|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/sc-300-microsoft-identity-and-access-administrator-y/
课程评论:没有评论
**课程名称:** SC-300: Microsoft Identity and Access Administrator **课程概述:** 本课程旨在系统地教授Azure安全知识,通过深入的实验练习和精心设计的课程内容,帮助学员掌握在企业环境中至关重要的实际技能,为通过Microsoft Azure安全认证打下坚实基础。无论您是想深化云安全专业知识,还是准备考取Azure安全认证,本课程都将一步步指导您。 **学习内容:** * **Azure Active Directory (Azure AD) 初始配置:** * 配置和管理目录角色和自定义域。 * 设置设备注册选项。 * 配置管理单位和租户级设置。 * **身份管理:** * 创建、配置和管理用户及组。 * 管理许可证。 * 配置外部协作和身份提供程序(社交、SAML、WS-Fed)。 * **混合身份和同步:** * 设置和管理Azure AD Connect (AADC)。 * 实现密码哈希同步 (PHS)、直通身份验证 (PTA) 和无缝 SSO。 * 集成和管理Azure AD Connect Health。 * 排查同步问题。 * **多重身份验证 (MFA):** * 规划和实现Azure MFA(不包括旧版MFA Server)。 * 管理用户的MFA设置。 * 配置密码保护和自助密码重置。 * **身份验证和访问控制:** * 配置FIDO2、无密码身份验证和Windows Hello for Business。 * 设置租户限制和智能锁定。 * 规划和实施条件访问策略和会话控件。 * **身份保护:** * 配置和管理用户与登录风险策略。 * 调查和修复高风险用户活动。 * 强制执行MFA注册策略。 * **企业应用程序集成和 SSO:** * 发现和管理企业应用程序。 * 使用Azure AD Application Proxy集成本地应用程序。 * 配置SaaS应用程序的SSO。 * 自定义令牌和管理应用程序预配。 * **应用程序注册和授权:** * 制定业务线应用程序注册策略。 * 配置应用程序权限和授权。 * **权利管理和访问评审:** * 定义目录和访问包。 * 管理外部用户的生命周期。 * 创建和自动化定期访问评审。 * 监控评审结果和许可证使用情况。 * **特权访问管理:** * 定义管理用户的策略。 * 配置和管理Azure AD特权身份管理 (PIM)。 * 分配角色、管理PIM请求和审核日志。 * 设置和维护“紧急访问”账户。 * **监控和集成:** * 使用登录和审核日志进行分析和排查。 * 启用Log Analytics和Azure Sentinel的诊断。 * 将日志导出到第三方SIEM。 * 使用Azure AD Workbooks和警报进行分析(不包括KQL)。 **课程更新说明:** * **更新进度:** 模块3和4正在进行更新,预计于2021年10月20日前完成。 * **全部更新:** 所有模块已于2021年10月28日更新。 * **新增实验活动:** 新增实验活动已于2021年11月29日上传。 * **Azure Sentinel更新:** 最后的模块“Azure Sentinel”已于2022年3月16日更新。
There are no shortcuts to learning Azure Security - and this course is designed to teach it the right way. Through in-depth lab exercises and a carefully structured curriculum, you'll build practical, real-world skills that prepare you for enterprise environments and certification success.Whether you're aiming to deepen your expertise in cloud security or pass a Microsoft Azure security certification, this course will guide you step by step.Course Update NotesNote 1: Course update in progress - Modules 3 and 4 will be updated by October 20th.Note 2: All modules updated - as of October 28th, 2021.Note 3: New lab activities uploaded - November 29th, 2021.Note 4: Azure Sentinel (final module) updated - March 16th, 2022.What You Will LearnInitial Configuration of Azure Active Directory (Azure AD)Configure and manage directory roles and custom domainsSet up device registration optionsConfigure administrative units and tenant-wide settingsIdentity ManagementCreate, configure, and manage users and groupsManage licensesConfigure external collaboration and identity providers (social, SAML, WS-Fed)Hybrid Identity and SynchronizationSet up and manage Azure AD Connect (AADC)Implement Password Hash Sync (PHS), Pass-Through Authentication (PTA), and Seamless SSOIntegrate and manage Azure AD Connect HealthTroubleshoot synchronization issuesMultifactor Authentication (MFA)Plan and implement Azure MFA (excluding legacy MFA Server)Manage MFA settings for usersConfigure password protection and self-service password resetAuthentication and Access ControlsConfigure FIDO2, passwordless, and Windows Hello for BusinessSet tenant restrictions and smart lockoutPlan and implement Conditional Access policies and session controlsIdentity ProtectionConfigure and manage user and sign-in risk policiesInvestigate and remediate risky user activitiesEnforce MFA registration policiesEnterprise Application Integration and SSODiscover and manage enterprise appsIntegrate on-premises applications using Azure AD Application ProxyConfigure SSO for SaaS applicationsCustomize tokens and manage app provisioningApplication Registration and AuthorizationDevelop a line-of-business app registration strategyConfigure application permissions and authorizationEntitlement Management and Access ReviewsDefine catalogs and access packagesManage lifecycle of external usersCreate and automate recurring access reviewsMonitor review findings and license usagePrivileged Access ManagementDefine strategies for managing administrative usersConfigure and manage Azure AD Privileged Identity Management (PIM)Assign roles, manage PIM requests, and review audit logsSet up and maintain break-glass accountsMonitoring and IntegrationAnalyze and troubleshoot using sign-in and audit logsEnable diagnostics with Log Analytics and Azure SentinelExport logs to third-party SIEMsUse Azure AD Workbooks and alerts for analysis (excluding KQL)