Azure Security Glossary: Core Terms for a Hands-On PoC
A concise map of Entra tenants, subscriptions, RBAC, Conditional Access, Azure Policy, Defender for Cloud, Log Analytics, and Microsoft Sentinel—with careful AWS comparisons.
Independent Hands-on Lab · Reference Architecture
This hands-on series demonstrates how generalized enterprise security requirements can be translated into a phased Azure architecture, implemented with measurable controls, and operationalized through identity governance, cloud security posture management, threat detection, and automated response.
Published Guides
Use these localized guides to establish the vocabulary and design decisions behind the lab. Publication makes the guidance available; it does not assert that a hands-on stage has been validated.
A concise map of Entra tenants, subscriptions, RBAC, Conditional Access, Azure Policy, Defender for Cloud, Log Analytics, and Microsoft Sentinel—with careful AWS comparisons.
A practical reference architecture for designing Azure identity, subscriptions, networking, policy, security operations, FinOps, and infrastructure as code for a global hybrid enterprise.
Coursera Review Series
These lesson-by-lesson reviews revisit key ideas from the Azure Cybersecurity Solutions and Microsoft Defender course.
Learning boundary: These notes are personal learning reviews; they are not evidence that any Azure Security Lab implementation or validation has been completed.
Study notes on Azure DDoS Protection, virtual networks, Azure Firewall, web application firewalls, just-in-time VM access, and encryption, updated for the 2026 Azure security landscape.
A practical method for turning Azure security layers into a verifiable architecture with clear trust boundaries, signals, owners, containment, and recovery evidence.
A precise guide to Azure's automatic DDoS infrastructure baseline, its workload-level gaps, and the evidence needed before claiming an application is DDoS-ready.
Compare Azure DDoS IP Protection and Network Protection by eligible resources, attachment scope, telemetry, response benefits, and pricing structure.
Design a private Azure VM by separating guest administration, application ingress, explicit internet egress, and private Azure service access—with evidence for every path.
Learn Azure networking through a three-tier example: plan non-overlapping CIDRs, segment subnets, read stateful NSG rules, and prove both allowed and denied traffic paths.
Compare Azure Firewall SKUs by real traffic paths, throughput, FQDN control, threat intelligence, TLS inspection, IDPS, cost, operations, and migration risk.
Build and verify a single-region Azure Firewall hub-spoke path with UDRs, symmetric return routing, DNS Proxy, Private Resolver, DNAT, hybrid routing, and a controlled forced-tunnel branch.
A detailed review of cloud security management, Defender for Cloud, Azure Bastion, Azure Policy, and Microsoft Sentinel SIEM/SOAR, with 2026 product corrections and validation patterns.
A practical review of Microsoft Defender XDR, Defender for Cloud, endpoint and identity protection, Microsoft Purview, incident correlation, and the Microsoft Sentinel connector covered in Module 3.
A final-course reflection that turns Azure DDoS, Firewall, Bastion, JIT, encryption, Policy, Defender, and Sentinel concepts into a threat-control-evidence model for securing virtual machines.
Implemented Baseline
Identity Stage · In Progress
Roadmap
Establish a governance, logging, access, policy, posture, and cost baseline.
Prepare a least-privilege, report-only identity access policy and its validation gates.
Model time-bound privileged access and approval controls.
Reduce credential exposure with workload identity and secret lifecycle controls.
Define scope, plan selection, data collection, and initial posture review.
Prioritize posture findings by risk, effort, cost, and operational impact.
Trace identity, resource, and exposure relationships in a synthetic environment.
Create a minimal monitoring and investigation workflow for the lab.
Develop explainable detections with test criteria and known limitations.
Automate a bounded response with approval and failure handling.
Document a synthetic investigation timeline, evidence, and containment decisions.
Review the end-to-end design, trade-offs, gaps, and production recommendations.
Validation Boundary
The first two stages are in progress and have not been marked as validated. Planned stages remain roadmap entries rather than empty public articles. Each stage will be published only after its implementation notes, validation criteria, redacted evidence, limitations, and production recommendations are ready. A published design reference does not by itself move a hands-on stage to Lab Validated.