Opleiding: Masterclass: Securing the Cloud [SEC]

OVERVIEW

Securing the Cloud is an advanced 5-day, 35-hour course focused on securing Microsoft cloud and hybrid environments. Participants will develop the skills required to monitor, protect, and govern identities, resources, and workloads across Microsoft Entra ID, Azure, and Microsoft 365.

The course combines security best practices from both blue team and red team perspectives with hands-on labs and real-world scenarios. Participants will gain practical experience in threat detection, log analysis, incident response, identity and access management, cloud security, and governance using Microsoft’s cloud security stack, including Defender, Sentinel, and Cloud App Security.

 

Updated August 2026

OBJECTIVES

By the end of the course, participants will be able to:

  • Monitor, protect, and govern identities, resources, and workloads across Microsoft Entra ID, Azure, and Microsoft 365.
  • Detect threats, analyze logs, and respond to security incidents using Microsoft cloud security tools.
  • Apply security best practices to strengthen identity and access controls.
  • Secure cloud resources and implement governance at scale.
  • Investigate security incidents and improve the security posture of cloud and hybrid environments.
  • Apply both blue team and red team approaches to cloud security.

AUDIENCE

- Security architects, Entra ID administrators, security administrators, and security auditors

- Enterprise administrators, infrastructure architects, security professionals, systems engineers, network administrators, IT professionals, and security consultants

CERTIFICATION

Participants receive a CQURE lifelong certification upon completion of the course.

NEXT STEP

None

CONTENT

This Live Virtual Class consists of 6 Modules in terms of Securing the Cloud. They include essential theory combined with individual practice during the exercises as well as loads of hands-on tools and real-case scenarios.

Module 1: Monitoring Operations in Entra ID

1. Entra ID Operations and Logs
2. Entra ID Roles
3. Identity Protection – Roles, Review access, alerts, Discovery and Insights
4. How to deal with Audit Log
5. Challenging Entra ID settings in Azure and Office from red team perspective
6. Privileged Identity Management – JITA, Discover and Monitor
7. Office Management API – Logs around Office 365
8. Microsoft Azure Policies – getting started, compliance, remediation, assignments, blueprints
9. Labs

Module 2: Microsoft 365 Security

1. Secure Score and Security Center
2. Best Practices for Improving Your
3. Secure Score
4. Azure Defender for Servers
5. Security Benchmark Policy
6. Labs
7. STIG & CIS – cloud security baseline

Module 3: Secure Resources and Identities in Azure

1. Secure identity and access (PIM, Identity Protection)
2. Secure Networking (NSG, Azure Firewall, APIM)
3. Secure Compute
4. Secure Storage
5. Secure Databases
6. Defender for Cloud
7. Labs

Module 4: Governance in Azure

1. Security Baseline
2. Azure Policy
3. Azure Role-Based Access Control (RBAC)
4. Management Groups
5. Resource Graph
6. Tagging in Azure
7. Labs

Module 5: Extended Detection and Response with Sentinel

1. Sentinel 101 – Azure Sentinel Dashboards, Connectors
2. Understanding Normalization in Azure Sentinel
3. Cloud & on-prem architecture
4. Workbooks deep dive – Visualize your security threats and hunts
5. Incidents
6. KQL intro (KQL hands-on lab exercises) and Optimizing Azure Sentinel KQL queries performance
7. Auditing and monitoring your Azure Sentinel workspace
8. Sentinel configuration with Microsoft Cloud stack and MCAS
9. Streamlining your SOC Workflow with Automated Notebooks
10. Customizing Azure Sentinel with Python
11. Best Practices for Converting Detection Rules from Splunk, QRadar, and ArcSight to Azure Sentinel Rules
12. Deep Dive into Azure Sentinel Innovations
13. Investigating Azure Security Center alerts using Azure Sentinel
14. Customizable Anomalies and How to Use Them
15. Introduction to Monitoring GitHub with Azure Sentinel for Security Professionals
16. Hunting in Sentinel
17. Deep Dive on Threat Intelligence
18. End-to-End SOC scenario with Sentinel

Module 6: Microsoft Cloud App Security

1. Intro do MCAS
2. Enabling Secure Remote Work
3. App Discovery and Log Collector Configuration
4. Extending real-time monitoring & controls to any app
5. Connecting 3rd party Applications
6. Automation and integration with Microsoft Flow
7. Conditional Access App Control
8. Threat detection
9. Information Protection
10. Labs: Protect Your Environment Using MCAS
11. DLP in Microsoft stack – how to deploy and monitor using MCAS and Sentinel

Meer...
€3.500
ex. BTW
Aangeboden door
Global Knowledge Network Netherlands B.V.
Onderwerp
Cloud Computing
Niveau
Looptijd
5 dagen
Taal
nl
Type product
cursus
Lesvorm
Klassikaal
Aantal deelnemers
Max: 16
Tijdstip
Overdag
Tijden en locaties
CQure Virtual English
ma 12 okt. 2026
CQure Virtual English
ma 7 dec. 2026
Keurmerken aanbieder
Cedeo
CRKBO en BTW-vrijstelling
VOI
EXIN
ISO register
Microsoft Learning Partner
VMWare Partner
Oracle Education Partner
AgilePM - Agile Project Management (APMG)
ASL