
Azure Compute, Storage, and Database Security Course
Lock down every layer of your Azure environment — from virtual machines and containers to blob storage and SQL databases. This course delivers hands-on security skills across compute, storage, and database services, grounded in real-world Azure architecture. Master RBAC, threat detection, encryption, and compliance automation to protect cloud workloads at enterprise scale.
What you will learn:
Configure role-based access control and least-privilege policies across Azure subscriptions and resources.
Secure Azure virtual machines using OS hardening, just-in-time access, and endpoint protection tools.
Protect blob, file, and queue storage with encryption, immutability policies, and network restrictions.
Implement Azure SQL and Cosmos DB defenses including auditing, data masking, and threat detection.
Deploy Microsoft Sentinel with analytics rules and Logic App playbooks for automated incident response.
Apply Zero Trust principles and DevSecOps practices to harden CI/CD pipelines and cloud architectures.
How you study in practice Azure Compute, Storage, and Database Security Course
How you practice Azure Compute, Storage, and Database Security Course
For companies looking to train their teams
With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.
Course Content
8 Chapters • 41 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsAzure Security Foundations and Architecture
Azure Security Foundations and Architecture
Lesson 1 • Azure Security Center and Defender Overview
Introduces Microsoft Defender for Cloud as the unified security posture management tool. Students understand how to read secure scores and prioritize recommendations.
Lesson 2 • Regulatory and Compliance Frameworks in Azure
Maps common industry compliance requirements to Azure built-in policy initiatives and compliance dashboards. Prepares students to align technical controls with audit expectations.
Lesson 3 • Cloud Security Shared Responsibility Model
Defines which security obligations belong to Microsoft versus the customer across service tiers. Anchors all subsequent chapters by clarifying accountability boundaries.
Lesson 4 • Azure Global Infrastructure Overview
Covers regions, availability zones, and data residency concepts that affect security design. Connects physical infrastructure choices to compliance and resilience outcomes.
Lesson 5 • Azure Identity and Access Fundamentals
Introduces Azure Active Directory, tenants, and identity-based access as the security perimeter. Provides the identity foundation required for all resource-level security chapters.
Chapter 2HideHide detailsSee detailsAzure Role-Based Access Control and Policies
Azure Role-Based Access Control and Policies
Lesson 1 • Designing Least-Privilege Access Models
Applies RBAC principles to minimize standing permissions and reduce attack surface. Students practice scoping roles to specific resource groups and service types.
Lesson 2 • Management Groups and Subscription Governance
Organizes subscriptions into hierarchies to apply policies and RBAC at enterprise scale. Students design governance structures that enforce security baselines across business units.
Lesson 3 • RBAC Core Concepts and Roles
Explains role definitions, assignments, and scope hierarchy across management groups, subscriptions, and resources. Establishes the permission model used throughout all service-specific chapters.
Lesson 4 • Azure Policy for Governance and Compliance
Covers policy definitions, initiatives, and enforcement modes to prevent non-compliant resource configurations. Enables automated guardrails that complement RBAC permissions.
Lesson 5 • Custom Role Definitions and Assignments
Guides creation of custom roles when built-in roles are too permissive or too restrictive. Connects to real-world scenarios where fine-grained control is required.
Chapter 3HideHide detailsSee detailsAzure Virtual Machine and Compute Security
Azure Virtual Machine and Compute Security
Lesson 1 • Disk Encryption and Secure Boot
Applies Azure Disk Encryption and Trusted Launch to protect data at rest and firmware integrity. Covers key management integration with Azure Key Vault for encryption keys.
Lesson 2 • Endpoint Protection and Antimalware
Deploys Microsoft Antimalware and Defender for Endpoint on Azure VMs to detect and respond to threats. Integrates endpoint telemetry with Defender for Cloud alerts.
Lesson 3 • VM Network Isolation and Security Groups
Uses network security groups, application security groups, and Azure Bastion to isolate VMs. Prevents lateral movement by enforcing traffic rules at the NIC and subnet levels.
Lesson 4 • Just-in-Time VM Access
Configures JIT access to lock management ports and grant time-limited access on demand. Eliminates persistent exposure of RDP and SSH to the internet.
Lesson 5 • VM Security Baselines and OS Hardening
Applies security baselines to Windows and Linux VMs using Azure Policy and guest configuration. Reduces attack surface by disabling unnecessary services and enforcing secure settings.
Lesson 6 • Patch Management and Update Automation
Implements Azure Update Manager to schedule and enforce OS and application patches. Ensures VMs remain compliant with vulnerability remediation timelines.
Chapter 4HideHide detailsSee detailsContainer and Serverless Compute Security
Container and Serverless Compute Security
Lesson 1 • Runtime Threat Detection for Containers
Enables Defender for Containers runtime protection to detect anomalous behavior inside running pods. Connects runtime alerts to incident response workflows.
Lesson 2 • Azure Functions Security Controls
Applies authentication, managed identities, and network restrictions to Azure Functions. Eliminates credential exposure and limits function invocation to authorized callers.
Lesson 3 • Container Image Security and Scanning
Uses Microsoft Defender for Containers and Azure Container Registry to scan images for vulnerabilities. Prevents deployment of images with known critical vulnerabilities.
Lesson 4 • Supply Chain Security for Compute Workloads
Addresses software supply chain risks through signed artifacts, dependency scanning, and CI/CD pipeline controls. Ensures only verified code reaches production compute environments.
