← Back

Top Azure Security Training Providers In 2026

Buying azure security training in 2026 is harder than it was a year ago, because the credential most buyers used as a reference point no longer exists. Microsoft retired the AZ-500 exam on 31 August 2026 and replaced the Azure Security Engineer Associate credential with the Cloud and AI Security Engineer Associate, earned through exam SC-500. Plenty of catalogs and bootcamp pages still carry AZ-500 branding. Some are current and simply unrenamed. Others are stale. Telling them apart is now part of the purchasing job.

The second source of confusion is that three very different products share the same shelf. The vendor certification route teaches you to configure Microsoft Entra ID, Defender for Cloud, Key Vault and Sentinel to a documented standard, ending in a proctored exam. The offensive route teaches you to enumerate a tenant, abuse consent grants and managed identities, escalate through Azure RBAC, and move laterally across subscriptions. The detection route teaches you to read cloud logs and design tenants that fail safely. An engineer who buys the wrong one gets a certificate and no capability.

This list covers providers and is explicit about which of those three jobs each one does. Every entry was checked against the provider’s own course pages in September 2026, not against a directory or a review aggregator. Where a provider publishes a price, a duration, a lab window or an exam format, it is quoted. Where pricing sits behind a contact form, that is stated rather than guessed.

What follows is for people securing, attacking or defending a Microsoft Azure and Entra ID estate, with hands on a real tenant.

Azure Security Training At A Glance

ProviderCourse Or CertificationFormatOffensive Or DefensiveMicrosoft Exam Route
White Knight LabsOffensive Azure Operations and Tactics Certification (OAOTC)Live instructor-led Zoom class and on demandOffensiveNo, vendor-neutral performance-based exam
MicrosoftSC-500 and SC-100 credentials, free Learn modules, SC-500T00 coursewareFree self-paced modules plus partner-delivered classroomDefensiveYes, the route itself
SANS InstituteSEC541 Cloud Security Threat Detection, SEC549 Cloud Security ArchitectureIn person, live virtual, or OnDemandDefensive and detectionNo, maps to GIAC GCTD and GCAD
Altered SecurityCertified Azure Red Team Professional (CARTP)On demand with timed cloud labOffensiveNo, 24-hour practical exam
XINTRAAttacking and Defending Azure and M365On demand, live cohort on requestBoth attack and detectionNo formal exam
SpecterOpsAdversary Perspectives: AzureFour-day live class on a hosted rangeOffensiveNo exam, certificate of completion
CloudBreachBreaching Azure (OASP), Breaching Azure Advanced (OASE)On demand, browser-based labsOffensiveNo, report-based practical exam
Antisyphon TrainingBreaching the CloudOn demand, 16 hoursOffensive, multi-cloudNo exam
Firebrand TrainingAccelerated SC-500 Cloud and AI Security EngineerFour-day classroom, online live, or residentialDefensiveYes, exam voucher and testing included
QAMAZ500 Secure Cloud Resources, MSC100 Cyber Security ArchitectFour-day virtual classroom and bespokeDefensiveYes, exam sold separately
PluralsightAZ-500 Microsoft Azure Security Technologies pathSelf-paced video with sandbox labsDefensiveExam prep only, path still AZ-500 branded
CybrGetting Started with Microsoft Defender for CloudSelf-paced subscription with hands-on labsDefensiveNo, posture and workload protection focus

Top Azure Security Training Providers In 2026

The 12 providers below run deepest hands-on first, then the vendor certification route, then the self-paced catalogs. Each entry states format, published duration and price, whether the content is offensive or defensive, and the honest limitation.

1. White Knight Labs — Offensive Azure Operations And Tactics Certification

White Knight Labs sells the Offensive Azure Operations and Tactics Certification, or OAOTC, which teaches attacking Azure and Entra ID environments rather than configuring them. The published syllabus runs through Azure and Entra ID fundamentals, identity enumeration and abuse, authentication and authorization attacks, Azure RBAC exploitation, managed identity abuse, cloud lateral movement, persistence, and configuration assessment and reporting. It is sold both as a live instructor-led class delivered over Zoom and as an on-demand version of the same material.

The assessment is the differentiator. Every certification in the catalog is performance based, and the OAOTC exam gives candidates 48 hours in a live lab followed by a further 48 hours to write and submit a professional report. That mirrors a real Azure assessment deliverable, which is why the credential reads differently to a hiring manager than a multiple-choice pass. Live classes run at $1,200 including the exam voucher, and vouchers do not expire. CertForge Pro covers the catalog at $1,000 a year with two exam attempts.

