Maksuton webinaari:

Viisi yleistä virhettä Copilot-agenttien hallinnassa ja miten vältät ne ti 6.10.2026 klo 10.00-11.00 Ilmoittaudu tästä mukaan! 

SC-500: Implement end-to-end security controls for cloud and AI workloads

Suojaa pilvi- ja AI-ympäristösi päästä päähän – identiteeteistä ja verkoista aina AI-agentteihin, dataan ja tietoturvan jatkuvaan valvontaan

kesto 4 pv

1890 + ALV
  • Kurssimuoto: Luokka, Etä

Pilviympäristöjen, hybridiratkaisujen ja tekoälypalveluiden yleistyessä myös tietoturvan hallinta muuttuu entistä monipuolisemmaksi. Tässä käytännönläheisessä koulutuksessa opit toteuttamaan kattavia tietoturvaratkaisuja Microsoft Azure- ja Microsoft 365 -ympäristöissä sekä suojaamaan nykyaikaisia AI-työkuormia ja -agentteja.

Koulutuksessa opit suojaamaan identiteettejä, käyttöoikeuksia, salausavaimia, tallennusta, tietokantoja, verkkoja ja laskentaympäristöjä. Keskeisessä roolissa ovat Microsoft Entra ID, Azure Key Vault, Azure Policy, RBAC, Microsoft Defender for Cloud sekä erilaiset verkon suojausratkaisut.

Perehdyt myös AI-ratkaisujen tietoturvaan. Opit tunnistamaan AI-työkuormien ja -agenttien identiteetti- ja tietoturvariskejä sekä hyödyntämään muun muassa Microsoft Entra Agent ID:tä, Microsoft Purview’ta, Microsoft Foundrya, Azure API Managementia ja Microsoft Defender for Cloudia AI-ratkaisujen suojaamisessa.

Lisäksi opit hallitsemaan Microsoft Sentinel -ympäristöjä ja niiden tapahtumien keräämistä sekä hyödyntämään Microsoft Security Copilotia tietoturvan hallinnassa. Koulutuksen käytännön hands-on-harjoitukset auttavat soveltamaan opittuja asioita todellisiin Azure- ja hybridipilviympäristöihin.

Kurssilla työskennellään useiden tietoturvan osa-alueiden parissa, kuten identiteetin, verkkojen, sovellusten, datan, laskennan ja AI-työkuormien suojaamisessa. Osallistujat oppivat myös hallitsemaan ja valvomaan ympäristön tietoturvatilaa Microsoft Defender for Cloudin, Microsoft Sentinel -ratkaisun ja Security Copilotin avulla.

Kohderyhmä

  • Tietoturva-asiantuntijoille 
  • Azure- ja Microsoft 365 -ylläpitäjille, jotka vastaavat ympäristöjen tietoturvasta 
  • Järjestelmä- ja infrastruktuuriasiantuntijoille 
  • Identiteetin- ja käyttöoikeuksien hallinnan asiantuntijoille 
  • Asiantuntijoille, jotka työskentelevät AI-ratkaisujen ja -agenttien tietoturvan parissa 
  • Microsoft Certified: Cloud and AI Security Engineer Associate sertifiointiin valmistautuville. 

Esitietovaatimukset

Koulutus on keskitason koulutus ja edellyttää osallistujalta perustason kokemusta Azure- ja Microsoft 365 -ympäristöistä. Kurssi ei sovellu Azure- tai tietoturvahallinnan perusteiden opiskeluun.

Osallistujalla olisi hyvä olla: 

  • perustason tuntemus Azuresta, mukaan lukien tilaukset, resurssiryhmät, virtuaaliverkot, tallennustilit, virtuaalikoneet ja Azure RBAC 
  • perustiedot Microsoft Entra ID:stä, käyttäjistä, ryhmistä, autentikoinnista, valtuutuksesta, MFA:sta ja Conditional Accessista 
  • yleinen ymmärrys tietoturvan periaatteista, kuten least privilege, Defense in Depth, Zero Trust, salaus ja turvallinen konfigurointi 
  • perustiedot Azure-verkoista, kuten VNetit, subnetit, private endpointit, palomuurit, VPN-yhteydet ja verkkoturvasäännöt 
  • perustason ymmärrys Azure-työkuormista, kuten Storage, SQL-tietokannat, virtuaalikoneet, kontit, App Services ja API:t 
  • kokemusta tai perustuntemusta Microsoftin tietoturvatyökaluista, kuten Defender for Cloud, Microsoft Sentinel, Defender XDR, Microsoft Purview tai Security Copilot 
  • perustason ymmärrys tekoälyn käsitteistä, kuten copilots, agents, prompts, models ja data grounding 
  • kokemusta Azure-portaalin käytöstä ja perusasetusten määrittämisestä. 

Miksi

Kurssi valmentaa sertifiointitestiä Microsoft Certified: Cloud and AI Security Engineer Associate varten. 

Tietoa koulutuksista

Luokkakoulutukset
Corellian koulutustiloissa:
Kalevankatu 9 A, Helsinki

Kiinnostaako asiakaskohtainen toteutus? Meillä onnistuu.