Lesson 5 • AKS Cluster Security Configuration
Hardens AKS clusters through RBAC, network policies, and private cluster configuration. Reduces the blast radius of compromised workloads within the cluster.
Chapter 5HideHide detailsSee detailsAzure Network Security for Compute Workloads
Azure Network Security for Compute Workloads
Lesson 1 • DDoS Protection and Traffic Filtering
Configures Azure DDoS Protection plans and rate-limiting policies to absorb volumetric attacks. Ensures compute availability during large-scale network-layer attacks.
Lesson 2 • Private Endpoints and Service Isolation
Removes public internet exposure from Azure services by routing traffic through private endpoints. Applies to storage, databases, and compute management planes covered in later chapters.
Lesson 3 • Virtual Network Design for Security
Structures VNets with subnets, peering, and hub-spoke topology to enforce traffic segmentation. Provides the network foundation that all subsequent security controls depend on.
Lesson 4 • Azure Firewall and Web Application Firewall
Deploys Azure Firewall and WAF policies to inspect and filter east-west and north-south traffic. Protects compute workloads from external attacks and internal lateral movement.
Lesson 5 • Network Monitoring and Threat Detection
Uses Network Watcher, NSG flow logs, and Azure Sentinel to detect anomalous network behavior. Closes the visibility gap between network configuration and active threat detection.
Chapter 6HideHide detailsSee detailsAzure Storage Security
Azure Storage Security
Lesson 1 • Encryption at Rest and in Transit
Applies Microsoft-managed and customer-managed keys for storage encryption and enforces TLS for data in transit. Ensures data confidentiality regardless of physical media access.
Lesson 2 • Threat Detection and Anomaly Monitoring
Enables Defender for Storage to detect suspicious access patterns, malware uploads, and data exfiltration. Integrates storage alerts with centralized SIEM for incident response.
Lesson 3 • Network Controls for Storage Accounts
Restricts storage account access to specific VNets, IP ranges, and private endpoints. Eliminates public internet exposure for sensitive data stores.
Lesson 4 • Blob Storage Security Features
Uses immutability policies, soft delete, and versioning to protect blob data from deletion and tampering. Addresses ransomware resilience and accidental data loss scenarios.
Lesson 5 • Storage Account Access Control
Configures shared access signatures, storage RBAC, and access key management to control who can read or write data. Replaces insecure key-based access with identity-based authorization.
Chapter 7HideHide detailsSee detailsAzure Database Security
Azure Database Security
Lesson 1 • SQL Auditing and Advanced Threat Protection
Enables SQL auditing to log all database activity and Defender for SQL to detect injection and anomalous queries. Provides the audit trail required for compliance and forensic investigation.
Lesson 2 • Cosmos DB and Managed Database Security
Applies network isolation, RBAC, and encryption controls to Cosmos DB and other managed database services. Extends database security principles to NoSQL and multi-model data stores.
Lesson 3 • Data Masking and Row-Level Security
Uses dynamic data masking to obscure sensitive columns for non-privileged users and row-level security to filter result sets. Reduces data exposure without changing application queries.
Lesson 4 • Transparent Data Encryption and Always Encrypted
Applies TDE for data-at-rest protection and Always Encrypted for column-level client-side encryption. Protects sensitive fields even from database administrators.
Lesson 5 • Azure SQL Database Access Control
Configures Azure AD authentication, contained database users, and server-level firewall rules for Azure SQL. Eliminates SQL authentication weaknesses by enforcing identity-based access.
Chapter 8HideHide detailsSee detailsSecurity Monitoring, Incident Response, and Governance
Security Monitoring, Incident Response, and Governance
Lesson 1 • Centralized Logging with Azure Monitor
Consolidates diagnostic logs, activity logs, and metrics from all Azure services into Log Analytics workspaces. Provides the data foundation for threat detection and compliance reporting.
Lesson 2 • Security Posture Management and Reporting
Uses Defender for Cloud secure score, regulatory compliance dashboards, and custom workbooks to track posture over time. Produces executive and technical reports that drive remediation prioritization.
Lesson 3 • Incident Response Playbooks and Automation
Builds Logic App playbooks to automate containment and notification actions triggered by Sentinel incidents. Reduces mean time to respond by eliminating manual steps in common scenarios.
Lesson 4 • Microsoft Sentinel SIEM Configuration
Deploys Microsoft Sentinel with data connectors, analytics rules, and workbooks for Azure-native threat detection. Enables automated triage and investigation of security incidents.
Lesson 5 • Threat Detection Rules and Alert Tuning
Creates and tunes KQL-based detection rules to reduce false positives while catching real threats. Applies threat intelligence feeds to enrich alerts with attacker context.
Your valid completion certificate
This course is for you:
Cloud engineers ready to specialize in Azure security and governance.
IT administrators transitioning from on-premises infrastructure to Azure environments.
DevOps engineers who need to embed security practices into their deployment workflows.
Security analysts expanding their skills into cloud-native threat detection and response.
Solutions architects designing secure, compliant Azure environments for enterprise clients.
Career changers with general IT backgrounds aiming for cloud security roles.
What our students say
Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.

I like the content and the presentation style and video transcription, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top trainings
FAQ
Who is Dedika?
Is the certificate valid in United States?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















