Open-source project
microsoft/Security-101 avatar
microsoft/Security-101

microsoft/Security-101: a free eight-module security curriculum you read in the browser

8 Lessons, Kick-start Your Cybersecurity Learning.

6,942 stars934 forksHTMLCC0-1.0

At a glance

What is it?
Microsoft's Security-101 repository is a vendor-agnostic set of Markdown lessons covering the CIA triad, risk, zero trust, IAM, networking, SecOps, AppSec, infrastructure, data and AI security. It is a reading course with quizzes, not a hands-on lab, and that distinction decides who should bother.
Who is it for?
Adopt microsoft/Security-101 if you need a structured, vendor-neutral starting point for security concepts and you accept that it teaches vocabulary rather than tool operation; the README states plainly that it does not cover how to use specific security tools, how to hack or do red teaming, or specific compliance standards.
Can I use it commercially?
Yes. CC0-1.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 37 days ago.
What is it written in?
Mainly HTML, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What the eight modules actually cover, and who the course is written for

The repository is a curriculum, not a library. The README describes it as "Cybersecurity for Beginners" and says it is vendor agnostic, split into small lessons that should take around 30-60 minutes each, with a short quiz per lesson and links to further reading. The top-level files confirm the shape: eight numbered groups, each opening with key concepts, then either a zero trust architecture lesson or a capabilities lesson, and closing with an end-of-module quiz.

The first group is the conceptual floor: 1.1 The CIA triad and other key concepts.md, 1.2 Common cybersecurity threats.md, 1.3 Understanding risk management.md, 1.4 Security practices and documentation.md, 1.5 Zero trust.md, 1.6 Shared responsibility model.md. Groups two through seven apply that vocabulary to a domain: IAM, networking, SecOps, AppSec, infrastructure security, data security. Group eight is the newest territory: 8.1 AI security key concepts.md, 8.2 AI security capabilities.md, 8.3 Responsible AI.md.

The audience is someone who has to talk to security people and currently cannot. A developer joining a team with a threat model, a product manager reading a penetration test report, a junior admin who has been handed a firewall policy. The lessons are written to be read in order, and the quiz files are the only self-check mechanism the repository provides. There is no video course in the repository itself; the README embeds a link to an introductory video hosted on an Azure media endpoint, and an images/banner.jpg illustration.

How the content is structured: Markdown files, a generated site, and translated copies

There is no application here. The primary language listed for the repository is HTML, which comes from index.html and the published site at microsoft.github.io/Security-101. The lessons themselves are Markdown files at the repository root, named with a numeric prefix and a human-readable title, for example "2.1 IAM key concepts.md". The numbering is the navigation: there is no manifest, no build config for a lesson index, and no database. The README table lists module number, module name, concepts taught and learning objectives, and it links directly to the raw Markdown files on GitHub.

Translations are the one piece of automation visible in the README. A block marked CO-OP TRANSLATOR LANGUAGES TABLE lists roughly fifty languages, each pointing at ./translations/<code>/README.md, and the README states these are supported via a GitHub Action, described as automated and always up to date. The supported-language list is external, linked to the Azure/co-op-translator repository. A translated_images/ directory sits alongside images/, which suggests the translation pipeline also handles image assets.

The practical consequence for a reader is that the English lesson files are canonical and the translations are downstream. If a translated lesson reads oddly, the fix is in the English source. The repository also carries AGENTS.md, SECURITY.md, SUPPORT.md and CODE_OF_CONDUCT.md at the root, which is a standard Microsoft open source layout rather than anything specific to the course content.

Reading it: cloning the repository and working through module 1.1

The README does not describe an installation procedure, because there is nothing to install. The two supported routes are the published site and a local clone. The repository has no package manifest, so after cloning there is no dependency step to follow.

The README's multi-language table links to translated copies under ./translations/, and the English lesson files sit at the repository root. A local clone is the ordinary git operation:

bash
git clone https://github.com/microsoft/Security-101.git

After that, the lesson files are at the repository root and can be opened in any Markdown viewer or read on GitHub. The README's module table links each module to its file, for example the first one:

bash
1.1 The CIA triad and other key concepts.md

That is the filename the README's table points at for module 1.1. If it is not present in your clone, the file has been renamed or the clone is incomplete. From there the README's own suggested sequence is to work through the numbered files in order and finish each group with its quiz file, for example "1.7 End of module quiz.md" for the first group. The quizzes are plain Markdown, so there is no scoring tool; you check your own answers.

The README also names a continuation path rather than a next command: it recommends Microsoft Security, Compliance, and Identity Fundamentals on Microsoft Learn, and mentions Exam SC-900 as a possible follow-on. Those are external to this repository and are not part of the clone.

What the course deliberately does not teach

The README has an explicit exclusions list, and it is unusually blunt. It states that the course does not cover how to use specific security tools, how to hack or do red teaming or offensive security, or learning about specific compliance standards. That is the honest boundary of the project, and it is the single most useful thing to read before adopting it.

There are consequences. A learner who finishes all eight modules will be able to explain what zero trust means and why identity is treated as a control plane, but will not be able to configure a conditional access policy, write a detection rule, or map a control to an auditor's framework. The capabilities lessons, such as 2.3 IAM capabilities.md or 4.3 SecOps capabilities.md, describe categories of tooling rather than walking through a product. If your goal is a certification, the README itself redirects you outward to Exam SC-900 rather than claiming the course prepares you for it.

