Skip to content

sc-100Expert

Microsoft Cybersecurity Architect

Microsoft Certified: Cybersecurity Architect Expert

SC-100 is design, not configuration: strategy, trade-offs, and how the Microsoft security stack composes. The path leans on the strategy and governance guides, with the product explainers as reference rather than the main event.

For: Architects designing Zero Trust across identity, endpoints, data, and operations. Requires one associate SC certification as a prerequisite.

26 guides in 4sections. The sections are this site's grouping, written to follow the shape of the published skills outline; weightings and the current outline live on the exam page above and change between exam versions.

01Zero Trust strategy and governance

  1. 1Zero trust in Microsoft 365What zero trust actually means in a Microsoft 365 context — and the concrete controls that get you there.
  2. 2Microsoft 365 security and complianceA practical tour of the Microsoft 365 security and compliance stack — Defender, Purview, Entra, and how they fit together.
  3. 3Microsoft 365 governance frameworkA practical framework for governing Microsoft 365 — domains, policies, roles, and operating cadence.
  4. 4Microsoft 365 security baselinesThe minimum security configuration every Microsoft 365 tenant should have — and how to get there.
  5. 5Microsoft 365 tenant isolation and data residencyHow Microsoft 365 isolates tenant data, where it's physically stored, and the data residency commitments by region.
  6. 6Microsoft Purview Compliance ManagerCompliance Manager scores your tenant against compliance frameworks and tracks improvements over time.

02Identity and access architecture

  1. 7Hybrid identity strategy for Microsoft 365How to plan the hybrid-identity journey from on-premises AD to Entra ID-only — staged, with the right choices at each stage.
  2. 8Entra ID Conditional Access designDesigning a Conditional Access baseline: the policies, the principles, the order to write them in, and the habits that keep the estate healthy.
  3. 9Entra ID Privileged Identity ManagementPIM turns standing admin access into just-in-time, approval-gated activation. The model, what it covers, role settings that work, and a rollout that sticks.
  4. 10Entra ID Governance explainedEntra ID Governance explained: access reviews, entitlement management, lifecycle workflows, separation of duties, P2 vs Suite licensing, and rollout order.
  5. 11Microsoft Entra Global Secure AccessMicrosoft's SSE platform — Internet Access and Private Access for zero-trust network access. Here's what it does.
  6. 12Entra Permissions ManagementMicrosoft's Cloud Infrastructure Entitlement Management (CIEM) product, covering Azure, AWS, and GCP permissions.
  7. 13The Entra Suite explainedEntra Suite explained: Internet Access, Private Access, Verified ID, ID Governance, and Identity Protection in one licence — what each does and when it pays.

03Security operations and resilience

  1. 14Which Microsoft Defender is whichWhich Microsoft Defender is which: Endpoint, Office 365, Identity, Cloud Apps, Business, XDR, Cloud, Antivirus — what each does and which licence gets it.
  2. 15Defender XDR and attack-surface managementHow Microsoft Defender XDR unifies Defender for Office, Endpoint, Identity, and Cloud Apps into a single SOC workflow.
  3. 16Defender External Attack Surface ManagementDefender EASM discovers your organisation's internet-facing assets — including the ones you didn't know about.
  4. 17Microsoft Sentinel for Microsoft 365How Microsoft Sentinel ingests Microsoft 365 signals and extends Defender XDR into a full SIEM.
  5. 18Microsoft 365 incident response runbookA structured incident response runbook for Microsoft 365 — detection, triage, containment, eradication, recovery, lessons.
  6. 19Ransomware preparedness for Microsoft 365How to harden a Microsoft 365 tenant against ransomware — prevention, detection, response, and recovery.
  7. 20Microsoft 365 disaster recovery planningWhat disaster recovery means in a Microsoft 365 SaaS context — Microsoft's responsibilities, yours, and what to plan for.
  8. 21Microsoft 365 backup and recoveryWhat Microsoft 365 protects natively, what it doesn't, and how to design backup for Exchange, OneDrive, SharePoint, and Teams — native Backup vs third party.

04Data and application security

  1. 22What is Microsoft Purview?What Microsoft Purview is: labels, DLP, retention, eDiscovery, insider risk, and the data-governance catalogue — how the two halves differ and where to start.
  2. 23Microsoft Purview Data Loss Prevention — a deep diveDLP policies detect and prevent sensitive data from leaving Microsoft 365. Here's the architecture and how to roll them out.
  3. 24Microsoft 365 Copilot data security and privacyHow Microsoft 365 Copilot handles your tenant's data — what's sent to the model, what's retained, and what compliance covers.
  4. 25App consent policies and the admin consent workflowHow to stop consent phishing without blocking legitimate apps: Entra ID app consent policies, the admin consent workflow, and a review process that scales.
  5. 26Microsoft 365 service principal best practicesHow to design, deploy, and operate service principals safely — credentials, permissions, and lifecycle.

Independent site, not affiliated with Microsoft. Found a gap in this path? Send it through the contact form.