Catalog

Microsoft Cybersecurity Architect

$2236.00

Course ID: CS-10078

Duration (Days): 4.0



Please contact us for additional details and scheduling options.

Contact Us
This course equips experienced cloud security engineers with the skills to design and evaluate cybersecurity strategies across key areas such as Zero Trust, Governance Risk Compliance (GRC), security operations (SecOps), and data and applications. Participants will learn to architect solutions using Zero Trust principles and specify security requirements for cloud infrastructure in various service models (SaaS, PaaS, IaaS). This course is ideal for those with advanced experience in cloud security, including hybrid and cloud implementations.
This course is designed for experienced cloud security engineers who seek to deepen their expertise in designing and evaluating cybersecurity strategies. Students will explore key areas such as Zero Trust, Governance Risk Compliance (GRC), security operations (SecOps), and securing data and applications. The course emphasizes the application of Zero Trust principles and provides a comprehensive understanding of how to architect solutions tailored to cloud infrastructure across different service models (SaaS, PaaS, IaaS). Participants will also gain insights into designing security solutions that align with industry best practices, including the Cloud Adoption Framework (CAF), Well-Architected Framework (WAF), and Microsoft Cybersecurity Reference Architecture (MCRA). Through case studies and practical exercises, students will learn to address regulatory compliance, manage identity and access, secure privileged access, and enhance security operations. This course is ideal for professionals with a strong background in security engineering, particularly those with experience in hybrid and cloud environments, aiming to advance their capabilities in delivering robust security solutions.

Course Outline

##### Module 1 - Introduction to Zero Trust and Best Practice Frameworks - Zero Trust initiatives - Zero Trust technology pillars part 1 - Zero Trust technology pillars part 2 ##### Module 2 - Design Solutions that Align with the Cloud Adoption Framework (CAF) and Well-Architected Framework (WAF) - Define a security strategy - Cloud Adoption Framework secure methodology - Design security with Azure Landing Zones - The Well-Architected Framework security pillar ##### Module 3 - Design Solutions that Align with the Microsoft Cybersecurity Reference Architecture (MCRA) and Microsoft Cloud Security Benchmark (MCSB) - Design solutions with best practices for capabilities and controls - Design solutions with best practices for attack protection ##### Module 4 - Design a Resiliency Strategy for Common Cyberthreats like Ransomware - Common cyberthreats and attack patterns - Support business resiliency - Ransomware protection - Configurations for secure backup and restore - Security updates ##### Module 5 - Case Study: Design Solutions that Align with Security Best Practices and Priorities - Case study description - Case study answers - Conceptual walkthrough - Technical walkthrough ##### Module 6 - Design Solutions for Regulatory Compliance - Translate compliance requirements into a security solution - Address compliance requirements with Microsoft Purview - Address privacy requirements with Microsoft Priva - Address security and compliance requirements with Azure Policy - Evaluate infrastructure compliance with Defender for Cloud ##### Module 7 - Design Solutions for Identity and Access Management - Design cloud, hybrid, and multicloud access strategies (including Microsoft Entra ID) - Design a solution for external identities - Design modern authentication and authorization strategies - Align conditional access and Zero Trust - Specify requirements to secure Active Directory Domain Services (AD DS) - Design a solution to manage secrets, keys, and certificates ##### Module 8 - Design Solutions for Securing Privileged Access - The enterprise access model - Design identity governance solutions - Design a solution to secure tenant administration - Design a solution for cloud infrastructure entitlement management (CIEM) - Design a solution for privileged access workstations and bastion services ##### Module 9 - Design Solutions for Security Operations - Design security operations capabilities in hybrid and multicloud environments - Design centralized logging and auditing - Design security information and event management (SIEM) solutions - Design solutions for detection and response - Design a solution for security orchestration, automation, and response (SOAR) - Design security workflows - Design threat detection coverage ##### Module 10 - Case Study: Design Security Operations, Identity, and Compliance Capabilities - Case study description - Case study answers - Conceptual walkthrough - Technical walkthrough ##### Module 11 - Design Solutions for Securing Microsoft 365 - Evaluate security posture for collaboration and productivity workloads - Design a Microsoft Defender XDR solution - Design configurations and operational practices for Microsoft 365 ##### Module 12 - Design Solutions for Securing Applications - Design and implement standards to secure application development - Evaluate security posture of existing application portfolios - Evaluate application threats with threat modeling - Design security lifecycle strategy for applications - Secure access for workload identities - Design a solution for API management and security - Design a solution for secure access to applications ##### Module 13 - Design Solutions for Securing an Organization\'s Data - Design a solution for data discovery and classification using Microsoft Purview - Design a solution for data protection - Design data security for Azure workloads - Design security for Azure Storage - Design a security solution with Microsoft Defender for SQL and Microsoft Defender for Storage ##### Module 14 - Case Study: Design Security Solutions for Applications and Data - Case study description - Case study answers - Conceptual walkthrough - Technical walkthrough ##### Module 15 - Specify Requirements for Securing SaaS, PaaS, and IaaS Services - Specify security baselines for SaaS, PaaS, and IaaS services - Specify security requirements for web workloads - Specify security requirements for containers and container orchestration ##### Module 16 - Design Solutions for Security Posture Management in Hybrid and Multicloud Environments - Evaluate security posture by using Microsoft Cloud Security Benchmark - Design integrated posture management and workload protection - Evaluate security posture by using Microsoft Defender for Cloud - Posture evaluation with Microsoft Defender for Cloud Secure Score - Design cloud workload protection with Microsoft Defender for Cloud - Integrate hybrid and multicloud environments with Azure Arc - Design a solution for external attack surface management ##### Module 17 - Design Solutions for Securing Server and Client Endpoints - Specify server security requirements - Specify requirements for mobile devices and clients - Specify Internet of Things (IoT) and embedded device security requirements - Secure operational technology (OT) and industrial control systems (ICS) with Microsoft Defender for IoT - Specify security baselines for server and client endpoints - Design a solution for secure remote access ##### Module 18 - Design Solutions for Network Security - Design solutions for network segmentation - Design solutions for traffic filtering with network security groups - Design solutions for network posture management - Design solutions for network monitoring ##### Module 19 - Case Study: Design Security Solutions for Infrastructure - Case study description - Case study answers - Conceptual walkthrough - Technical walkthrough