Course overview
Secure the AI workloads your organization is building. This Express course gives cloud security engineers, platform teams, Microsoft 365 administrators, and AI workload owners a practical model for applying Microsoft Entra, Defender for Cloud, Microsoft Foundry security, Purview, Key Vault, Azure Policy, and agent governance controls to AI and cloud workloads.
A hybrid security architecture course for securing cloud-hosted AI solutions, Microsoft Foundry environments, Microsoft 365 AI agents, and Azure workloads. It emphasizes preventive controls, identity, workload protection, posture, data governance, and architectural review rather than SOC investigation workflows.
Who this is for
Cloud security engineers, security architects, platform engineers, Microsoft 365 administrators, AI workload owners, and security-minded cloud engineers.
Prerequisites
Azure and Microsoft 365 security fundamentals. Familiarity with Microsoft Entra, Azure resources, and cloud security concepts recommended.
Recommended prior course or experience: Azure AI Developer Express or Azure AI Cloud Developer Express for teams securing AI apps; SC-900, AZ-900, AI-900, AZ-500, or SC-500 background helpful.
Course outline
Secure AI and cloud workload landscape
How AI changes cloud security assumptions
Identity, data, model, agent, and network domains
AI apps vs agents vs cloud workloads
Risk-to-control mapping for AI projects
Identity and access controls
Microsoft Entra as the control plane
Conditional Access, groups, and roles
Workload and managed identities
Privileged Identity Management and reviews
Securing Microsoft Foundry and AI workloads
Foundry projects, endpoints, and data connections
Trust boundaries for users, apps, and agents
Securing model, tool, and data access
Prompt injection and data exfiltration risks
Defender for Cloud for AI and cloud workloads
Security posture management and secure score
Recommendations and remediation priority
Workload protection for compute and data
AI workload posture scorecard
Cloud infrastructure security baseline
Secure compute, containers, Functions, and AKS
Storage, database, and network controls
Key Vault, secrets, certificates, and rotation
Azure Policy and compliant-by-default deploys
Data protection and Purview controls
Sensitivity labels, DLP, and retention
Data access boundaries for Copilot and agents
Sensitive sources, vector data, and outputs
Governed data handoff to Fabric Analytics
Microsoft 365 AI agent governance
Agent discovery, inventory, and ownership
Identity and access governance for agents
Protecting data accessed by agents
Monitoring agent threats and anomalies
Security review and exception management
Secure-by-design review gates
Risk acceptance, owner, and expiration
Go-live checklist for AI and cloud workloads
Handoff to SOC and operations teams
Portfolio security workshop
Apply the risk-to-control matrix to a workload
Select controls across Entra, Defender, Purview
Document go/no-go recommendations