The wider catalog is all performance based and includes ELPT, OADOC, ARTOC, ODPC, OGOTC and ASCPC, so Azure students have an obvious next step. Co-founders John Stigerwalt and Greg Hatcher teach the classes themselves, and Hatcher came from Army Special Operations and then instructing at the NSA. The firm holds CREST Pathway+ status, CREST’s pre-accreditation program. The limitation is scope. This is an attacker course, it maps to no Microsoft exam, and students deploying labs in their own Azure tenant carry the cloud costs.

2. Microsoft — The Official SC-500 And SC-100 Certification Route

Microsoft is the reference point for anyone whose employer asks for an azure security certification with a recognized name on it. The Azure Security Engineer Associate credential and its AZ-500 exam retired on 31 August 2026. The successor is the Cloud and AI Security Engineer Associate, earned through exam SC-500, Implementing End-to-End Security Controls for Cloud and AI Workloads. The exam runs 120 minutes, is proctored with interactive components, and is currently English only.

The four scored domains are identity, access and governance at 20 to 25 percent, storage, databases and networking at 25 to 30 percent, compute at 20 to 25 percent, and security posture at 20 to 25 percent. The content now stretches past classic Azure into AI workload security and Microsoft Security Copilot. Microsoft publishes free self-paced learning paths on Learn, and the paid classroom equivalent is course SC-500T00-A, four days of instructor-led training delivered by Microsoft Learning Partners.

Above associate level sits SC-100, Microsoft Cybersecurity Architect, which now requires one of three associate prerequisites: Identity and Access Administrator, Security Operations Analyst, or the new Cloud and AI Security Engineer. Its English version was updated on 28 July 2026. The limitation is that Microsoft does not run the classroom itself, and the free Learn modules teach configuration rather than adversarial thinking. They will not prepare an engineer for what an attacker does with a consent grant.

3. SANS Institute — Cloud Detection And Architecture With GIAC Certification

SANS covers the defensive and detection side of Azure more thoroughly than anyone else here. SEC541, Cloud Security Threat Detection, runs five days instructor led or roughly 30 hours self-paced, carries 30 CPE credits, and includes 22 hands-on labs. It covers Azure and Microsoft 365 telemetry alongside AWS, teaching cloud-native logging, API monitoring and detection engineering against real attack scenarios. It maps to the GIAC Cloud Threat Detection certification, GCTD.

The companion course is SEC549, Cloud Security Architecture, also five days and 30 CPEs with 15 labs, mapping to GIAC Cloud Security Architecture and Design, GCAD. Its Entra ID content is substantial, with federated access and single sign-on modules and labs that include Azure to AWS single sign-on and Azure organization policies. Together the two cover the design and detection halves of a tenant.

Delivery is in person, live virtual, or OnDemand with four months of access. SANS publishes list pricing openly, and both courses show $8,260 for OnDemand and for United States live delivery, with regional pricing at international venues. The limitations are cost and focus. This is the most expensive option here by a wide margin, the GIAC exam attempt is a separate line item, and neither course is Azure-only. A team running a pure Microsoft estate pays for AWS content it does not need.

4. Altered Security — Certified Azure Red Team Professional Lab

Altered Security built its reputation on Active Directory attack labs and carried the same model into Azure with the Certified Azure Red Team Professional, CARTP. The product is an on-demand course plus a timed cloud lab, sold in three windows: 30 days at $449, 60 days at $649, and 90 days at $849. Course material access is lifetime, and the purchase includes more than 15 hours of video, a lab manual and one exam attempt.

The syllabus is organized around a full Azure kill chain. It covers architecture and role assignments, discovery and reconnaissance, initial access through consent grant attacks and credential abuse, enumeration of Azure resources and identities, privilege escalation within Entra ID and Azure, lateral movement across tenants and hybrid environments, persistence including Golden SAML, data extraction from Key Vault and storage, and defense bypass techniques. Altered Security states that a basic understanding of Azure and Entra ID is desired but not mandatory.

The exam is a 24-hour hands-on practical in a dedicated lab with multiple Azure tenants, where the candidate must compromise resources across those tenants and submit a report. The honest limitation is the clock. Lab time is metered from activation, so a student who buys a 30-day window and loses two weeks to work commitments has bought considerably less than they paid for.

5. XINTRA — Attack And Detection Coverage In One Azure Course

XINTRA’s Attacking and Defending Azure and M365 is the rare course that teaches both halves of the same technique. Each topic is covered three ways: how the attack works, how to detect it, and how to mitigate it. That suits detection engineers who must write rules against attacker tradecraft, and red teamers who must explain findings to a blue team.

