← All 186 courses
SEC-203 Security

Azure Security Engineering

The Azure security stack in operator depth: Entra ID hardening, Conditional Access, Privileged Identity Management for just-in-time admin, Defender for Cloud posture and workload protection, Key Vault patterns, and network security — with a PIM-governed admin model built live.

B4Professional
6modules
42skill atoms
1role journey
Curriculum

What this course covers.

6 modules, 42 named skill atoms. Expand any module to see them.

1Entra ID Hardening7 skill atoms
Conditional Access designrisky sign-in policylegacy authentication blockingnamed locations & device filtersIdentity Protection risk levelswhat-if policy testingbreak-glass account exclusions
2Privileged Access7 skill atoms
PIMJIT elevationaccess reviewseligible vs active assignmentsapproval & justification workflowsactivation duration tuningGlobal Administrator minimisation
3Defender for Cloud7 skill atoms
secure scoreworkload protectionsalertsDefender plans per resource typeagentless vs agent-based scanningalert routing into Sentinelexemptions & governance rules
4Secrets & Keys7 skill atoms
Key Vault patternsrotationRBAC vs access policiesmanaged identity vault accesssoft delete & purge protectionHSM-backed key tiersprivate endpoint isolation
5Network Security7 skill atoms
NSG/ASG disciplineFirewall integrationPrivate Linkhub-spoke with forced tunnellingUDR & next-hop designservice endpoints vs private endpointsNSG flow log analytics
6Governance Lab7 skill atoms
policy assignmentscompliance dashboardexceptionsdeny vs audit vs deployIfNotExists effectsinitiative design & management group scopingremediation tasksexemption expiry
Where it fits

SEC-203 in a role journey.

This course appears in 1 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

Cloud Security Engineer

Practitioner stage
SEC-202SEC-203SEC-204

Roles this course serves

The capability ladder

This course is authored to band B4.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-203 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free