This page lists exercises associated with Microsoft skilling content on Microsoft Learn


Configure Privileged Identity Management

Level: 300 | Duration: 45

Configure PIM-eligible role assignments, activation settings, and approval workflows to enforce just-in-time privileged access to Microsoft Entra roles.


Deploy and Secure Azure Key Vault

Level: 300 | Duration: 60

Deploy an Azure Key Vault using the RBAC authorization model, configure role assignments for an App Service managed identity and a test user, store secrets and cryptographic keys, retrieve a secret using the App Service managed identity token endpoint, apply network firewall rules, and enable the Defender for Key Vault protection plan.


Configure Azure Policy and Role-Based Access Control

Level: 300 | Duration: 60

Assign a built-in Azure Policy and verify compliance evaluation, deploy a custom tag-enforcement policy via Bicep using Cloud Shell, create a custom Azure role with scoped permissions, evaluate and remediate an overprivileged role assignment using an Entra ID Access Review, and protect a resource against deletion with a resource lock.


Secure Azure Storage

Level: 300 | Duration: 60

Restrict network access to a pre-provisioned storage account using VNet firewall rules, create a stored access policy and generate a SAS token, verify that the firewall blocks unauthorized access, enable Defender for Storage, and confirm diagnostic logging to a Log Analytics workspace.


Secure Azure SQL Database

Level: 300 | Duration: 60

Harden a pre-provisioned Azure SQL database by replacing SQL authentication with Entra ID group-based authentication, restricting network access via a Private Endpoint, enabling auditing to a Log Analytics workspace, and enabling Defender for Databases.


Configure Network Security Controls

Level: 300 | Duration: 65

Apply NSG rules using Application Security Groups to a workload VM, deploy Azure Firewall with an application rule collection, route spoke traffic through the firewall, configure a Private Endpoint for a storage account, and validate the configuration using Network Watcher IP flow verify.


Configure AI Gateway and Foundry Security Controls

Level: 300 | Duration: 60

Configure token rate limiting and subscription key authentication in Azure API Management in front of a pre-provisioned Azure AI Foundry model endpoint, create a content safety guardrail with Prompt Shield in Azure AI Foundry, apply it to the deployed model, and enable Defender for AI Services in Microsoft Defender for Cloud.


Monitor AI Security with Defender for Cloud

Level: 300 | Duration: 15

Use a guided review of the Microsoft Defender for Cloud Data and AI security dashboard to understand AI workload protection, findings, and recommendations, and optionally examine live results when Defender data is available.


Secure Container Workloads with AKS and Defender for Containers

Level: 300 | Duration: 45

Enable Defender for Containers on a pre-provisioned AKS cluster, verify container and registry monitoring, and remediate access and network security gaps in Azure Container Registry.


Secure Azure App Services and API Management

Level: 300 | Duration: 60

Use WAF detection and prevention controls, configure Microsoft Entra authentication and network restrictions for app services, and enforce API subscription key protection in API Management.


Explore Defender for Cloud Security Posture and CSPM

Level: 300 | Duration: 75

Use a guided review of Defender CSPM posture, compliance, secret scanning, attack paths, and governance workflows, and optionally examine live results when asynchronous posture data is available.


Enforce MFA with Conditional Access

Level: 300 | Duration: 45

Create a Conditional Access policy that enforces MFA for a named user accessing the Azure portal, validate the policy in Report-only mode using the What If tool, test MFA enforcement at sign-in, and register an application in Entra ID with scoped API permissions.


Identify AI Data Risks with Microsoft Purview

Level: 300 | Duration: 45

Navigate the Microsoft Purview DSPM for AI (classic) dashboard to identify SharePoint oversharing risks, unlabeled sensitive data accessible to Copilot, and Copilot interaction signals for a pre-seeded site.


Secure Microsoft Entra Agent Identities

Level: 300 | Duration: 60

Locate a pre-provisioned Copilot Studio agent identity in Microsoft Entra ID, create Conditional Access policies scoped to agent identities and agent user accounts, analyze blast radius in Microsoft Defender XDR, manage the agent in the Microsoft 365 admin center, and enable real-time protection in Copilot Studio.


Configure Microsoft Sentinel Data Collection and Automation

Level: 300 | Duration: 45

Connect Microsoft Defender XDR and Azure Activity data into Sentinel, verify ingestion, and configure automation rules that trigger a pre-built playbook.


Configure and Use Microsoft Security Copilot

Level: 300 | Duration: 45

Provision Security Copilot capacity, configure workspace settings and roles, enable core Microsoft security plugins, review agent capabilities, and run grounded security prompts.