Training Catalog
Build the skills your teams need to adopt, govern and operate AI securely — through role-based training, realistic labs and official certification training.
Training builds lasting internal capability across the four stages of the AI & Copilot Operationalization Program.
Need a decision rather than training? Explore Focused Workshops
Training aligned to the Program
Assess
Build readiness and identify value and risk.
Govern
Build governance, assurance and security capability.
Build
Develop practical agent and Copilot Studio skills.
Operationalize
Build adoption, monitoring, ownership and sustainable internal capability.
Core training offers
AI Security and Assurance in Practice
How to review AI systems, risks, controls and evidence
Supports: AI Governance & Security · AI Agent Governance & Operations
Ideal for organizations that want internal governance and risk teams to apply the same assessment discipline used in AI governance engagements.
A two-day, no-code training that gives governance and risk teams a practical method to assess AI systems with confidence.
A repeatable five-step method — classify the architecture, build the system map, place controls and collect evidence, analyse threats and mitigations, then write the audit report and action plan.
Uses NIST AI RMF, OWASP for LLMs, MITRE ATLAS, GDPR and the EU AI Act as practical reference points — no need to memorise the frameworks.
View audience details
- Internal and external auditors
- Risk, governance and compliance professionals
- Data-protection, privacy and responsible AI teams
- Business managers and AI system owners
- Procurement and third-party risk professionals
- IT, security and architecture professionals seeking an assurance perspective
Ideal for mixed groups of technical and non-technical participants.
View lab outcomes
- Map an AI system: users, data, components and trust boundaries
- Recognise security, privacy, fairness and governance risks
- Evaluate controls and audit evidence across the AI lifecycle
- Observe live control-failure demonstrations in the lab
- Produce a concise AI Security & Governance Assessment with remediation priorities
View programme details
Day 1 — Understand the system
Why AI security differs from traditional application security, classifying six common AI architectures, and building a full system map covering users, data, identity, components, information flows and trust boundaries — with live demonstrations of access-control and retrieved-content failures.
Day 2 — Assess and act
Privacy, governance and EU regulation (GDPR and the EU AI Act), threat assessment with NIST AI RMF, MITRE ATLAS and OWASP, AI-assisted threat mapping and audit-report drafting, then a critical review and a practical 30-day action plan.
Final deliverable
Working from the Contoso HR Assistant case study, participants produce a one-page AI Security Assessment covering the business purpose, architecture and trust boundaries, priority risks, controls and evidence, framework references, residual risk and a 30-day action plan.
Microsoft Copilot Readiness & Adoption
Prepare teams to use Microsoft 365 Copilot safely, effectively and within clear governance boundaries.
- Copilot readiness and the permissions and oversharing risks to address first
- Safe, effective everyday use and realistic business use cases
- Role-based adoption and clear governance expectations
- Champions, adoption and measuring value
AI Agents & Copilot Studio
Build the practical skills needed to design, test and govern human-led, agent-assisted workflows.
- Identify agent use cases and design the workflow around them
- Build agents with Copilot Studio and connect key integrations
- Test, evaluate and set human-oversight and approval points
- Manage permissions and production-readiness considerations
Custom Immersive AI & Security Labs
A tailored AI-and-security training journey where your teams learn on realistic scenarios built around your own environment.
Scenarios can be built around Copilot adoption, AI governance, agent governance, Copilot Studio, Microsoft 365 security or AI operating-model needs.
- Scenarios generated for your systems, roles and threat context
- Learn by doing, including Capture-the-Flag style challenges
- Adaptable depth — from executives to technical teams
- Repeatable and updatable as tools and risks evolve
Sample scenario: securing a Copilot rollout for a 500-person organisation
- Map where Copilot can surface sensitive data across SharePoint, Teams and email
- Design and apply governance guardrails with Purview and sensitivity labels
- Run a hands-on lab where teams test prompts, oversharing and mitigations
- Leave with a repeatable checklist and an updatable training pack
Want a core offer delivered for your teams, or tailored to your environment?
Let's talkScenario-based security workshops (Microsoft 365)
Optional deep-dive workshops for teams that operate and defend Microsoft 365. Expand a workshop to see its full outcomes and programme.
Microsoft 365 in Action: A Day in the Life of an IT Manager
Microsoft 365 administration & operations — learn by running a real tenant
Supports: Microsoft Copilot Readiness & Adoption
View full workshop
A hands-on Microsoft 365 operations workshop where your team builds and secures a tenant through one realistic end-to-end storyline.
Every lab is triggered by a realistic business event — an HR request, a manager needing autonomy, a CISO policy requirement or an urgent support ticket. You configure the solution in a live Microsoft 365 environment, then sign in as the manager and employee to prove it works.
View audience details
- IT administrators and IT managers responsible for Microsoft 365 operations
- Identity, security and collaboration administrators
- Systems engineers moving from on-premises to Microsoft Entra and cloud services
- Consultants and support professionals who provision, delegate and secure Microsoft 365 workloads
Prerequisites: working knowledge of Microsoft 365 admin portals and basic identity/MFA concepts. PowerShell and Conditional Access exposure helpful but not required.
