GitHub Advanced Security (GHAS) plays a crucial role in enhancing the security posture of software development projects on GitHub. It provides a comprehensive set of tools and features designed to identify and address security vulnerabilities throughout the development lifecycle. By integrating security directly into the development process with GHAS, your team can build more secure and reliable software. The course will explore how to utilize GHAS to maximize security impact and understand GHAS and its role in the security ecosystem.

Learning objectives:
- Understand and configure GitHub Advanced Security features.
- Implement Dependabot for automated dependency updates.
- Set up and manage secret scanning to protect sensitive information.
- Configure code scanning using CodeQL for vulnerability detection.
- Analyze and interpret CodeQL scan results.
- Administer security policies and manage sensitive data within GitHub.
Course modules:
Introduction to GitHub Advanced Security
- Define GHAS and the importance of the integral features such as Secret scanning, Code scanning, and Dependabot
- Know how to utilize GHAS to maximize security impact
- Understand GHAS and its role in the security ecosystem
Configure Dependabot security updates on your GitHub repo
- Describe the available tools for managing vulnerable dependencies on GitHub.
- Enable and configure Dependabot alerts.
- Identify the permissions and roles required to view and enable Dependabot alerts.
- Enable and configure Dependabot security updates.
- Identify, review, and address vulnerable dependencies.
- Explain how to use GraphQL API to retrieve vulnerability information.
- Explain how to configure notifications for vulnerable dependencies.
- Lab: Configure Dependabot security updates
Configure and use secret scanning in your GitHub repository
- Describe secret scanning.
- Configure secret scanning.
- Use secret scanning.
Configure code scanning on GitHub
- Describe code scanning.
- List the steps for enabling code scanning in a repository.
- List the steps for enabling code scanning with third-party analysis.
- Contrast how to implement CodeQL analysis in a GitHub Actions workflow versus a third-party continuous integration (CI) tool.
- Explain how to configure code scanning on a repository using triggering events.
- Contrast the frequency of code scanning workflows (scheduled vs triggered by events).
Identify security vulnerabilities in your codebase by using CodeQL
- Create a database by using CodeQL to extract a single relational representation of each source file in the codebase.
- Run CodeQL in a database to find problems in your source code and find potential security vulnerabilities.
- Understand CodeQL scan results by using GitHub-created queries or your own custom queries.
Code scanning with GitHub CodeQL
- Understand CodeQL and how it analyzes code.
- Understand QL, a unique logic programming language.
- Set up CodeQL based code scanning in a GitHub repository.
- Reference a custom CodeQL query.
- Configure the language matrix in a CodeQL workflow.
- Learn how to use the CodeQL CLI to generate code scanning results and upload them to GitHub.
- Implement custom build steps.
- Lab: Reference a CodeQL query
- Lab: Configure a CodeQL language matrix
GitHub administration for GitHub Advanced Security
- Understand what GitHub Advanced Security is and how to use it in the software development lifecycle.
- Identify which GitHub Advanced Security features are available for open-source projects and which are available on enterprise products.
- Enable the different features of GitHub Advanced Security on different enterprise products.
- Determine who should get access to GitHub Advanced Security features in an organization and grant the correct permissions.
- Set security policies at the organization and repository levels.
- Understand how to respond to a security alert.
- Use the Security Overview to monitor security alerts.
- Use the GitHub Advanced Security API endpoints to manage the GitHub
- Advanced Security features and alerts.
Manage sensitive data and security policies within GitHub
- Create documentation that details security guidelines and useful information for collaborators.
- Set permissions and other rules.
- Automate processes that prevent security breaches.
- Respond to security breaches.

This AB-6005 course doesn´t lead to a standalone official microsoft certification.
After attending the course you´ll receive an Official Microsoft course completion certificate from Glasspaper.

FAQ – AB-6005: Introduction to supply chain management in Dynamics 365
Hva koster kurset?
Prisen er 12 000 NOK. Kurset inkluderer digital kursdokumentasjon og hands-on labs. Lunsj og forfriskninger er inkludert ved klasseromskurs.
Hvor lenge varer kurset?
Kurset går over 1 dag fra kl. 09.00 til 16.00.
Hvordan gjennomføres kurset?
Kurset kombinerer faglig gjennomgang og praktiske øvelser i Dynamics 365 Supply Chain Management. Kursdokumentasjonen er på engelsk, og instruktøren kan undervise på engelsk eller norsk.
Hvem passer kurset for?
Kurset passer for nybegynnere og fagpersoner som vil forstå hvordan Dynamics 365 Supply Chain Management støtter innkjøp, lager, produksjon, planlegging og logistikk.
- Business Managers
- Business Professionals
- Dynamics Functional Consultants
- Studenter på høyskole- og universitetsnivå
- Supply Chain Consultants
Hvilke forkunnskaper kreves?
Det kreves grunnleggende datakunnskaper og generell forståelse av forretningsprosesser.
Hvilke forkunnskaper anbefales?
Det er en fordel med kjennskap til supply chain, innkjøp, lagerstyring eller produksjon, samt grunnleggende forståelse av ERP-systemer og digitale forretningsprosesser.
Hva lærer jeg i løpet av kurset?
Du lærer hvordan Dynamics 365 Supply Chain Management brukes til å støtte sentrale forretningsoperasjoner. Etter kurset vil du kunne:
- Forstå rollen til Dynamics 365 Supply Chain Management i virksomhetsdrift
- Beskrive produktinformasjon, produkter, produktvarianter og dimensjoner
- Forstå lagerstyring og inventory control-prosesser
- Beskrive innkjøp, sourcing, warehousing, logistikk og produksjon
- Forstå demand planning og supply chain optimization
- Se hvordan AI og Microsoft-integrasjoner kan forbedre supply chain-prosesser
Er kurset praktisk rettet?
Ja. Kurset inkluderer hands-on labs og praktiske øvelser som gir deltakerne erfaring med sentrale funksjoner i Dynamics 365 Finance and Operations og Supply Chain Management.
Hvilke temaer dekkes i kurset?
Kurset dekker blant annet:
- Dynamics 365 Finance and Operations Apps
- ERP og forretningsprosesser
- AI-verktøy i Finance and Operations Apps
- Rapportering, Power BI og Microsoft 365-integrasjon
- Power Platform-integrasjon og Business Events
- Sikkerhet, workflows, batch jobs og juridiske enheter
- Produktinformasjon og released products
- Product dimensions, variants og item groups
- Lagerstyring, inventory journals og transfer orders
- AI-assisterte inventory insights og quality management
Får jeg sertifisering etter kurset?
Dette AB-6005-kurset leder ikke til en offisiell Microsoft-sertifisering.
Får jeg kursbevis?
Ja. Etter gjennomført kurs mottar du et offisielt kursbevis fra Glasspaper.
Hva gjør dette kurset nyttig?
Kurset gir en praktisk og tilgjengelig introduksjon til hvordan Dynamics 365 Supply Chain Management støtter ende-til-ende forretningsoperasjoner, fra produktoppsett og lagerstyring til innkjøp, produksjon og logistikk.
Kan kurset leveres bedriftsinternt?
Ja. Kurset kan leveres både som åpent kurs og som bedriftsinternt kurs.

Dynamics 365 Supply Chain & ERP
Finance & Operations
Dynamics 365 & forretningsprosesser