Virginia Tech pays for LinkedIn Learning. Every current employee and student can take any course in it for free by signing in through the VT portal. The IT Security Office (ITSO) keeps a list of security courses it recommends, and that list is where most of the picks below come from. The AI picks are ours.
The ITSO list is 51 links with no descriptions. This page tells you which ones are worth your hour, who each one is for, and how long it takes. If you want everything, the full catalog has a card for every course on the ITSO list plus the AI picks.
Sign in the right way, or you will hit a paywall
The public LinkedIn Learning pages show a "Start my 1-month free trial" button. Ignore it. Go in through VT and the courses are free.
- Go to linkedinlearning.vt.edu.
- Type your VT email address and click Continue.
- You will be sent to VT single sign-on. Sign in with your VT Username (PID) and password and answer the 2-factor prompt.
- The first time, click Accept on the "Consent to Release Your Data" window.
- If you get asked to pay or start a trial, you are signed in to a personal LinkedIn account, not the VT portal. Sign out of LinkedIn and start again from step 1.
If you have a personal LinkedIn account linked to LinkedIn Learning, you will be asked for that password too. Linking is optional, and courses you take do not show up on your LinkedIn profile unless you share them. Full instructions: 4Help article LinkedIn Learning at Virginia Tech (KB0010087).
Every course below gives you a LinkedIn Learning certificate of completion when you finish. It is a LinkedIn certificate, not a VT credential.
Pick by who you are
Times are the course lengths shown on each course page.
Everyone in the college (faculty and staff)
EveryoneFaculty
1h 6m · Beginner · Released 6/28/2023
The one course to take if you take one. Phishing, bad Wi-Fi, passwords, updates, a stolen-laptop scenario, hybrid work. Scenario-based, no jargon.
Take it first. The title says 2025; the page's release date is 2023 and it lists no update date.
Everyone
1h 10m · Beginner · Released 12/12/2024
The attack you will actually see. Covers voice, text, and social-media phishing, has a lesson on AI-written phishing, and ends with what to do after you click.
Take it. Pair with our Report Phishing in Outlook guide for the VT-specific part.
EveryoneIT support
1h 1m · General · Released 11/21/2024
Your own computer: automatic updates, Windows security and privacy settings, password managers, browser privacy, two-factor. Windows-centric; Mac users still get the browser and account material.
Take it if you want a checklist for your own machine. ITSO lists it twice, once as Foundational and once as Advanced for IT professionals; it is a beginner course either way.
AAD IT and anyone with elevated access
EveryoneIT support
1h 52m · Beginner · Released 11/22/2022
Lisa Bock's baseline: risk, malware, how systems get breached, browser and wireless security, encryption basics.
Take it as the IT baseline. ITSO lists it under two labels; both land here. Note the label "Foundational Security" is also used for a different course under Awareness Training.
IT support
2h 4m · Beginner · Released 4/29/2022
Windows (NTFS, UAC), macOS, Linux, authentication and MFA, email protection, encryption.
Take it after Core Concepts. The macOS chapter is short; this is not a Mac admin course.
IT support
1h 53m · Intermediate · Released 11/4/2024
Practical hardening of a Linux server: boot, disk encryption, SELinux/AppArmor, PAM, sudo, permissions, SSH, firewall rules.
Take it if you have root on anything. Current and specific.
Developers (web apps, scripts, integrations)
Developers
46m · Beginner · Released 6/23/2023
The common web vulnerabilities, each shown and then fixed: broken auth, IDOR, XSS, CSRF, information disclosure, open redirects, business-logic errors.
Take it second, after Ten Security Tips. Then take the OWASP Top 10.
Developers
35m · Beginner · Released 12/6/2021
One lesson per item on the 2021 list. Take it right after the course above.
Take it. ITSO's safeguard pages point at the OWASP Top Ten as the reference list; this is the 35-minute tour of it. It is the 2021 list; OWASP has since published a newer edition, so check owasp.org for changes.
Developers
37m · Intermediate · Released 12/7/2022
Don't trust the user, validate and sanitize, limit privileges, encrypt, authenticate every interaction, assume you will be breached.
Take it as the first developer course. Short, and every lesson is a habit.
Managers and directors
Managers
1h 24m · Beginner · Released 8/22/2022
Why you are a target, what phishing, malware, identity theft, and financial fraud look like from the manager's chair, and what the organizational response is for each.
Take it if you lead a unit. It is the only course on the list written for a manager's decisions rather than a user's habits.
Managers
1h 52m · Beginner · Released 2/3/2022
Risk appetite and tolerance, assessments, a risk register, choosing and validating controls. This is the vocabulary the university's unit risk register uses.
Take it before your next risk assessment cycle. The register lesson and the controls lessons map directly to what ITSO asks units to do.
IT supportManagers
41m · Beginner · Released 8/1/2023
The outside context: US federal roles, privacy and consumer protection, EU privacy, law enforcement contacts. VT-specific policy lives on the ITSO site, not here.
