sc-100Expert
Microsoft Cybersecurity Architect
Microsoft Certified: Cybersecurity Architect Expert
SC-100 is design, not configuration: strategy, trade-offs, and how the Microsoft security stack composes. The path leans on the strategy and governance guides, with the product explainers as reference rather than the main event.
For: Architects designing Zero Trust across identity, endpoints, data, and operations. Requires one associate SC certification as a prerequisite.
26 guides in 4sections. The sections are this site's grouping, written to follow the shape of the published skills outline; weightings and the current outline live on the exam page above and change between exam versions.
01Zero Trust strategy and governance
- 1Zero trust in Microsoft 365What zero trust actually means in a Microsoft 365 context — and the concrete controls that get you there.
- 2Microsoft 365 security and complianceA practical tour of the Microsoft 365 security and compliance stack — Defender, Purview, Entra, and how they fit together.
- 3Microsoft 365 governance frameworkA practical framework for governing Microsoft 365 — domains, policies, roles, and operating cadence.
- 4Microsoft 365 security baselinesThe minimum security configuration every Microsoft 365 tenant should have — and how to get there.
- 5Microsoft 365 tenant isolation and data residencyHow Microsoft 365 isolates tenant data, where it's physically stored, and the data residency commitments by region.
- 6Microsoft Purview Compliance ManagerCompliance Manager scores your tenant against compliance frameworks and tracks improvements over time.
02Identity and access architecture
- 7Hybrid identity strategy for Microsoft 365How to plan the hybrid-identity journey from on-premises AD to Entra ID-only — staged, with the right choices at each stage.
- 8Entra ID Conditional Access designDesigning a Conditional Access baseline: the policies, the principles, the order to write them in, and the habits that keep the estate healthy.
- 9Entra ID Privileged Identity ManagementPIM turns standing admin access into just-in-time, approval-gated activation. The model, what it covers, role settings that work, and a rollout that sticks.
- 10Entra ID Governance explainedEntra ID Governance explained: access reviews, entitlement management, lifecycle workflows, separation of duties, P2 vs Suite licensing, and rollout order.
- 11Microsoft Entra Global Secure AccessMicrosoft's SSE platform — Internet Access and Private Access for zero-trust network access. Here's what it does.
- 12Entra Permissions ManagementMicrosoft's Cloud Infrastructure Entitlement Management (CIEM) product, covering Azure, AWS, and GCP permissions.
- 13The Entra Suite explainedEntra Suite explained: Internet Access, Private Access, Verified ID, ID Governance, and Identity Protection in one licence — what each does and when it pays.
03Security operations and resilience
- 14Which Microsoft Defender is whichWhich Microsoft Defender is which: Endpoint, Office 365, Identity, Cloud Apps, Business, XDR, Cloud, Antivirus — what each does and which licence gets it.
- 15Defender XDR and attack-surface managementHow Microsoft Defender XDR unifies Defender for Office, Endpoint, Identity, and Cloud Apps into a single SOC workflow.
- 16Defender External Attack Surface ManagementDefender EASM discovers your organisation's internet-facing assets — including the ones you didn't know about.
- 17Microsoft Sentinel for Microsoft 365How Microsoft Sentinel ingests Microsoft 365 signals and extends Defender XDR into a full SIEM.
- 18Microsoft 365 incident response runbookA structured incident response runbook for Microsoft 365 — detection, triage, containment, eradication, recovery, lessons.
- 19Ransomware preparedness for Microsoft 365How to harden a Microsoft 365 tenant against ransomware — prevention, detection, response, and recovery.
- 20Microsoft 365 disaster recovery planningWhat disaster recovery means in a Microsoft 365 SaaS context — Microsoft's responsibilities, yours, and what to plan for.
- 21Microsoft 365 backup and recoveryWhat Microsoft 365 protects natively, what it doesn't, and how to design backup for Exchange, OneDrive, SharePoint, and Teams — native Backup vs third party.
04Data and application security
- 22What is Microsoft Purview?What Microsoft Purview is: labels, DLP, retention, eDiscovery, insider risk, and the data-governance catalogue — how the two halves differ and where to start.
- 23Microsoft Purview Data Loss Prevention — a deep diveDLP policies detect and prevent sensitive data from leaving Microsoft 365. Here's the architecture and how to roll them out.
- 24Microsoft 365 Copilot data security and privacyHow Microsoft 365 Copilot handles your tenant's data — what's sent to the model, what's retained, and what compliance covers.
- 25App consent policies and the admin consent workflowHow to stop consent phishing without blocking legitimate apps: Entra ID app consent policies, the admin consent workflow, and a review process that scales.
- 26Microsoft 365 service principal best practicesHow to design, deploy, and operate service principals safely — credentials, permissions, and lifecycle.
Independent site, not affiliated with Microsoft. Found a gap in this path? Send it through the contact form.