The on-demand package costs $1,550 and includes more than 30 hours of content across 110 videos and 26 labs, with access running for one year from purchase. A live cohort is available at $3,000 per person with a 10-person minimum, which in practice makes it a team purchase. The syllabus spans 11 modules covering reconnaissance and enumeration, initial access through password spraying, OAuth abuse and multifactor bypass, credential theft, lateral movement, privilege escalation, persistence and defense evasion.

The course is taught by InverseCos, whose incident response background covers defense, banking and energy sectors and who holds GXPN, GASF, GREM and GCFA. The stated audience is deliberately mixed, spanning red team, blue team, incident response and cloud engineering. Prerequisites are modest, requiring a Windows virtual machine and a SOF-ELK setup. Two limitations matter. There is no certification exam, so the output is knowledge rather than a credential, and access expires after 12 months. XINTRA has flagged a major content refresh for January 2027.

6. SpecterOps — Four-Day Live Azure And Entra ID Attack Path Class

SpecterOps built BloodHound, and its Azure course is organized around how identity chains together rather than around a service list. Adversary Perspectives: Azure runs four days on a hosted training range, and the day-by-day breakdown is published openly. Day one covers Entra ID, application registration, Entra roles, Azure Resource Manager and Azure roles. Day two covers Microsoft 365, App Services, virtual machines, Microsoft Graph, Microsoft Intune and OAuth.

Day three moves into hybrid identities, device authentication, passwordless authentication, OpenID Connect and multifactor authentication. Day four covers Conditional Access policies, external information gathering, credentials, Privileged Identity Management and tooling. That progression from directory objects to hybrid trust to policy bypass is the clearest published syllabus of any offensive Azure class here, and it is unusually strong on authentication mechanics most courses skip.

SpecterOps states the course assumes no prior Azure knowledge, though basic familiarity with cloud concepts and exposure to an enterprise Azure environment both help. Students need only their own computer with a modern browser because the range is hosted, and completion brings course slides, a certificate, a challenge coin and a digital badge. Two limitations apply. There is no examination, so nothing independently validates skill afterward, and the course page does not publish a seat price, so budget holders should request a quote before shortlisting it.

7. CloudBreach — Breaching Azure And Breaching Azure Advanced Certifications

CloudBreach runs a focused catalog of offensive cloud courses, and its Azure track has two rungs. Breaching Azure leads to the OASP certification and contains 17 modules across 32 topics, with 16 hands-on labs and nine video lessons. Labs are browser based, and materials come with lifetime access. Topics include Azure environment enumeration, Entra ID identity abuse, OAuth flow exploitation and managed identity pivoting.

Pricing is tiered by lab window and exam attempts. Essential costs $499 with 30 days of cloud lab access, Extended costs $699 with 60 days, and Breaching Azure+ costs $1,000 with two exam attempts instead of one. The exam is practical rather than multiple choice: candidates get 24 hours to compromise the target environment and capture the exam flag, then a further day to submit a methodology report. CloudBreach recommends around one year of Azure infrastructure experience.

The second rung, Breaching Azure Advanced, leads to OASE and covers 17 modules with 17 labs. Its topics are the ones most Azure courses stop short of, including Privileged Identity Management and Conditional Access bypass, cross-tenant attacks, and Azure DevOps pipeline compromise. For a tester who already knows tenant enumeration, that is the reason to look here. The limitations are that CloudBreach is a small independent provider with a correspondingly small instructor bench, and there is no defensive or detection content in the Azure track.

8. Antisyphon Training — Low-Cost Entry Into Cloud Attack Methodology

Antisyphon’s Breaching the Cloud, taught by Beau Bullock, is the cheapest credible way onto this list. The on-demand version runs 16 hours and costs $575. It covers Amazon Web Services, Microsoft Azure and Google Cloud Platform, plus the productivity layers on top of them including Microsoft 365, which matters because most real Azure compromises start in the identity and mail tier rather than in Azure Resource Manager.

The methodology arc is complete for the price. It runs through cloud reconnaissance, discovering misconfigurations, establishing initial access, post-compromise work including privilege escalation and persistence, and data exfiltration from cloud services. It also covers using cloud services offensively for phishing, domain fronting and command and control, which is infrastructure knowledge that red teams need and that vendor certification tracks never touch.

