Secure AI solutions in the cloud by configuring AI workloads, applying cloud-native protections, and reinforcing security outcomes with identity controls. Learn how AI workloads authenticate, how trust boundaries are established, and how security posture and workload protection reduce risk using Microsoft Defender for Cloud and Microsoft Foundry. Extend these protections by using Microsoft Entra to design and apply identity and access controls that explain and harden earlier security decisions. Learning outcomes:
Apply security posture management and workload protection for AI services using Microsoft Defender for Cloud
Configure and secure Microsoft Foundry environments using cloud-native security controls
Design and apply identity and access controls for AI workloads using Microsoft Entra
Course Outline
1 – Understand how Microsoft Defender for Cloud supports AI security and governance in Azure
Understand AI services in Azure
Understand AI security risks in Azure
AI guardrails and protections in Azure
How Azure security and governance tools support AI workloads
Module assessment
2 – Protect AI workloads with Microsoft Defender for Cloud
Enable the AI workloads plan
Review insights in the Data & AI security dashboard
Assess and improve AI security posture with Cloud Security Posture Management (CSPM)
Detect AI threats at runtime with Cloud Workload Protection (CWP)
Investigate AI security alerts with prompt evidence in Microsoft Defender XDR
Module assessment
3 – Configure and manage guardrails in Microsoft Foundry
Understand guardrails and Microsoft Content Safety
Understand safety controls in Microsoft Foundry
Try out built-in guardrails
Create and manage blocklists in Microsoft Foundry
Configure and apply guardrails in Microsoft Foundry
Choose and refine the right guardrails for your AI workloads
Module assessment
4 – Secure Microsoft Foundry environments
Control access to Microsoft Foundry with Microsoft Entra ID
Manage access within Microsoft Foundry projects
Secure Microsoft Foundry secrets with Azure Key Vault (preview)
Isolate networks with managed virtual network and Private Link