The Azure Security Engineer AZ-500 Specialization prepares you to design, implement, and manage security across Microsoft Azure environments. Across four courses, you'll develop hands-on skills in identity and access management, network security, workload protection, and security monitoring—the core domains covered by the Microsoft AZ-500 certification.
You'll start by securing Azure identities and governance using Microsoft Entra ID, Privileged Identity Management, Conditional Access, hybrid identity, and Azure RBAC. Next, you'll protect Azure network infrastructure using Azure Firewall, DDoS Protection, network security groups, Web Application Firewall, Private Link, and ExpressRoute.
From there, you'll secure compute resources, containers, applications, secrets, storage, and databases using tools including Azure Key Vault, managed identities, Microsoft Defender for Endpoint, and Always Encrypted. In the final course, you'll build security operations skills using Azure Monitor, Microsoft Defender for Cloud, and Microsoft Sentinel—learning to detect threats, investigate incidents, and automate response.
Each course includes demonstrations, assessments, and scenario-based role-play activities that reflect real organizational security requirements.
Who this is for: IT professionals, cloud administrators, and security practitioners who work with Azure and want to build verified, role-level security engineering skills.
Applied Learning Project
Throughout this specialization, you'll apply your skills through scenario-based role-play activities that simulate real security engineering decisions. Projects span all four security domains: designing an identity foundation for a growing organization; defending a public-facing Azure environment from network threats; hardening fleets of virtual machines and securing AKS platforms; centralizing and protecting application secrets; and investigating a suspicious sign-in campaign using Microsoft Sentinel. Each activity puts you in the role of a security engineer making practical decisions for realistic organizational requirements, helping you build a portfolio of applied experience across the Azure security stack.

















