This page lists exercises associated with Microsoft skilling content on Microsoft Learn
Configure Privileged Identity Management
Level: 300 | Duration: 45
Configure PIM-eligible role assignments, activation settings, and approval workflows to enforce just-in-time privileged access to Microsoft Entra roles.
Deploy and Secure Azure Key Vault
Level: 300 | Duration: 60
Deploy an Azure Key Vault using the RBAC authorization model, configure role assignments for an App Service managed identity and a test user, store secrets and cryptographic keys, retrieve a secret using the App Service managed identity token endpoint, apply network firewall rules, and enable the Defender for Key Vault protection plan.
Configure Azure Policy and Role-Based Access Control
Level: 300 | Duration: 60
Assign a built-in Azure Policy and verify compliance evaluation, deploy a custom tag-enforcement policy via Bicep using Cloud Shell, create a custom Azure role with scoped permissions, evaluate and remediate an overprivileged role assignment using an Entra ID Access Review, and protect a resource against deletion with a resource lock.
Secure Azure Storage
Level: 300 | Duration: 60
Restrict network access to a pre-provisioned storage account using VNet firewall rules, create a stored access policy and generate a SAS token, verify that the firewall blocks unauthorized access, enable Defender for Storage, and confirm diagnostic logging to a Log Analytics workspace.
Secure Azure SQL Database
Level: 300 | Duration: 60
Harden a pre-provisioned Azure SQL database by replacing SQL authentication with Entra ID group-based authentication, restricting network access via a Private Endpoint, enabling auditing to a Log Analytics workspace, and enabling Defender for Databases.
Configure Network Security Controls
Level: 300 | Duration: 65
Apply NSG rules using Application Security Groups to a workload VM, deploy Azure Firewall with an application rule collection, route spoke traffic through the firewall, configure a Private Endpoint for a storage account, and validate the configuration using Network Watcher IP flow verify.
Configure AI Gateway and Foundry Security Controls
Level: 300 | Duration: 60
Configure token rate limiting and subscription key authentication in Azure API Management in front of a pre-provisioned Azure AI Foundry model endpoint, create a content safety guardrail with Prompt Shield in Azure AI Foundry, apply it to the deployed model, and enable Defender for AI Services in Microsoft Defender for Cloud.
Monitor AI Security with Defender for Cloud
Level: 300 | Duration: 15
Use a guided review of the Microsoft Defender for Cloud Data and AI security dashboard to understand AI workload protection, findings, and recommendations, and optionally examine live results when Defender data is available.
Secure Container Workloads with AKS and Defender for Containers
Level: 300 | Duration: 45
Enable Defender for Containers on a pre-provisioned AKS cluster, verify container and registry monitoring, and remediate access and network security gaps in Azure Container Registry.
Secure Azure App Services and API Management
Level: 300 | Duration: 60
Use WAF detection and prevention controls, configure Microsoft Entra authentication and network restrictions for app services, and enforce API subscription key protection in API Management.
Explore Defender for Cloud Security Posture and CSPM
Level: 300 | Duration: 75
Use a guided review of Defender CSPM posture, compliance, secret scanning, attack paths, and governance workflows, and optionally examine live results when asynchronous posture data is available.
Enforce MFA with Conditional Access
Level: 300 | Duration: 45
Create a Conditional Access policy that enforces MFA for a named user accessing the Azure portal, validate the policy in Report-only mode using the What If tool, test MFA enforcement at sign-in, and register an application in Entra ID with scoped API permissions.
Identify AI Data Risks with Microsoft Purview
Level: 300 | Duration: 45
Navigate the Microsoft Purview DSPM for AI (classic) dashboard to identify SharePoint oversharing risks, unlabeled sensitive data accessible to Copilot, and Copilot interaction signals for a pre-seeded site.
Secure Microsoft Entra Agent Identities
Level: 300 | Duration: 60
Locate a pre-provisioned Copilot Studio agent identity in Microsoft Entra ID, create Conditional Access policies scoped to agent identities and agent user accounts, analyze blast radius in Microsoft Defender XDR, manage the agent in the Microsoft 365 admin center, and enable real-time protection in Copilot Studio.
Configure Microsoft Sentinel Data Collection and Automation
Level: 300 | Duration: 45
Connect Microsoft Defender XDR and Azure Activity data into Sentinel, verify ingestion, and configure automation rules that trigger a pre-built playbook.
Configure and Use Microsoft Security Copilot
Level: 300 | Duration: 45
Provision Security Copilot capacity, configure workspace settings and roles, enable core Microsoft security plugins, review agent capabilities, and run grounded security prompts.