SC-500 Labs

Lab exercises for SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads. Includes Applied Skills, Microsoft Learn, and Microsoft GitHub labs.

Configure Privileged Identity ManagementConfigure PIM-eligible role assignments, activation settings, and approval workflows to enforce just-in-time privileged access to Microsoft Entra roles.Deploy and Secure Azure Key VaultDeploy an Azure Key Vault using RBAC, store secrets and keys, and apply network firewall rules and Defender for Key Vault protection.Configure Azure Policy and Role-Based Access ControlAssign Azure Policy, create a custom Azure role, and remediate an overprivileged role assignment using an Entra ID Access Review.Enforce MFA with Conditional AccessCreate a Conditional Access policy that enforces MFA, validate it in Report-only mode, and register an application with scoped API permissions.Secure Azure StorageRestrict network access to a storage account, generate a SAS token, and enable Defender for Storage.Secure Azure SQL DatabaseReplace SQL authentication with Entra ID group-based authentication, restrict access via Private Endpoint, and enable Defender for Databases.Configure Network Security ControlsApply NSG rules with Application Security Groups, deploy Azure Firewall, and validate configuration with Network Watcher.Configure AI Gateway and Foundry Security ControlsConfigure token rate limiting in API Management, create a Prompt Shield content safety guardrail, and enable Defender for AI Services.Monitor AI Security with Defender for CloudReview the Microsoft Defender for Cloud Data and AI security dashboard for AI workload protection findings.Identify AI Data Risks with Microsoft PurviewNavigate the Microsoft Purview DSPM for AI dashboard to identify SharePoint oversharing risks and unlabeled sensitive data.Secure Microsoft Entra Agent IdentitiesCreate Conditional Access policies scoped to agent identities, analyze blast radius in Defender XDR, and enable real-time protection in Copilot Studio.Secure Container Workloads with AKS and Defender for ContainersEnable Defender for Containers on an AKS cluster and remediate access and network security gaps in Azure Container Registry.Secure Azure App Services and API ManagementUse WAF detection controls, configure Microsoft Entra authentication for app services, and enforce API subscription key protection.Explore Defender for Cloud Security Posture and CSPMReview Defender CSPM posture, compliance, secret scanning, attack paths, and governance workflows.Configure Microsoft Sentinel Data Collection and AutomationConnect Microsoft Defender XDR and Azure Activity data into Sentinel and configure automation rules that trigger a playbook.Configure and Use Microsoft Security CopilotProvision Security Copilot capacity, configure roles, enable core security plugins, and run grounded security prompts.