Kurssin olennainen sisältö

Learning Path 1: Secure Access to resources using Microsoft Entra ID 

  • Manage and Implement Authentication Methods in Microsoft Entra ID 
  • Implement and Configure Privileged Identity Management (PIM) 
  • Authenticate your API plugin for declarative agents with secured APIs

Learning Path 2: Secure secrets and keys using Azure Key Vault 

  • Configure and Secure Azure Key Vault 
  • Manage Keys and Secrets in Azure Key Vault 
  • Manage Certificates and Monitor Azure Key Vault 
  • Protect Azure Key Vault with Microsoft Defender for Cloud

Learning Path 3: Implement governance to enforce security and regulatory compliance 

  • Enforce Governance with Azure Policy and Resource Locks 
  • Configure Security Controls and Remediate Recommendations in Defender for Cloud 
  • Evaluate Regulatory Compliance in Defender for Cloud 
  • Manage and Right-Size RBAC Role Assignments for Least Privilege 
  • Protect Backup Data with Azure Backup Security Features 
  • Implement Security Controls in Infrastructure as Code

Learning Path 4: Implement security for storage accounts 

  • Describe Azure storage services 
  • Implement Security and Manage Access for Azure Storage 
  • Configure Network Security for Azure Storage 
  • Implement Microsoft Defender for Storage

Learning Path 5: Implement security for Azure SQL databases 

  • Configure Platform-Level Security for Azure SQL 
  • Configure Auditing for Azure SQL Database and SQL Managed Instance 
  • Implement Microsoft Defender for Databases

Learning Path 6: Implement security for Azure networking 

  • Segment and Isolate Azure Workloads Using Network Security Controls 
  • Centralize and Enforce Traffic Inspection Using Azure Firewall 
  • Secure Remote and Hybrid Connectivity Using VPN Gateways and Microsoft Entra Private Access 
  • Eliminate Public Network Exposure of Azure PaaS Services 

Learning Path 7: Implement security for AI 

  • Secure Access for Microsoft Entra Agent Identity 
  • Analyze AI Identity Risks Using Microsoft Defender XDR 
  • Enable Real-Time Protection for Copilot Studio Agents 
  • Configure AI Gateway Security in Microsoft Foundry 
  • Configure and manage guardrails in Microsoft Foundry 
  • Protect AI workloads with Microsoft Defender for Cloud 
  • Enable Defender for AI Services Workload Protection in Microsoft Defender for Cloud 
  • Manage Agents Using Microsoft Agent 365 
  • Identify AI Data Risks Using Microsoft Purview Data Security Posture Management 

Learning Path 8: Implement security for servers and virtual machines 

  • Implement Disk Encryption for Azure Virtual Machines 
  • Configure Trusted Launch Security Features for Azure Virtual Machines 
  • Plan and Implement Azure Bastion 
  • Manage Security for Arc-Enabled Hybrid Servers 
  • Implement Microsoft Defender for Servers 
  • Enable and Enforce Just-in-Time VM Access 
  • Enforce VM Security Configuration with Azure Machine Configuration 

Learning Path 9: Implement security for application platform services 

  • Detect Container Risks Using Microsoft Defender for Containers 
  • Implement Security Controls for Azure Kubernetes Service 
  • Implement Security Controls for Azure Container Registry, Container Instances, and Container Apps 
  • Implement Security Controls for Azure Function Apps and Logic Apps 
  • Implement Security Controls for Azure App Services and Web Application Firewall 
  • Implement API Backend Security Using Azure API Management 

Learning Path 10: Manage security posture by using Defender for Cloud 

  • Connect Hybrid and multicloud Environments to Microsoft Defender for Cloud 
  • Identify Security Risks by Using Cloud Security Posture Management 
  • Discover Unprotected Assets and Vulnerabilities by Using Microsoft Defender External Attack Surface Management 
  • Evaluate Regulatory Compliance in Defender for Cloud 
  • Enable and Configure Workload Protection Plans in Microsoft Defender for Cloud 
  • Configure Microsoft Defender Vulnerability Management Settings for Azure VMs 

Learning Path 11: Implement activity and event collections in Microsoft Sentinel 

  • Create and manage Microsoft Sentinel workspaces 
  • Manage content in Microsoft Sentinel 
  • Connect Microsoft services to Microsoft Sentinel 
  • Connect syslog data sources to Microsoft Sentinel 
  • Connect Common Event Format logs to Microsoft Sentinel 
  • Connect Windows hosts to Microsoft Sentinel 
  • Implement Automation Rules and Playbooks in Microsoft Sentinel 
  • Manage Data Storage and Query Audit Logs in Microsoft Sentinel 

Learning Path 12: Implement Microsoft Security Copilot 

  • Describe Microsoft Security Copilot 
  • Configure workspaces for Microsoft Security Copilot 
  • Manage Plugins and Agents in Microsoft Security Copilot 

Kurssin kesto

Kesto 4 pv.

Kurssityyppi

Luokka / Etä

Kouluttajat

Arto Roth
Sami Isoaho

Ilmoittaudu kurssille

Oletko kiinnostunut asiakaskohtaisesta toteutuksesta?

Kerro tarpeesi, niin suunnittelemme koulutuksen tarpeisiinne räätälöitynä.