View lab outcomes
- Just-in-time admin access with Microsoft Entra PIM and Access Packages
- Delegated administration with custom roles and Administrative Units
- Tested Conditional Access with named locations, Terms of Use and authentication strengths
- A secure SharePoint onboarding site with sensitivity labels and governed Teams policies
- Hardened Exchange Online, Microsoft 365, Office and Edge policies
- Entra ID Governance access packages, lifecycle workflows and access reviews
- Microsoft Intune device configuration, compliance and enrollment
View programme details
Day 1 — Identity, privilege & delegation
Build the identity foundation in a security-first tenant with no standing admin rights: activate access via PIM and Access Packages, provision users and guests, and create custom roles and Administrative Units for least-privilege delegation.
Day 2 — Securing access, applications & collaboration
Configure and test Conditional Access with What If and Report-Only, integrate enterprise apps with self-service and approval, and stand up secure SharePoint and Teams collaboration.
Day 3 — Messaging, hardening, governance & endpoints
Secure Exchange Online messaging, harden tenant and app policies, automate governance with access packages and reviews, and configure Microsoft Intune — then consolidate a repeatable operational playbook.
What you'll take away
A repeatable, security-first playbook for onboarding and governing a Microsoft 365 department — plus the practical judgment to know why and when each control should be applied.
Microsoft 365 Under Attack: A Security Analyst Investigation
Microsoft 365 security administrator & analyst — investigate a full attack chain
Supports: AI Governance & Security · Microsoft Copilot Readiness & Adoption
View full workshop
A realistic incident-driven workshop where analysts investigate a full Microsoft 365 attack chain and deliver an executive-ready security briefing.
The focus is evidence, decision-making and CISO-ready recommendations. A guiding principle runs throughout: prove what is connected and what is separate — distinguishing exposure from interaction, interaction from compromise, and alerts from confirmed data loss.
View audience details
- Security analysts and SOC team members
- Microsoft 365 security administrators and identity or security engineers
- Incident responders and threat hunters new to the Microsoft 365 security stack
- IT professionals moving into detection, response and evidence-based reporting
Prerequisites: working knowledge of Microsoft 365 admin portals and core security concepts. Defender and Conditional Access exposure helpful but not required.
View lab outcomes
- Security posture recon with Secure Score and Threat Analytics
- A phishing campaign with Defender for Office 365 — scope and containment
- Suspicious sign-ins and TAP/MFA recovery abuse — compromise vs attempt
- A risky OAuth consent grant and application persistence
- Device-trust abuse and SharePoint Finance data access
- Cloud exfiltration and Endpoint DLP response
- RDP access and endpoint persistence in Defender for Endpoint
- The CISO briefing — turning evidence into an executive incident story
View programme details
Day 1 — Identity, access & posture foundations
Onboard the analyst identity, learn the Zero Trust investigation model, and assess the tenant's posture with Secure Score and Threat Analytics — completing the first posture-review challenge.
Day 2 — Identity & application attack paths
Follow the incident from phishing into identity and application abuse: investigate the campaign, suspicious sign-ins and recovery abuse, and a risky OAuth consent grant, then review the controls that reduce each risk.
Day 3 — Data, endpoint & executive briefing
Trace device-trust abuse and Finance data access, sensitive-data movement through Endpoint DLP, and RDP-based endpoint persistence with Defender for Endpoint — then consolidate everything into the final CISO incident briefing.
What you'll take away
The ability to investigate a full Microsoft 365 attack chain across identity, applications, data and endpoints; to separate confirmed facts from assumptions; to recommend controls that reduce recurrence without blocking the business; and to brief leadership with clear, prioritized, evidence-based conclusions.
Official Certification Training
We also deliver official certification training for teams that need recognized, role-based credentials alongside practical capability building.
CompTIA Security+ (official)
The industry-standard foundation in cybersecurity — threats, architecture, operations and governance — with official courseware, hands-on labs and exam preparation.
CompTIA SecAI+ (official)
CompTIA's certification for securing AI systems — official training, hands-on labs and exam preparation to validate your AI security skills.
Selected official Microsoft certification courses aligned with AI, Copilot, security and architecture.
Microsoft AB-730 (official)
Official Microsoft AB-730 preparation with practical labs, role-based scenarios and exam-focused coaching for your team.
Microsoft AB-731 (official)
Official Microsoft AB-731 preparation with guided labs and real-world exercises to build confidence before the exam.
Microsoft AB-100 (official)
Official Microsoft AB-100 training that blends architecture guidance, hands-on practice and targeted exam preparation.
Microsoft GH-300 Copilot (official)
Official Microsoft GH-300 Copilot preparation focused on practical scenarios, governance and operational readiness.
Need help choosing the right certification track for your team?
Discuss a certification trackBuild the capability your AI transformation needs
Choose a core offer, tailor a lab to your environment, or align certification training to your team's goals.
Let's talk