Students enroll through Antisyphon’s learning platform and receive a certificate of completion. Antisyphon also operates a pay-what-you-can model across parts of its catalog so that cost is not a barrier, although that model does not apply to this course. The limitations follow from the price and the format. Sixteen hours split across three cloud providers means Azure gets breadth rather than depth, there is no examination, and a tester who must demonstrate Azure-specific competence to a client will need a deeper second course on top.

9. Firebrand Training — Accelerated SC-500 Bootcamp With Exam Included

Firebrand is the option for engineers who need the new Microsoft credential quickly and can clear their calendar to get it. Its accelerated Cloud and AI Security Engineer Associate course compresses SC-500 preparation into four days, with up to 12 hours of instructor-led training each day and 24-hour lab access. Three study modes are offered: city center classroom, online live, and residential.

The package is bundled rather than modular, which is the main reason buyers choose accelerated training. It includes the exam voucher and on-site testing, practice tests, official courseware and digital materials, and on the residential option accommodation and meals as well. Firebrand describes itself as one of the few companies in the world designated a Microsoft Cloud Partner. It runs a pass guarantee: candidates who do not pass first time may train again free, unlimited for one year, with accommodation, exam and incidental costs excluded.

This is firmly defensive training, covering the four SC-500 domains: securing access with Entra ID and Key Vault, securing storage, databases, networking and compute, securing AI solutions, and managing security posture. The limitations are cost transparency and intensity. Firebrand does not publish a price on the course page and requires a form submission to get one. Twelve-hour teaching days also suit experienced engineers refreshing knowledge far better than newcomers meeting Entra ID for the first time.

10. QA — Microsoft-Accredited Instructor-Led Azure Security Courses

QA is a large accredited Microsoft training provider and runs the official Azure security courseware as scheduled instructor-led events. Its course MAZ500, Secure Cloud Resources with Microsoft Security Technologies, runs four days and is priced at £3,205 plus VAT. Delivery is virtual classroom, with a bespoke option for organizations wanting a private cohort. Published content maps to the official curriculum across Microsoft Entra identity and access, secure networking, compute, storage and database security, and governance through Defender for Cloud and Sentinel.

QA also runs MSC100, Microsoft Cyber Security Architect, for the SC-100 credential. Its stated prerequisites are blunt and worth heeding: advanced experience across identity and access, platform protection, security operations, and securing data and applications, plus hybrid and cloud implementation experience. That is an architect course, not a next step for someone who has just finished an associate exam. Attendees are issued a unique code to register completion against their Microsoft Learn account.

Two limitations deserve attention. The exam is not bundled. QA lists it as available separately, so the £3,205 figure is the training cost alone. More importantly, the MAZ500 course code and title still carry AZ-500 branding after that exam retired in August 2026, so any buyer should confirm in writing which exam the current delivery prepares for before booking seats. Pricing is published in pounds, which adds a conversion step for North American buyers.

11. Pluralsight — Self-Paced Video Path With Sandbox Labs

Pluralsight covers the exam preparation job for teams that already hold a platform subscription and want azure security engineer training without scheduling anyone out of the office. Its AZ-500 Microsoft Azure Security Technologies path contains six courses and five hands-on labs totaling roughly 50 hours, organized by exam domain: manage identity and access, secure networking, secure compute, storage and databases, manage security operations, and exam preparation.

The labs are the part worth paying for. They include managing users in Microsoft Entra ID, securing network traffic, configuring storage access and setting up logging with Azure Monitor, all executed in a provisioned environment rather than watched in a video. Pluralsight lists Azure Fundamentals as a minimum prerequisite and recommends Azure Administrator experience on top. Access comes through the Cloud and Security library subscriptions, with pricing on Pluralsight’s plans page rather than the path page.

The limitation is the one affecting a large share of this market in 2026. The path is still branded around AZ-500, an exam that retired at the end of August 2026, so a buyer using it as SC-500 preparation is working from a blueprint that no longer matches the scored domains. The underlying Azure configuration skills remain valid and transferable. The exam mapping does not. There is also no proctored assessment, so the output is knowledge and a completion record, not a credential.

12. Cybr — Subscription Labs For Defender For Cloud And Posture Management

Cybr is a subscription learning platform best known for AWS security content, and its Azure catalog is smaller but practical. Getting Started with Microsoft Defender for Cloud runs 17 lessons taught by Chad Mcrowell and teaches Cloud Security Posture Management and Cloud Workload Protection across Azure, AWS, Google Cloud and on-premises estates. Topics span virtual machines, containers, storage, networking, identity, threat detection and automated incident response, worked through NIST 800-53, CIS and PCI DSS.

