Topics
Skill: Implement and Manage User Identities
Part 1: Configure and Manage a Microsoft Entra Tenant
Session 1: Managing Roles and Administrative Units
- Configuring built-in and custom Microsoft Entra roles
- Using and managing administrative units
- Evaluating effective permissions for Microsoft Entra roles
Session 2: Domain and Tenant Configuration
- Configuring and managing domains in Microsoft Entra ID and Microsoft 365
- Setting up company branding and tenant properties
Session 3: User, Group, and Device Management
- Creating and managing users, groups, and custom security attributes
- Automating bulk operations using the admin center and PowerShell
- Managing device join and registration in Microsoft Entra ID
Part 2: Implement and Manage Identities for External Users and Tenants
Session 4: External Collaboration
- Configuring external collaboration settings
- Managing external user accounts and bulk invitations
- Implementing cross-tenant access settings and synchronization
Session 5: External Identity Providers
- Configuring identity providers using SAML and WS-Fed
- Setting up authentication protocols for external users
Part 3: Implement and Manage Hybrid Identity
Session 6: Hybrid Identity Solutions
- Implementing Microsoft Entra Connect Sync and Cloud Sync
- Managing password hash synchronization, pass-through authentication, and seamless SSO
- Migrating from AD FS to modern authentication mechanisms
Session 7: Monitoring and Health Management
- Using Microsoft Entra Connect Health for hybrid environments
Skill: Implement Authentication and Access Management
Part 1: Plan, Implement, and Manage Authentication
Session 8: Authentication Methods
- Implementing certificate-based, temporary access pass, OAuth tokens, Microsoft Authenticator, and FIDO2
- Deploying tenant-wide MFA and self-service password reset (SSPR)
Session 9: Advanced Authentication Features
- Configuring Windows Hello for Business and Microsoft Entra Kerberos authentication
- Managing password protection settings and session management
Part 2: Plan, Implement, and Manage Conditional Access
Session 10: Configuring Conditional Access Policies
- Planning, testing, and troubleshooting Conditional Access policies
- Implementing session management, device-enforced restrictions, and protected actions
Session 11: Continuous Access Evaluation
- Implementing authentication context and evaluating risky users and sign-ins
Part 3: Manage Risk Using Microsoft Entra ID Protection
Session 12: Risk Management
- Monitoring and remediating risky users, sign-ins, and workload identities
- Implementing multifactor authentication registration policies
Part 4: Implement Access Management for Azure Resources
Session 13: Role-Based Access Control (RBAC)
- Creating and managing custom Azure roles and evaluating effective permissions
- Configuring Key Vault RBAC and access policies
Session 14: Global Secure Access
- Deploying Global Secure Access clients, Private Access, and Internet Access
Skill: Plan and Implement Workload Identities
Part 1: Application and Workload Identities
Session 15: Creating Managed Identities
- Assigning managed identities to Azure resources
- Using managed identities to access other Azure resources
Session 16: Enterprise Application Integration
- Configuring settings for enterprise and SaaS applications
- Implementing Microsoft Entra Application Proxy for on-premises apps
Part 2: App Registrations and Monitoring
Session 17: App Registration Management
- Planning and creating app registrations
- Configuring app authentication, API permissions, and roles
Session 18: Monitoring Application Access
- Using Microsoft Defender for Cloud Apps to analyze cloud discovery results
- Configuring Conditional Access app control and session policies
Skill: Plan and Automate Identity Governance
Part 1: Entitlement Management
Session 19: Managing Entitlements
- Planning and implementing catalogs, access packages, and terms of use
- Managing the lifecycle of external users
Session 20: Connected Organizations
- Configuring and managing connected organizations
Part 2: Access Reviews and Privileged Access
Session 21: Managing Access Reviews
- Planning and configuring access reviews
- Monitoring and responding to access review activities
Session 22: Privileged Identity Management (PIM)
- Managing Microsoft Entra and Azure resources in PIM
- Configuring groups managed by PIM and break-glass accounts
Part 3: Identity Monitoring and Reporting
Session 23: Log Analysis and Reporting
- Reviewing sign-in, audit, and provisioning logs
- Configuring diagnostic settings for Log Analytics and reporting using KQL
Session 24: Identity Secure Score
- Monitoring and improving security posture using Identity Secure Score
Part 4: Permissions Management
Session 25: Evaluating and Remediating Risks
- Onboarding Azure subscriptions to Permissions Management
- Remediating risks related to identities, roles, and Permissions Creep Index (PCI)
Session 26: Activity Alerts and Triggers
- Configuring alerts and triggers for Azure subscriptions