3 • Virtual Network Design for Security

    Structures VNets with subnets, peering, and hub-spoke topology to enforce traffic segmentation. Provides the network foundation that all subsequent security controls depend on.

  • Lesson 4 • Azure Firewall and Web Application Firewall

    Deploys Azure Firewall and WAF policies to inspect and filter east-west and north-south traffic. Protects compute workloads from external attacks and internal lateral movement.

  • Lesson 5 • Network Monitoring and Threat Detection

    Uses Network Watcher, NSG flow logs, and Azure Sentinel to detect anomalous network behavior. Closes the visibility gap between network configuration and active threat detection.

Chapter 6See details

Azure Storage Security

  • Lesson 1 • Encryption at Rest and in Transit

    Applies Microsoft-managed and customer-managed keys for storage encryption and enforces TLS for data in transit. Ensures data confidentiality regardless of physical media access.

  • Lesson 2 • Threat Detection and Anomaly Monitoring

    Enables Defender for Storage to detect suspicious access patterns, malware uploads, and data exfiltration. Integrates storage alerts with centralized SIEM for incident response.

  • Lesson 3 • Network Controls for Storage Accounts

    Restricts storage account access to specific VNets, IP ranges, and private endpoints. Eliminates public internet exposure for sensitive data stores.

  • Lesson 4 • Blob Storage Security Features

    Uses immutability policies, soft delete, and versioning to protect blob data from deletion and tampering. Addresses ransomware resilience and accidental data loss scenarios.

  • Lesson 5 • Storage Account Access Control

    Configures shared access signatures, storage RBAC, and access key management to control who can read or write data. Replaces insecure key-based access with identity-based authorization.

Chapter 7See details

Azure Database Security

  • Lesson 1 • SQL Auditing and Advanced Threat Protection

    Enables SQL auditing to log all database activity and Defender for SQL to detect injection and anomalous queries. Provides the audit trail required for compliance and forensic investigation.

  • Lesson 2 • Cosmos DB and Managed Database Security

    Applies network isolation, RBAC, and encryption controls to Cosmos DB and other managed database services. Extends database security principles to NoSQL and multi-model data stores.

  • Lesson 3 • Data Masking and Row-Level Security

    Uses dynamic data masking to obscure sensitive columns for non-privileged users and row-level security to filter result sets. Reduces data exposure without changing application queries.

  • Lesson 4 • Transparent Data Encryption and Always Encrypted

    Applies TDE for data-at-rest protection and Always Encrypted for column-level client-side encryption. Protects sensitive fields even from database administrators.

  • Lesson 5 • Azure SQL Database Access Control

    Configures Azure AD authentication, contained database users, and server-level firewall rules for Azure SQL. Eliminates SQL authentication weaknesses by enforcing identity-based access.

Chapter 8See details

Security Monitoring, Incident Response, and Governance

  • Lesson 1 • Centralized Logging with Azure Monitor

    Consolidates diagnostic logs, activity logs, and metrics from all Azure services into Log Analytics workspaces. Provides the data foundation for threat detection and compliance reporting.

  • Lesson 2 • Security Posture Management and Reporting

    Uses Defender for Cloud secure score, regulatory compliance dashboards, and custom workbooks to track posture over time. Produces executive and technical reports that drive remediation prioritization.

  • Lesson 3 • Incident Response Playbooks and Automation

    Builds Logic App playbooks to automate containment and notification actions triggered by Sentinel incidents. Reduces mean time to respond by eliminating manual steps in common scenarios.

  • Lesson 4 • Microsoft Sentinel SIEM Configuration

    Deploys Microsoft Sentinel with data connectors, analytics rules, and workbooks for Azure-native threat detection. Enables automated triage and investigation of security incidents.

  • Lesson 5 • Threat Detection Rules and Alert Tuning

    Creates and tunes KQL-based detection rules to reduce false positives while catching real threats. Applies threat intelligence feeds to enrich alerts with attacker context.

Certification

Your valid completion certificate

This course is for you:

  • Cloud engineers ready to specialize in Azure security and governance.

  • IT administrators transitioning from on-premises infrastructure to Azure environments.

  • DevOps engineers who need to embed security practices into their deployment workflows.

  • Security analysts expanding their skills into cloud-native threat detection and response.

  • Solutions architects designing secure, compliant Azure environments for enterprise clients.

  • Career changers with general IT backgrounds aiming for cloud security roles.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the presentation style and video transcription, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQ

Who is Dedika?

Is the certificate valid in United States?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course