Pricing is the reason this entry earns a place on a list where most options cost four figures. Membership is $20 a month or $200 a year, reduced from a $240 list rate, and either plan carries unlimited access to premium courses, hands-on labs, ebooks and practice exams. A free account tier with a subset of free courses and labs lets a buyer test the platform before committing.

The course is pitched at intermediate level and assumes a basic understanding of Azure services and the Azure portal, plus general networking and security knowledge, so it is not a first cloud course. Course materials including slides, scripts and commands are distributed through a GitHub repository. The limitation is coverage. Cybr’s depth is in AWS, the Azure catalog is currently thin, and this is posture and workload protection training rather than a route to any Microsoft certification.

How To Choose An Azure Security Training Provider

Are You Buying Offensive Skills Or Defensive Skills?

This question decides most of the shortlist, and buyers most often skip it. Offensive courses from White Knight Labs, Altered Security, SpecterOps, CloudBreach and Antisyphon teach enumeration, consent grant abuse, managed identity pivoting and cross-tenant movement. Defensive courses from Microsoft, Firebrand, QA, Pluralsight and Cybr teach configuration, posture management and compliance. SANS and XINTRA sit across both.

Does The Course Map To A Microsoft Exam That Still Exists?

AZ-500 retired on 31 August 2026 and SC-500 replaced it, but much published AZ-500 training predates that change. Some of it is fine, because the underlying Entra ID, Key Vault, networking and Defender for Cloud material carries over almost unchanged. What does not carry over is the AI workload security content SC-500 now scores, or exam preparation modules that drill against the retired blueprint. Before buying anything with AZ-500 in the title, ask in writing which exam the delivery prepares for and when the courseware was last revised.

How Long Does Lab Access Actually Last?

Course access and lab access are separate products in this market, and the difference is expensive. Altered Security sells 30, 60 and 90 day lab windows at $449, $649 and $849 while giving lifetime access to course material. CloudBreach splits the same way on its Essential and Extended tiers. XINTRA gives one year from purchase. SANS OnDemand gives four months. Because lab clocks usually start on activation rather than first use, map the window against real availability, and avoid buying seats months before engineers can use them.

Is The Assessment Performance Based Or Multiple Choice?

Assessment format tells a hiring manager more than the certification name does. White Knight Labs gives 48 hours in a live lab plus 48 hours to write and submit a professional report, mirroring a real client deliverable. Altered Security and CloudBreach run 24-hour practical exams with a report requirement afterward. Microsoft’s SC-500 is a 120-minute proctored exam. SANS routes to GIAC exams bought separately. SpecterOps, XINTRA and Antisyphon issue completion certificates with no examination. Only a report-based practical proves a candidate can communicate findings.

Who Pays For The Azure Tenant And The Cloud Bill?

Offensive Azure training carries a cost classroom training does not, because someone has to run the target environment. Providers handle this three ways. Hosted ranges, used by SpecterOps and by the browser-based labs at CloudBreach, include infrastructure in the seat price. Dedicated exam tenants, as with the multi-tenant Altered Security practical, are similarly provided. The third model asks students to deploy labs into their own Azure subscription, which keeps the course price lower but puts the consumption bill on the employer, as it does for White Knight Labs students using their own tenant. Confirm which model applies before approving a purchase order.

Conclusion

The Azure security training market in 2026 splits cleanly between two things that rarely appear in the same catalog. One side teaches you to build and monitor a tenant to Microsoft’s documented standard, and now routes through SC-500 rather than the retired AZ-500. The other teaches you to break one, and is measured by whether you can compromise a live environment under a clock and write up what you did.

For most buyers the sensible sequence is to establish the defensive baseline first through Microsoft’s own material or an accredited partner delivery, then add an offensive course once the team can read a tenant well enough to understand what is being attacked. Engineers who arrive at an offensive Azure class without knowing how Conditional Access, Privileged Identity Management and managed identities work spend two days catching up.

Whichever route you take, weigh the assessment format as heavily as the syllabus. A performance-based exam requiring a written report is harder to pass and harder to fake than a multiple-choice paper, and it produces evidence a stakeholder can read. That is why offensive specialists such as White Knight Labs structure their certifications the way they do. Verify the course version, confirm the exam it maps to, check who pays the cloud bill, and buy the training that matches the job you need done.

If you want to add your company to this list, drop us a line or submit a form in the Top Choices section. After a thorough review, we’ll decide whether it’s an appropriate addition.

Turn your marketing into a profit engine

Submit your details, and we’ll build a strategy to scale your brand and drive a steady flow of high-quality leads.