A second limitation is structural. The repository has no releases, so there is no versioned snapshot to cite in a syllabus, and the lesson files can change in place. The last push to the default branch was on 2026-08-24. Recency of commits is not a stability guarantee for a document you are assigning to a class. The README table is truncated in the published view, so the file tree, not the table, is the reliable inventory.

How it compares with OWASP and NIST starting points

The obvious alternative for a beginner is the OWASP Top Ten, and the difference in approach matters. OWASP's list is organized around web application vulnerability categories and is written for people building or testing web software; it assumes a target and a category of defect. Security-101 is organized around concepts and domains, and it starts from the CIA triad and risk management before it reaches any application-specific material. If you are a backend developer whose immediate problem is a class of injection flaw, OWASP is the shorter path. If you are trying to understand why your organization has an identity team and a separate network team, the module structure here is the better fit.

NIST publications are the other comparison point. NIST material is authoritative and framework-shaped, written for organizational adoption, and it is not designed to be read in 30-60 minute sittings with a quiz at the end. Security-101 borrows the vocabulary that NIST frameworks use, particularly around risk, controls and zero trust, without reproducing any framework's control catalogue. The README says it does not teach compliance standards, and that is consistent with this positioning: it teaches the concepts you need before a framework makes sense.

Neither comparison is a knock. The trade-off is depth against breadth, and Security-101 chooses breadth on purpose.

Licence, reuse, and the cost of keeping a fork current

The repository is licensed CC0-1.0, which the LICENSE file at the root carries. CC0 is a public domain dedication rather than a permissive software licence, so the practical effect is that reuse in teaching material, internal onboarding documents or paid courses carries very few conditions. This is a content licence being applied to content, which is the correct fit; the caveat is that CC0 covers the repository's own text and images, and third-party links inside the lessons, such as the Microsoft Learn paths and the SC-900 exam page, are governed by their own terms. That is a factual boundary, not legal advice.

The upgrade cost is close to zero and also close to invisible. There is no version to pin and no changelog to read, so a fork does not receive a signal when a lesson is rewritten. The only observable maintenance signal is the commit history on the default branch; the last push was on 2026-08-24. A team that mirrors these lessons internally should decide deliberately whether to track upstream or freeze a copy, because nothing in the repository will tell them when the two diverge. The translation pipeline adds a second consideration: the README states the translated READMEs are produced by a GitHub Action, so a fork that edits English lessons will not automatically regenerate the translations it carries.

Who this is for and what to check before assigning it

The strongest use case is a study group or an onboarding track where someone needs shared vocabulary fast and nobody wants to buy seats. Eight modules at 30-60 minutes each is a bounded commitment, the quiz files give a natural checkpoint, and the CC0 licence removes the usual permission friction. It also works as a prerequisite reading list before a deeper course, which is exactly the role the README assigns it when it points readers onward to Microsoft Learn and Exam SC-900.

The wrong use case is a team that needs to operate something. If the deliverable is a hardened configuration, a detection rule, or an audit response, this repository will not produce it, and the README says so in its exclusions list. It is also a poor fit for anyone who learns by doing rather than reading; there are no labs, no sandbox and no exercises beyond self-marked quizzes.

Before assigning it, verify two things in the repository rather than in the README: that the numbered lesson files still match the module list you intend to teach, and that the translation you plan to use exists under translations/ and is current relative to the English file. Both checks take a minute and both are the kind of thing a truncated README table will not tell you.

Editorial conclusion

Adopt microsoft/Security-101 if you need a structured, vendor-neutral starting point for security concepts and you accept that it teaches vocabulary rather than tool operation; the README states plainly that it does not cover how to use specific security tools, how to hack or do red teaming, or specific compliance standards. Skip it if you want hands-on labs, offensive technique, or certification-aligned depth; the README points to Microsoft Learn and Exam SC-900 for that continuation instead. Before committing a study group to it, open the repository and check whether the module list still matches the files in the tree, since the README table is truncated and the individual lesson files are the actual source of truth.

Frequently asked questions

What is microsoft/Security-101?

It is a free cybersecurity curriculum published as a GitHub repository, described in its README as "Cybersecurity for Beginners" and organized into eight modules with a short quiz at the end of each. It is vendor agnostic and each lesson is meant to take around 30-60 minutes.

What does microsoft/Security-101 cover?

The README lists basic concepts such as the CIA triad and the difference between risks and threats, what a security control is, what zero trust means, and key concepts across identity, networking, security operations, infrastructure and data security. The file tree adds a final module on AI security and responsible AI.

Does microsoft/Security-101 teach how to use security tools?

No. The README's exclusions list states the course does not cover how to use specific security tools, how to hack or do red teaming or offensive security, or specific compliance standards.

Is there an install step for microsoft/Security-101?

There is nothing to install. The README points readers to the published site, and the lessons are Markdown files at the repository root that can be cloned and read locally or opened on GitHub.

What licence does microsoft/Security-101 use?

The repository carries CC0-1.0, a public domain dedication, which applies to the repository's own lesson text and images. Links inside the lessons to external Microsoft Learn material are governed by their own terms.

Official sources

  1. Issues
  2. License: CC0-1.0
  3. microsoft/Security-101 on GitHub
  4. Project website
  5. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/microsoft-security-101.svg)](https://hysenlabs.com/projects/microsoft-security-101)