Hands-On Azure Lighthouse with Microsoft Sentinel

所在平台: Udemy

课程主页: https://www.udemy.com/course/hands-on-azure-lighthouse-with-microsoft-sentinel/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:使用 Microsoft Sentinel 的 Azure Lighthouse 实践 课程概述:在多个 Azure 租户中管理安全性可能非常复杂,这需要高效的基于角色的访问控制(RBAC)、无缝的跨租户可见性以及强大的事件响应能力。使用 Microsoft Sentinel 的 Azure Lighthouse 实践是一门全面的课程,旨在为安全运营中心(SOC)分析师、安全工程师和云管理员提供中央监控和保护多租户环境所需的技能。课程涵盖了关键的 SOC 用例,如 RBAC 监控、特权访问管理、安全控制执行和日志收集策略,所有这些对于有效的威胁检测和响应至关重要。学员还将学习安全分析的高级 KQL 查询、日志导出和自动事件处理。 通过利用 Azure Lighthouse,学员将学习如何简化安全操作,提高跨租户的可见性,并实施治理、安全监控和合规执行的最佳实践。 学习内容: - Azure Lighthouse 基础:了解服务提供商与客户角色以及安全的跨租户操作。 - 在租户间部署 Microsoft Sentinel:使用 Azure Lighthouse 配置集中安全监控。 - RBAC 和特权访问监控:跟踪全局管理员活动、角色分配和特权身份访问。 - 安全用例与控制:监控 NSG 变化、密钥保管库访问、基因组存储安全和 HSM 导出。 - 事件响应与威胁检测:调查跨租户的警报、审计敏感操作,并自动化修复。 - 安全分析的高级 KQL:查询日志以检测恶意活动、异常和政策违规。 - 跨租户日志收集与 SIEM 优化:集中日志以进行威胁情报关联。 - MSSP 与大型企业的最佳实践:利用 Azure Lighthouse 大规模管理安全性。 适合人群: - 需要保护多个 Azure 租户的 SOC 分析师与安全工程师。 - 管理客户环境的托管安全服务提供商(MSSP)。 - 寻求实施集中安全监控的 Azure 管理员与安全专业人员。 - 设计安全多租户架构的云解决方案架构师。 通过参加此实践课程,学员将获得在多个 Azure 环境中部署和管理 Microsoft Sentinel 的实际经验,从而增强可见性、自动化和安全响应能力。立即注册,掌握使用 Azure Lighthouse 和 Microsoft Sentinel 的多租户安全操作!

课程评论(0条)

课程详情

Managing security across multiple Azure tenants can be complex, requiring efficient role-based access control (RBAC), seamless cross-tenant visibility, and robust incident response capabilities. Hands-On Azure Lighthouse with Microsoft Sentinel is a comprehensive course that equips SOC analysts, security engineers, and cloud administrators with the skills to centrally monitor and secure multi-tenant environments using Azure Lighthouse and Microsoft Sentinel.This course covers key SOC use cases such as RBAC monitoring, privileged access management, security control enforcement, and log collection strategies-all critical for effective threat detection and response. You'll also explore advanced KQL queries for security analytics, log exports, and automated incident handling.By leveraging Azure Lighthouse, you'll learn how to streamline security operations, improve visibility across tenants, and implement best practices for governance, security monitoring, and compliance enforcement.What You Will Learn:Azure Lighthouse Fundamentals: Understand service provider vs. customer roles and secure cross-tenant operationsDeploying Microsoft Sentinel Across Tenants: Configure centralized security monitoring using Azure LighthouseRBAC & Privileged Access Monitoring: Track global admin activity, role assignments, and privileged identity accessSecurity Use Cases & Controls: Monitor NSG changes, Key Vault access, Genomics storage security, and HSM exportsIncident Response & Threat Detection: Investigate alerts across tenants, audit sensitive actions, and automate remediationAdvanced KQL for Security Analytics: Query logs for malicious activity, anomaly detection, and policy violationsCross-Tenant Log Collection & SIEM Optimization: Centralize logs for threat intelligence correlationBest Practices for MSSPs & Large Enterprises: Manage security at scale using Azure LighthouseWho Should Take This Course?SOC Analysts & Security Engineers securing multiple Azure tenantsManaged Security Service Providers (MSSPs) managing client environmentsAzure Administrators & Security Professionals looking to implement centralized security monitoring Cloud Solution Architects designing secure multi-tenant architecturesBy the end of this hands-on course, you will have practical experience in deploying and managing Microsoft Sentinel with Azure Lighthouse to enhance visibility, automation, and security response across multiple Azure environments.Enroll today and master multi-tenant security operations with Azure Lighthouse & Microsoft Sentinel!

课程标签

0人关注该课程

主题相关的课程