Take it for the big picture. Skip it if you want VT policy; that is at security.vt.edu and policies.vt.edu, not in this course.
Data stewards and anyone who handles student or personnel records
Data roles
1h 55m · Beginner · Released 7/23/2021
Roles, data quality, security, privacy principles, and the regulations, with separate lessons on FERPA and HIPAA.
Take it if you are a steward or you supervise people who touch protected records; the FERPA lesson alone is worth it. Skip it if you want the strategy view.
Working with AI
These are not on the ITSO list. We picked them from LinkedIn Learning's current AI catalog for a college where most people are not programmers and a few are. Practice on HokieAI, the university's AI tool, so you are not pasting work data into a personal account.
Start here (anyone)
Everyone
1h · Beginner · Released 5/11/2026
Newest of the plain-language primers. Explains hallucinations, retrieval, and agents in short lessons, and has a lesson on questions to ask vendors.
Take it. If you want the older, longer, most-taken version of this idea, "What Is Generative AI?" (1h 3m, 2023) is still available, but its tool examples are dated.
Everyone
54m · Beginner · Released 8/11/2026
The 2026 rewrite of the most-taken prompting course. Take this one, not the 2023 version that still shows up in search.
Take this edition. The 2023 edition (29m) is still listed and still shows up first in some searches; it predates most of the tools you now use.
Use it for real work (anyone)
Everyone
1h 36m · Beginner · Released 7/9/2025
Research prompts, summarizing, outlining, editing, citations, and a lesson on fact-checking your own draft.
Take it if you want the practical version of "how do I actually use this." The lessons are tool-agnostic even though the description says ChatGPT.
Everyone
48m · Beginner · Released 12/22/2025
What an agent is, when not to use one, keeping a human in the loop, then building a workflow from a template and from scratch.
Take it if you want to try. Check with AAD IT before connecting any agent to university data or accounts; the course's "human in the loop" lesson is the part to remember.
Check what it gives you (anyone)
Everyone
46m · Intermediate · Released 4/22/2026
Why polished output is harder to verify, the red flags, a step-by-step verification workflow, and what changes when an agent takes actions instead of writing words.
Take it. It is the only nontechnical course found that treats checking the output as the whole subject.
Protect data and stay on the right side of policy (anyone, especially managers)
Everyone
39m · Beginner · Released 4/28/2025
AI-written phishing, deepfakes, data privacy when using AI tools, reporting suspicious AI content. Same instructor and format as the ITSO phishing course.
Take it. It is the shortest way to cover "what should I not paste into a chatbot" and "that voice on the phone may not be your dean."
EveryoneManagers
1h 9m · General · Released 1/23/2025
Copyright, privacy, security risks, workplace AI policy, and what "know your tool" means before you paste anything into it.
Take it if you supervise people who use AI tools, or if you are unsure what you are allowed to do with a student's or colleague's work in one.
Faculty
Managers and IT staff deciding whether to use agents
IT supportManagers
1h 23m · Beginner · Released 6/25/2025
What agents are, when to use and not use them, return on investment, security and safety, monitoring. No code.
Take it before approving or building an agent for a real workflow. It is the only agent course we found with a "when not to" lesson and a security lesson at the concept level.
Developers
Developers
1h 14m · Intermediate · Released 2/12/2025
Hands-on Python: a ReAct agent, a retrieval-backed Q&A bot, custom LangGraph agents, multi-agent systems. Runs in GitHub Codespaces.
Take it as the hands-on complement to the concepts course. If you want to work through hallucination testing in code, the same instructor's colleague course "LLM Evaluations and Grounding Techniques" (2h 44m, 2024) goes deeper.
Developers
1h 1m · Beginner · Released 3/30/2026
Build MCP servers and clients in Python: tools, resources, prompts, the Inspector, a document-management project.
Take it if you will write an integration. For the usage side (installing MCP servers into Claude Desktop or Cursor) plus a TypeScript server, "Model Context Protocol (MCP): Hands-On with Agentic AI" (55m, 2025) is the alternative.
Developers
1h 7m · Beginner · Released 8/18/2026
Using a coding agent day to day: the explore, plan, code, commit loop, context management, CLAUDE.md, subagents, MCP, hooks.
Take it if you have Claude access through HokieAI or otherwise and want to use a coding agent on real code. Tool-specific by design.
What this page is not
- It is not the university's required annual security awareness training. That is the SANS "Securing the Human" course in PageUp, which ITSO requires of all active employees every year. This page does not replace it.
- It does not say that any course here satisfies a specific ITSO or audit requirement. ITSO recommends these courses; whether a given course counts toward a finding in your unit's risk register is a question for ITSO, and you should ask before assuming.
- It is not a complete catalog of LinkedIn Learning. Search the library yourself once you are signed in.
Questions, or a course we should add: open a ticket with AAD IT.