Training plan
Module 1: Protect Microsoft Foundry solutions by using Microsoft Defender for Cloud
- Understand how Microsoft Defender for Cloud supports AI security and governance in Azure
- Protect AI workloads with Microsoft Defender for Cloud
- Configure and manage guardrails in Microsoft Foundry
- Secure Microsoft Foundry environments
Module 2: Secure AI identity infrastructure with Microsoft Entra
- Understand identity architecture for AI workloads
- Implement access management for Azure resources
- Plan, implement, and administer Conditional Access
- Manage Microsoft Entra Identity Protection
Recommended prerequisite knowledge
- Understanding the fundamentals of Microsoft Azure
- Knowledge of cloud-native security concepts (security posture, workload protection)
- Basic knowledge of Identity and Access Management (IAM), ideally with Microsoft Entra
- Familiarity with Microsoft Defender for Cloud (or equivalent CSPM/CWPP principles)
- General understanding of AI workloads in the cloud (authentication, trust boundaries, service integrations)
Eccentrix Corner Articles: Resources Securing AI solutions in the cloud using Microsoft Defender for Cloud and Microsoft Entra SC-5009
Delve deeper into the concepts covered in the SC-5009 course with our Eccentrix Corner articles: best practices for securing AI workloads in the cloud, security posture and workload protection with Microsoft Defender for Cloud, and identity and access controls with Microsoft Entra.
AI Security in the Cloud Training
The SC-5009 course provides in-depth mastery of best practices for securing AI solutions in the cloud using Microsoft Defender for Cloud and Microsoft Entra. This course teaches security professionals and cloud teams how to configure AI workloads, apply cloud-native protections, define trust boundaries, and mitigate risk through security posture and workload protection, then enforce these decisions with identity and access controls.
Ideal for cloud security engineers, platform engineers, and application teams working with AI services, this course equips you with practical skills to secure and operate AI environments on Azure, aligning workload protection, governance, and access controls.
Why choose the SC-5009 training course?
AI workloads in the cloud introduce new risks (identity issues, trust boundaries, service exposure, expanded attack surfaces) and demand a cloud-native security approach. Organizations therefore need professionals capable of securing these environments end-to-end by combining security posture, workload protection, and identity and access controls.
This training prepares you to concretely reduce risk by securing AI solutions on Azure with Microsoft Defender for Cloud and Microsoft Foundry, and then reinforcing these decisions with Microsoft Entra (identity and access controls). You will develop a crucial capability: designing consistent protections that can be applied at scale and are aligned with security and governance requirements.
Skills developed during training
Securing AI Workloads in the Cloud
Learn how to configure AI environments on Azure and apply cloud-native protections tailored to AI workloads.Strengthening Security Posture and Reducing Risk
Mastering security posture assessment and improvement to identify gaps, prioritize actions, and reduce exposure.Implementing Workload Protection with Microsoft Defender for Cloud
Discover how to apply workload protection mechanisms to safeguard the services and components used by AI solutions.Understanding AI Workload Authentication and Setting Trust Boundaries
Learn how AI workloads authenticate, how to establish trust boundaries, and how these choices impact overall security.Design and enforce identity and access controls with Microsoft Entra
Implement identity and access management (IAM) controls that explain, complement, and harden cloud/workload security decisions.Operate consistent and defensible protections at scale
Develop a structured approach to deploying, maintaining, and scaling security and governance controls in cloud AI environments.
Instructor-led comprehensive training
This training is led by Microsoft-certified experts who provide hands-on experience and real-world scenarios related to securing AI workloads in the cloud. Participants benefit from interactive exercises to apply concepts of security posture, workload protection with Microsoft Defender for Cloud (and Microsoft Foundry), and identity and access controls with Microsoft Entra, preparing them to address concrete security challenges in Azure environments.
Laboratory environment (overview)
You will practice in a structured lab environment with guided steps to validate your progress throughout the exercises. Depending on the lab, it is usually possible to save your progress and resume the steps later, making it easier to practice between sessions.
To ensure a complete experience, a Microsoft 365/Azure tenant environment may be provided to access the features required for the course scenarios (depending on the module requirements and lab conditions).
After the training, access to the lab remains available for a defined period. Tenant access may be time-limited, while access to the virtual machines and guided steps remains available for up to 180 days.
The screenshots above are provided as examples and may vary depending on the lab version and updates.
Who is this training for?
This training is ideal for:
- Cloud security engineers responsible for securing and operating AI workloads on Azure
- Platform engineers and infrastructure teams deploying AI environments and needing to apply cloud-native protections at scale
- Application teams integrating AI services and wanting to understand workload authentication, trust boundaries, and access controls
- Security/IAM administrators looking to strengthen governance and identity and access controls with Microsoft Entra
- Organizations that want to reduce the risk associated with AI solutions by combining security posture, workload protection, and identity controls
Secure your AI solutions in the cloud with SC-5009
The Securing AI Solutions in the Cloud (SC-5009) course provides you with the essential skills to protect AI workloads on Azure by applying cloud-native protections, improving security posture, and strengthening workload protection with Microsoft Defender for Cloud and Microsoft Foundry. You will also learn how to extend these protections with Microsoft Entra to design and enforce consistent and durable identity and access controls.
Frequently asked questions
Who is the SC-5009 training course intended for?
It is aimed at professionals who design, secure or operate AI workloads in the cloud: cloud security engineers, platform engineers, application/DevOps teams, and IAM specialists who need to strengthen identity and access controls.
What prerequisites are required before taking SC-5009?
An understanding of Azure basics, cloud-native security concepts (posture/protection), and IAM fundamentals. Familiarity with Microsoft Defender for Cloud and Microsoft Entra is a plus.
What exactly will I learn during the training?
You will learn how to secure AI solutions by configuring AI workloads, applying cloud-native protections, setting trust boundaries, and then reinforcing these decisions with identity and access controls via Microsoft Entra.
Is the training practice-oriented?
Yes. The training is structured around concrete scenarios and guided exercises to apply the concepts of security posture, workload protection and IAM in contexts close to production.
Is this an “AI” training course or a “security” training course?
This is primarily a security training course focused on AI workloads in the cloud: the goal is to reduce risk and make AI solutions deployed on Azure safer and more governed.
Which Microsoft tools are covered?
The course primarily relies on Microsoft Defender for Cloud, Microsoft Foundry, and Microsoft Entra to secure AI workloads, strengthen posture, and enforce identity and access controls.
How is SC-5009 different from a SOC/SIEM course like Microsoft Sentinel?
SC-5009 focuses on securing AI workloads (posture, protection, identity, trust boundaries). Sentinel training is geared towards SOC detection/response (collection, correlation, detection, investigation, automation).
How much time should I allow to become comfortable with the concepts in the course?
If you already have a foundation in Azure and IAM, you’ll be up and running quickly. Otherwise, plan some preparation time to review Azure fundamentals, identity, and cloud-native security concepts.





