Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Microsoft

Infrastructure and Network Protection

Microsoft via Coursera

Overview

Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
This advanced-level course focuses on securing the underlying systems that power the modern enterprise. You'll learn to architect micro-segmented network zones to prevent lateral movement and contain potential breaches. You'll implement host hardening baselines at scale and design secure, scalable foundations for both on-premise fabrics and multi-cloud landing zones, using policy-as-code principles to ensure consistency and automation. You'll also assess GenAI infrastructure risks and design risk-informed architectural safeguards that extend existing enterprise security controls and governance frameworks. This course is for security professionals with familiarity with core networking protocols, foundational cloud architecture principles, and basic experience with infrastructure automation or scripting. By the end of this course, you will be able to architect micro-segmented network zones using east-west firewall policies and TLS encryption to isolate container and Kubernetes workloads; implement host hardening baselines via configuration management to maintain compliance across on-prem hypervisors and storage fabrics; develop cloud landing zones with policy-as-code to enforce least-privilege, encryption, and logging defaults across multi-cloud environments; and assess GenAI infrastructure risks to design architectural safeguards that extend existing enterprise security controls. This course works with tools like Microsoft Defender for Cloud and Azure Firewall. Some Microsoft Defender for Cloud and Azure Firewall capabilities involve usage-based or post-trial costs.

Syllabus

  • Segmentation: Architect Micro-Segmentation
    • Move away from perimeter-only defenses. Learn to design granular network boundaries inside your cloud environment to contain breaches and isolate critical workloads.
  • Segmentation: Harden Hosts at Scale
    • Manual server configuration is insecure and unscalable. Learn to leverage Microsoft Defender for Cloud and Azure Policy to enforce CIS baselines across thousands of machines dynamically.
  • Infra and Landing Zones: Secure On-Prem Fabric
    • Legacy on-premises environments often lack visibility. Learn to use Azure Arc and Defender for Servers to extend modern cloud-native drift detection (File Integrity Monitoring) into on-premises data centers.
  • Infra and Landing Zones: Build Cloud Landing Zones
    • Ensure every new cloud environment is secure by default. Learn to architect Azure Landing Zones utilizing Azure Policy (Policy-as-Code) to establish non-negotiable security guardrails for engineering teams.
  • GenAI Module: GenAI for Infrastructure Security
    • Deploying Generative AI models (like Azure OpenAI) inside an enterprise introduces new infrastructure risks, from data exfiltration to misconfigured network connectivity across VNets and services. In this module, you will evaluate GenAI infrastructure risks and design architectural safeguards like Azure Private Endpoints and strict trust boundaries to ensure AI interoperability without sacrificing network security.
  • Project Module: Secure Infra Design
    • Synthesize your knowledge of micro-segmentation, Policy-as-Code, and secure Landing Zones. You will create a comprehensive High-Level infrastructure diagram defining boundaries, data flows, and control placements to ensure a secure and consistent enterprise cloud deployment.

Taught by

Microsoft

Reviews

Start your review of Infrastructure and Network Protection

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.